CVE-2014-0502

Double free vulnerability in Adobe Flash Player before 11.7.700.269 and 11.8.x through 12.0.x before 12.0.0.70 on Windows and Mac OS X and before 11.2.202.341 on Linux, Adobe AIR before 4.0.0.1628 on Android, Adobe AIR SDK before 4.0.0.1628, and Adobe AIR SDK & Compiler before 4.0.0.1628 allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in February 2014.
References
Link Resource
http://helpx.adobe.com/security/products/flash-player/apsb14-07.html Broken Link Patch Vendor Advisory
http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00014.html Mailing List
http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00015.html Mailing List
http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00017.html Mailing List
http://rhn.redhat.com/errata/RHSA-2014-0196.html Third Party Advisory
http://security.gentoo.org/glsa/glsa-201405-04.xml Third Party Advisory
http://www.alienvault.com/open-threat-exchange/blog/analysis-of-an-attack-exploiting-the-adobe-zero-day-cve-2014-0502/ Exploit Third Party Advisory
https://volatility-labs.blogspot.com/2014/04/building-decoder-for-cve-2014-0502.html Exploit Third Party Advisory
http://helpx.adobe.com/security/products/flash-player/apsb14-07.html Broken Link Patch Vendor Advisory
http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00014.html Mailing List
http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00015.html Mailing List
http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00017.html Mailing List
http://rhn.redhat.com/errata/RHSA-2014-0196.html Third Party Advisory
http://security.gentoo.org/glsa/glsa-201405-04.xml Third Party Advisory
http://www.alienvault.com/open-threat-exchange/blog/analysis-of-an-attack-exploiting-the-adobe-zero-day-cve-2014-0502/ Exploit Third Party Advisory
https://volatility-labs.blogspot.com/2014/04/building-decoder-for-cve-2014-0502.html Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:*
OR cpe:2.3:o:apple:mac_os_x:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:a:adobe:adobe_air_sdk:*:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:a:adobe:adobe_air:*:*:*:*:*:*:*:*
cpe:2.3:o:google:android:-:*:*:*:*:*:*:*

Configuration 5 (hide)

OR cpe:2.3:o:opensuse:opensuse:11.4:*:*:*:*:*:*:*
cpe:2.3:o:opensuse:opensuse:12.3:*:*:*:*:*:*:*
cpe:2.3:o:opensuse:opensuse:13.1:*:*:*:*:*:*:*
cpe:2.3:o:suse:linux_enterprise_desktop:11:sp3:*:*:*:*:*:*

Configuration 6 (hide)

OR cpe:2.3:o:redhat:enterprise_linux_desktop:5.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_desktop:6.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_eus:6.5:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server:5.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server:6.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server_aus:6.5:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_workstation:5.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_workstation:6.0:*:*:*:*:*:*:*

History

No history.

Information

Published : 2014-02-21 05:07

Updated : 2025-04-11 00:51


NVD link : CVE-2014-0502

Mitre link : CVE-2014-0502

CVE.ORG link : CVE-2014-0502


JSON object : View

Products Affected

opensuse

  • opensuse

redhat

  • enterprise_linux_workstation
  • enterprise_linux_server_aus
  • enterprise_linux_desktop
  • enterprise_linux_eus
  • enterprise_linux_server

adobe

  • flash_player
  • adobe_air_sdk
  • adobe_air

suse

  • linux_enterprise_desktop

google

  • android

apple

  • mac_os_x

linux

  • linux_kernel

microsoft

  • windows
CWE
CWE-415

Double Free