CVE-2014-0531

Cross-site scripting (XSS) vulnerability in Adobe Flash Player before 13.0.0.223 and 14.x before 14.0.0.125 on Windows and OS X and before 11.2.202.378 on Linux, Adobe AIR before 14.0.0.110, Adobe AIR SDK before 14.0.0.110, and Adobe AIR SDK & Compiler before 14.0.0.110 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2014-0532 and CVE-2014-0533.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:adobe:adobe_air:*:*:*:*:*:*:*:*
cpe:2.3:a:adobe:adobe_air:13.0.0.83:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
OR cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:13.0.0.182:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:13.0.0.201:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:13.0.0.206:*:*:*:*:*:*:*
OR cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:*:*:*:*:*:*:*:*

Configuration 3 (hide)

OR cpe:2.3:a:adobe:adobe_air_sdk:*:*:*:*:*:*:*:*
cpe:2.3:a:adobe:adobe_air_sdk:13.0.0.83:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
OR cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:11.2.202.223:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:11.2.202.228:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:11.2.202.233:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:11.2.202.235:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:11.2.202.236:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:11.2.202.238:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:11.2.202.243:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:11.2.202.251:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:11.2.202.258:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:11.2.202.261:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:11.2.202.262:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:11.2.202.270:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:11.2.202.273:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:11.2.202.275:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:11.2.202.280:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:11.2.202.285:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:11.2.202.291:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:11.2.202.297:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:11.2.202.310:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:11.2.202.332:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:11.2.202.335:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:11.2.202.336:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:11.2.202.341:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:11.2.202.346:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:11.2.202.350:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:11.2.202.356:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

History

21 Nov 2024, 02:02

Type Values Removed Values Added
References () http://helpx.adobe.com/security/products/flash-player/apsb14-16.html - Patch, Vendor Advisory () http://helpx.adobe.com/security/products/flash-player/apsb14-16.html - Patch, Vendor Advisory
References () http://lists.opensuse.org/opensuse-security-announce/2014-06/msg00021.html - () http://lists.opensuse.org/opensuse-security-announce/2014-06/msg00021.html -
References () http://lists.opensuse.org/opensuse-updates/2014-06/msg00029.html - () http://lists.opensuse.org/opensuse-updates/2014-06/msg00029.html -
References () http://lists.opensuse.org/opensuse-updates/2014-06/msg00030.html - () http://lists.opensuse.org/opensuse-updates/2014-06/msg00030.html -
References () http://rhn.redhat.com/errata/RHSA-2014-0745.html - () http://rhn.redhat.com/errata/RHSA-2014-0745.html -
References () http://secunia.com/advisories/58390 - () http://secunia.com/advisories/58390 -
References () http://secunia.com/advisories/58465 - () http://secunia.com/advisories/58465 -
References () http://secunia.com/advisories/58585 - () http://secunia.com/advisories/58585 -
References () http://secunia.com/advisories/59053 - () http://secunia.com/advisories/59053 -
References () http://secunia.com/advisories/59304 - () http://secunia.com/advisories/59304 -
References () http://security.gentoo.org/glsa/glsa-201406-17.xml - () http://security.gentoo.org/glsa/glsa-201406-17.xml -
References () http://www.securityfocus.com/bid/67962 - () http://www.securityfocus.com/bid/67962 -
References () http://www.securitytracker.com/id/1030368 - () http://www.securitytracker.com/id/1030368 -

Information

Published : 2014-06-11 10:57

Updated : 2024-11-21 02:02


NVD link : CVE-2014-0531

Mitre link : CVE-2014-0531

CVE.ORG link : CVE-2014-0531


JSON object : View

Products Affected

apple

  • mac_os_x

adobe

  • adobe_air_sdk
  • adobe_air
  • flash_player

linux

  • linux_kernel

microsoft

  • windows
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')