PT-2014-1338 · Adobe+3 · Air Sdk & Compiler+7

Publicado

2014-06-10

·

Atualizado

2017-12-22

·

CVE-2014-0532

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Adobe Flash Player (affected versions not specified) Adobe AIR (affected versions not specified) Adobe AIR SDK (affected versions not specified) Adobe AIR SDK & Compiler (affected versions not specified) Adobe Pepper Flash for Google Chrome (affected versions not specified)
Description The issue allows remote attackers to inject arbitrary web scripts or HTML code, enabling them to perform cross-site scripting (XSS) attacks. This can lead to the execution of malicious scripts on the victim's browser, potentially resulting in unauthorized actions or data theft. The estimated number of potentially affected devices worldwide is not specified. There is no information available about real-world incidents where this issue was exploited.
Recommendations For Adobe Flash Player, update to a version that contains a fix for this issue. For Adobe AIR, consider disabling the use of vulnerable components until a patch is available. For Adobe AIR SDK, restrict access to vulnerable modules to minimize the risk of exploitation. For Adobe AIR SDK & Compiler, avoid using vulnerable parameters in affected API endpoints until the issue is resolved. For Adobe Pepper Flash for Google Chrome, consider disabling the vulnerableFunction() function until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2014-1787
BDU:2015-00198
BDU:2015-00259
BDU:2015-00260
CVE-2014-0532
MGASA-2014-0261
RHSA-2014:0745
RHSA-2014_0745

Produtos afetados

Alt Linux
Air
Air Sdk
Air Sdk & Compiler
Flash Player
Pepper Flash For Google Chrome
Red Hat
Suse