PT-2014-1336 · Google+4 · Google Chrome+8

Published

2014-06-10

·

Updated

2017-12-22

·

CVE-2014-0531

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Adobe AIR (affected versions not specified) Adobe Pepper Flash for Google Chrome (affected versions not specified) Adobe Flash Player (affected versions not specified) Adobe AIR SDK (affected versions not specified) Adobe AIR SDK & Compiler (affected versions not specified)
Description The issue allows remote attackers to inject arbitrary web scripts or HTML code, enabling them to perform cross-site scripting (XSS) attacks. This can lead to the execution of malicious scripts on the victim's browser, potentially resulting in unauthorized actions or data theft. The estimated number of potentially affected devices worldwide is not specified. There is no information about real-world incidents where this issue was exploited.
Recommendations For Adobe AIR, consider disabling the execution of web scripts until a patch is available. For Adobe Pepper Flash for Google Chrome, restrict access to flash content to minimize the risk of exploitation. For Adobe Flash Player, avoid using flash-based applications until the issue is resolved. For Adobe AIR SDK, restrict the use of the SDK to prevent the development of vulnerable applications. For Adobe AIR SDK & Compiler, consider disabling the compiler until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2014-1787
BDU:2015-00196
BDU:2015-00255
BDU:2015-00256
CVE-2014-0531
MGASA-2014-0261
RHSA-2014:0745
RHSA-2014_0745
SUSE-SU-2014_0806-1

Affected Products

Alt Linux
Air
Air Sdk
Air Sdk & Compiler
Flash Player
Pepper Flash
Google Chrome
Red Hat
Suse