PT-2014-1337 · Adobe+3 · Air Sdk & Compiler+7

Published

2014-06-10

·

Updated

2017-12-22

·

CVE-2014-0533

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Adobe Flash Player (affected versions not specified) Adobe AIR (affected versions not specified) Adobe AIR SDK (affected versions not specified) Adobe AIR SDK & Compiler (affected versions not specified) Adobe Pepper Flash for Google Chrome (affected versions not specified)
Description The issue allows remote attackers to inject arbitrary web scripts or HTML code, enabling them to perform malicious actions. This is a case of cross-site scripting (XSS), which can lead to various security problems.
Recommendations For Adobe Flash Player, update to a version that includes a fix for this issue. For Adobe AIR, consider disabling the execution of external scripts until a patch is available. For Adobe AIR SDK, restrict the use of vulnerable components to minimize the risk of exploitation. For Adobe AIR SDK & Compiler, avoid using the vulnerable SDK until the issue is resolved. For Adobe Pepper Flash for Google Chrome, consider disabling the plugin until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2014-1787
BDU:2015-00197
BDU:2015-00257
BDU:2015-00258
CVE-2014-0533
MGASA-2014-0261
RHSA-2014:0745
RHSA-2014_0745

Affected Products

Alt Linux
Air
Air Sdk
Air Sdk & Compiler
Flash Player
Pepper Flash For Google Chrome
Red Hat
Suse