CVE-2014-8439
adobe flash player, adobe air, adobe air sdk
Published 25 Nov 2014 · updated 17 Jun 2026 · Analyzed
8.8 High · CVSS 3.1, CISA ADP
Exploited in the wild
CISA added this to its Known Exploited Vulnerabilities catalog on 25 May 2022, with a remediation deadline of 15 Jun 2022 for US federal agencies.
Required action: The impacted product is end-of-life and should be disconnected if still in use.
Description
Adobe Flash Player before 13.0.0.258 and 14.x and 15.x before 15.0.0.239 on Windows and OS X and before 11.2.202.424 on Linux, Adobe AIR before 15.0.0.293, Adobe AIR SDK before 15.0.0.302, and Adobe AIR SDK & Compiler before 15.0.0.302 allow attackers to execute arbitrary code or cause a denial of service (invalid pointer dereference) via unspecified vectors.
References
- helpx.adobe.com/security/products/flash-player/apsb14-22.html · Vendor Advisory
- helpx.adobe.com/security/products/flash-player/apsb14-26.html · Vendor Advisory
- lists.opensuse.org/opensuse-security-announce/2014-11/msg00020.html · Third Party Advisory
- lists.opensuse.org/opensuse-security-announce/2014-12/msg00001.html · Third Party Advisory
- lists.opensuse.org/opensuse-security-announce/2014-12/msg00004.html · Third Party Advisory
- rhn.redhat.com/errata/RHSA-2014-1915.html · Vendor Advisory
- secunia.com/advisories/60217 · Permissions Required
- www.securityfocus.com/bid/71289 · Third Party Advisory, VDB Entry
- www.securitytracker.com/id/1031259 · Third Party Advisory, VDB Entry
- exchange.xforce.ibmcloud.com/vulnerabilities/98932 · Third Party Advisory, VDB Entry
- www.f-secure.com/weblog/archives/00002768.html · Third Party Advisory
- www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2014-8439 · US Government Resource