CVE Vulnerabilities

CVE-2014-0497

Integer Underflow (Wrap or Wraparound)

Published: Feb 05, 2014 | Modified: Dec 20, 2024
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
10 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
6.8 CRITICAL
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V3
Ubuntu
MEDIUM

Integer underflow in Adobe Flash Player before 11.7.700.261 and 11.8.x through 12.0.x before 12.0.0.44 on Windows and Mac OS X, and before 11.2.202.336 on Linux, allows remote attackers to execute arbitrary code via unspecified vectors.

Weakness

The product subtracts one value from another, such that the result is less than the minimum allowable integer value, which produces a value that is not equal to the correct result.

Affected Software

Name Vendor Start Version End Version
Flash_player Adobe * 11.2.202.336 (excluding)
Supplementary for Red Hat Enterprise Linux 5 RedHat flash-plugin-0:11.2.202.336-1.el5 *
Supplementary for Red Hat Enterprise Linux 6 RedHat flash-plugin-0:11.2.202.336-1.el6 *
Adobe-flashplugin Ubuntu lucid *
Adobe-flashplugin Ubuntu precise *
Adobe-flashplugin Ubuntu quantal *
Adobe-flashplugin Ubuntu saucy *
Flashplugin-nonfree Ubuntu devel *
Flashplugin-nonfree Ubuntu lucid *
Flashplugin-nonfree Ubuntu precise *
Flashplugin-nonfree Ubuntu quantal *
Flashplugin-nonfree Ubuntu saucy *

References