First published: Wed Mar 12 2014(Updated: )
Adobe Flash Player before 11.7.700.272 and 11.8.x through 12.0.x before 12.0.0.77 on Windows and OS X, and before 11.2.202.346 on Linux, allows remote attackers to bypass the Same Origin Policy via unspecified vectors.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Macromedia Flash Player | >=11.0<11.2.202.346 | |
Linux Kernel | ||
Macromedia Flash Player | >=11.0<11.7.700.272 | |
Macromedia Flash Player | >=11.8<12.0.0.77 | |
Apple iOS and macOS | ||
Microsoft Windows Operating System | ||
All of | ||
Macromedia Flash Player | >=11.0<11.2.202.346 | |
Linux Kernel | ||
All of | ||
Any of | ||
Macromedia Flash Player | >=11.0<11.7.700.272 | |
Macromedia Flash Player | >=11.8<12.0.0.77 | |
Any of | ||
Apple iOS and macOS | ||
Microsoft Windows Operating System |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2014-0503 is considered critical as it allows attackers to bypass the Same Origin Policy.
To fix CVE-2014-0503, update Adobe Flash Player to version 12.0.0.77 or later on affected platforms.
Adobe Flash Player versions prior to 11.7.700.272, versions 11.8.x through 12.0.x before 12.0.0.77 on Windows and OS X, and versions before 11.2.202.346 on Linux are affected.
CVE-2014-0503 impacts Windows, macOS, and Linux platforms running the affected versions of Adobe Flash Player.
Yes, CVE-2014-0503 can be exploited remotely, allowing attackers to manipulate the Same Origin Policy.