CVE-2014-0531: XSS
Cross-site scripting (XSS) vulnerability in Adobe Flash Player before 13.0.0.223 and 14.x before 14.0.0.125 on Windows and OS X and before 11.2.202.378 on Linux, Adobe AIR before 14.0.0.110, Adobe AIR SDK before 14.0.0.110, and Adobe AIR SDK & Compiler before 14.0.0.110 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2014-0532 and CVE-2014-0533.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2014-0531?
CVE-2014-0531 is classified as a critical security vulnerability due to its potential for remote exploitation via cross-site scripting.
How do I fix CVE-2014-0531?
To fix CVE-2014-0531, update Adobe Flash Player to version 13.0.0.223 or later for Windows and OS X, or 11.2.202.378 or later for Linux.
Which versions of Adobe Flash Player are affected by CVE-2014-0531?
Adobe Flash Player versions before 13.0.0.223 on Windows and OS X, and 11.2.202.378 on Linux are affected by CVE-2014-0531.
What type of vulnerability is CVE-2014-0531?
CVE-2014-0531 is a cross-site scripting (XSS) vulnerability that allows attackers to execute malicious scripts in the context of a user's session.
Is Adobe AIR affected by CVE-2014-0531?
Yes, Adobe AIR versions prior to 14.0.0.110 are also affected by CVE-2014-0531.