CVE-2014-0556: Buffer Overflow
Heap-based buffer overflow in Adobe Flash Player before 13.0.0.244 and 14.x and 15.x before 15.0.0.152 on Windows and OS X and before 11.2.202.406 on Linux, Adobe AIR before 15.0.0.249 on Windows and OS X and before 15.0.0.252 on Android, Adobe AIR SDK before 15.0.0.249, and Adobe AIR SDK & Compiler before 15.0.0.249 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2014-0559.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2014-0556?
CVE-2014-0556 has a high severity rating, making it a critical security vulnerability in Adobe Flash Player.
How do I fix CVE-2014-0556?
To fix CVE-2014-0556, update your Adobe Flash Player to version 13.0.0.244 or later for Windows and OS X, and version 11.2.202.406 for Linux.
Which versions of Adobe Flash Player are affected by CVE-2014-0556?
Adobe Flash Player versions prior to 13.0.0.244 for Windows and OS X, and versions prior to 11.2.202.406 for Linux are affected by CVE-2014-0556.
Are Adobe AIR versions vulnerable to CVE-2014-0556?
Yes, Adobe AIR versions before 15.0.0.249 for Windows and OS X as well as before 14.0.0.178 are vulnerable to CVE-2014-0556.
What kind of vulnerability is CVE-2014-0556?
CVE-2014-0556 is a heap-based buffer overflow vulnerability that can be exploited to execute arbitrary code.