CVE-2014-0580: Critical severity macromedia flash player vulnerability
Adobe Flash Player before 13.0.0.259 and 14.x through 16.x before 16.0.0.235 on Windows and OS X and before 11.2.202.425 on Linux allows remote attackers to bypass the Same Origin Policy via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-0580?
CVE-2014-0580 is considered a critical vulnerability that allows remote attackers to bypass the Same Origin Policy.
How do I fix CVE-2014-0580?
To fix CVE-2014-0580, update Adobe Flash Player to version 13.0.0.259 or later, or version 16.0.0.235 or later.
Which versions of Adobe Flash Player are affected by CVE-2014-0580?
CVE-2014-0580 affects Adobe Flash Player versions before 13.0.0.259, versions from 14.x up to 16.0.0.235, and version 11.2.202.425 on Linux.
Can CVE-2014-0580 affect users on macOS?
Yes, users on macOS with Adobe Flash Player versions before 16.0.0.235 are vulnerable to CVE-2014-0580.
Is there a workaround for CVE-2014-0580?
While updating Adobe Flash Player is the best solution, disabling Flash content in browsers can serve as a temporary workaround for CVE-2014-0580.