CVE-2014-9164: Code Injection
Adobe Flash Player before 13.0.0.259 and 14.x through 16.x before 16.0.0.235 on Windows and OS X and before 11.2.202.425 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2014-0587.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-9164?
CVE-2014-9164 is considered a critical vulnerability because it allows attackers to execute arbitrary code or cause a denial of service.
How do I fix CVE-2014-9164?
To fix CVE-2014-9164, update Adobe Flash Player to version 13.0.0.259 or later for Windows and OS X, or to version 11.2.202.425 or later for Linux.
What systems are affected by CVE-2014-9164?
CVE-2014-9164 affects Adobe Flash Player versions earlier than 13.0.0.259, 14.x through 16.x before 16.0.0.235 on Windows and OS X, and versions before 11.2.202.425 on Linux.
Is CVE-2014-9164 related to any other vulnerabilities?
CVE-2014-9164 is a different vulnerability than CVE-2014-0587, despite both impacting Adobe Flash Player.
What should I do if I can't update Adobe Flash Player for CVE-2014-9164?
If you cannot update Adobe Flash Player, consider disabling it or using alternative software to reduce your exposure to CVE-2014-9164.