Adobe Flash Player before 11.7.700.260 and 11.8.x and 11.9.x before 12.0.0.38 on Windows and Mac OS X and before 11.2.202.335 on Linux, Adobe AIR before 4.0.0.1390, Adobe AIR SDK before 4.0.0.1390, and Adobe AIR SDK & Compiler before 4.0.0.1390 allow attackers to defeat the ASLR protection mechanism by leveraging an "address leak."
2014-01-15T16:13:04.023
2025-04-11T00:51:21.963
Deferred
CVSSv2: 10.0 (HIGH)
AV:N/AC:L/Au:N/C:C/I:C/A:C
10.0
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | adobe | flash_player | < 11.7.700.260 | Yes |
Application | adobe | flash_player | < 11.8.800.175 | Yes |
Application | adobe | flash_player | < 12.0.0.38 | Yes |
Operating System | apple | mac_os_x | * | No |
Operating System | microsoft | windows | - | No |
Application | adobe | adobe_air_sdk | < 4.0.0.1390 | Yes |
Application | adobe | flash_player | < 11.2.202.335 | Yes |
Operating System | linux | linux_kernel | * | No |
Application | adobe | adobe_air | < 4.0.0.1390 | Yes |