Adobe Flash Player before 11.7.700.269 and 11.8.x through 12.0.x before 12.0.0.70 on Windows and Mac OS X and before 11.2.202.341 on Linux, Adobe AIR before 4.0.0.1628 on Android, Adobe AIR SDK before 4.0.0.1628, and Adobe AIR SDK & Compiler before 4.0.0.1628 do not prevent access to address information, which makes it easier for attackers to bypass the ASLR protection mechanism via unspecified vectors.
2014-02-21T05:07:00.000
2025-04-11T00:51:21.963
Deferred
CVSSv2: 7.8 (HIGH)
AV:N/AC:L/Au:N/C:C/I:N/A:N
10.0
6.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | adobe | flash_player | < 11.7.700.269 | Yes |
Application | adobe | flash_player | < 11.8.800.175 | Yes |
Application | adobe | flash_player | < 12.0.0.70 | Yes |
Operating System | apple | mac_os_x | * | No |
Operating System | microsoft | windows | - | No |
Application | adobe | adobe_air_sdk | < 4.0.0.1628 | Yes |
Application | adobe | flash_player | < 11.2.202.341 | Yes |
Operating System | linux | linux_kernel | * | No |
Application | adobe | adobe_air | < 4.0.0.1628 | Yes |