Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2014-0503


Adobe Flash Player before 11.7.700.272 and 11.8.x through 12.0.x before 12.0.0.77 on Windows and OS X, and before 11.2.202.346 on Linux, allows remote attackers to bypass the Same Origin Policy via unspecified vectors.


Published

2014-03-12T05:15:20.163

Last Modified

2025-04-12T10:46:40.837

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 6.4 (MEDIUM)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:P/I:P/A:N

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: NONE
Exploitability Score

10.0

Impact Score

4.9

Weaknesses
  • Type: Primary
    CWE-264

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application adobe flash_player < 11.2.202.346 Yes
Operating System linux linux_kernel * No
Application adobe flash_player < 11.7.700.272 Yes
Application adobe flash_player < 12.0.0.77 Yes
Operating System apple mac_os_x * No
Operating System microsoft windows - No

References