ALT-PU-2014-1289-1
Package adobe-flash-player updated to version 11-alt27 for branch c7 in task 116412.
Closed vulnerabilities
Modified: 2025-04-11
CVE-2013-5329
Adobe Flash Player before 11.7.700.252 and 11.8.x and 11.9.x before 11.9.900.152 on Windows and Mac OS X and before 11.2.202.327 on Linux, Adobe AIR before 3.9.0.1210, Adobe AIR SDK before 3.9.0.1210, and Adobe AIR SDK & Compiler before 3.9.0.1210 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-5330.
- http://lists.opensuse.org/opensuse-security-announce/2013-11/msg00015.html
- http://lists.opensuse.org/opensuse-security-announce/2013-11/msg00016.html
- http://lists.opensuse.org/opensuse-security-announce/2013-11/msg00019.html
- http://rhn.redhat.com/errata/RHSA-2013-1518.html
- http://www.adobe.com/support/security/bulletins/apsb13-26.html
- http://lists.opensuse.org/opensuse-security-announce/2013-11/msg00015.html
- http://lists.opensuse.org/opensuse-security-announce/2013-11/msg00016.html
- http://lists.opensuse.org/opensuse-security-announce/2013-11/msg00019.html
- http://rhn.redhat.com/errata/RHSA-2013-1518.html
- http://www.adobe.com/support/security/bulletins/apsb13-26.html
Modified: 2025-04-11
CVE-2013-5330
Adobe Flash Player before 11.7.700.252 and 11.8.x and 11.9.x before 11.9.900.152 on Windows and Mac OS X and before 11.2.202.327 on Linux, Adobe AIR before 3.9.0.1210, Adobe AIR SDK before 3.9.0.1210, and Adobe AIR SDK & Compiler before 3.9.0.1210 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-5329.
- http://lists.opensuse.org/opensuse-security-announce/2013-11/msg00015.html
- http://lists.opensuse.org/opensuse-security-announce/2013-11/msg00016.html
- http://lists.opensuse.org/opensuse-security-announce/2013-11/msg00019.html
- http://rhn.redhat.com/errata/RHSA-2013-1518.html
- http://www.adobe.com/support/security/bulletins/apsb13-26.html
- http://lists.opensuse.org/opensuse-security-announce/2013-11/msg00015.html
- http://lists.opensuse.org/opensuse-security-announce/2013-11/msg00016.html
- http://lists.opensuse.org/opensuse-security-announce/2013-11/msg00019.html
- http://rhn.redhat.com/errata/RHSA-2013-1518.html
- http://www.adobe.com/support/security/bulletins/apsb13-26.html
Modified: 2025-04-11
CVE-2013-5331
Adobe Flash Player before 11.7.700.257 and 11.8.x and 11.9.x before 11.9.900.170 on Windows and Mac OS X and before 11.2.202.332 on Linux, Adobe AIR before 3.9.0.1380, Adobe AIR SDK before 3.9.0.1380, and Adobe AIR SDK & Compiler before 3.9.0.1380 allow remote attackers to execute arbitrary code via crafted .swf content that leverages an unspecified "type confusion," as exploited in the wild in December 2013.
- http://helpx.adobe.com/security/products/flash-player/apsb13-28.html
- http://lists.opensuse.org/opensuse-security-announce/2013-12/msg00008.html
- http://lists.opensuse.org/opensuse-updates/2013-12/msg00075.html
- http://lists.opensuse.org/opensuse-updates/2013-12/msg00084.html
- http://rhn.redhat.com/errata/RHSA-2013-1818.html
- http://helpx.adobe.com/security/products/flash-player/apsb13-28.html
- http://lists.opensuse.org/opensuse-security-announce/2013-12/msg00008.html
- http://lists.opensuse.org/opensuse-updates/2013-12/msg00075.html
- http://lists.opensuse.org/opensuse-updates/2013-12/msg00084.html
- http://rhn.redhat.com/errata/RHSA-2013-1818.html
Modified: 2025-04-11
CVE-2013-5332
Adobe Flash Player before 11.7.700.257 and 11.8.x and 11.9.x before 11.9.900.170 on Windows and Mac OS X and before 11.2.202.332 on Linux, Adobe AIR before 3.9.0.1380, Adobe AIR SDK before 3.9.0.1380, and Adobe AIR SDK & Compiler before 3.9.0.1380 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.
- http://helpx.adobe.com/security/products/flash-player/apsb13-28.html
- http://lists.opensuse.org/opensuse-security-announce/2013-12/msg00008.html
- http://lists.opensuse.org/opensuse-updates/2013-12/msg00075.html
- http://lists.opensuse.org/opensuse-updates/2013-12/msg00084.html
- http://rhn.redhat.com/errata/RHSA-2013-1818.html
- http://helpx.adobe.com/security/products/flash-player/apsb13-28.html
- http://lists.opensuse.org/opensuse-security-announce/2013-12/msg00008.html
- http://lists.opensuse.org/opensuse-updates/2013-12/msg00075.html
- http://lists.opensuse.org/opensuse-updates/2013-12/msg00084.html
- http://rhn.redhat.com/errata/RHSA-2013-1818.html
Modified: 2025-04-11
CVE-2014-0491
Adobe Flash Player before 11.7.700.260 and 11.8.x and 11.9.x before 12.0.0.38 on Windows and Mac OS X and before 11.2.202.335 on Linux, Adobe AIR before 4.0.0.1390, Adobe AIR SDK before 4.0.0.1390, and Adobe AIR SDK & Compiler before 4.0.0.1390 allow attackers to bypass unspecified protection mechanisms via unknown vectors.
- http://helpx.adobe.com/security/products/flash-player/apsb14-02.html
- http://lists.opensuse.org/opensuse-security-announce/2014-01/msg00006.html
- http://rhn.redhat.com/errata/RHSA-2014-0028.html
- http://secunia.com/advisories/56516
- http://secunia.com/advisories/56636
- http://www.securitytracker.com/id/1029602
- http://helpx.adobe.com/security/products/flash-player/apsb14-02.html
- http://lists.opensuse.org/opensuse-security-announce/2014-01/msg00006.html
- http://rhn.redhat.com/errata/RHSA-2014-0028.html
- http://secunia.com/advisories/56516
- http://secunia.com/advisories/56636
- http://www.securitytracker.com/id/1029602
Modified: 2025-04-11
CVE-2014-0492
Adobe Flash Player before 11.7.700.260 and 11.8.x and 11.9.x before 12.0.0.38 on Windows and Mac OS X and before 11.2.202.335 on Linux, Adobe AIR before 4.0.0.1390, Adobe AIR SDK before 4.0.0.1390, and Adobe AIR SDK & Compiler before 4.0.0.1390 allow attackers to defeat the ASLR protection mechanism by leveraging an "address leak."
- http://helpx.adobe.com/security/products/flash-player/apsb14-02.html
- http://lists.opensuse.org/opensuse-security-announce/2014-01/msg00006.html
- http://rhn.redhat.com/errata/RHSA-2014-0028.html
- http://secunia.com/advisories/56516
- http://secunia.com/advisories/56636
- http://www.securitytracker.com/id/1029602
- http://helpx.adobe.com/security/products/flash-player/apsb14-02.html
- http://lists.opensuse.org/opensuse-security-announce/2014-01/msg00006.html
- http://rhn.redhat.com/errata/RHSA-2014-0028.html
- http://secunia.com/advisories/56516
- http://secunia.com/advisories/56636
- http://www.securitytracker.com/id/1029602
Modified: 2025-10-22
CVE-2014-0497
Integer underflow in Adobe Flash Player before 11.7.700.261 and 11.8.x through 12.0.x before 12.0.0.44 on Windows and Mac OS X, and before 11.2.202.336 on Linux, allows remote attackers to execute arbitrary code via unspecified vectors.
- http://googlechromereleases.blogspot.com/2014/02/stable-channel-update.html
- http://helpx.adobe.com/security/products/flash-player/apsb14-04.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00000.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00001.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00006.html
- http://rhn.redhat.com/errata/RHSA-2014-0137.html
- http://secunia.com/advisories/56437
- http://secunia.com/advisories/56737
- http://secunia.com/advisories/56780
- http://secunia.com/advisories/56799
- http://secunia.com/advisories/56839
- http://www.exploit-db.com/exploits/33212
- http://www.osvdb.org/102849
- http://www.securityfocus.com/bid/65327
- http://www.securitytracker.com/id/1029715
- https://exchange.xforce.ibmcloud.com/vulnerabilities/90884
- http://googlechromereleases.blogspot.com/2014/02/stable-channel-update.html
- http://helpx.adobe.com/security/products/flash-player/apsb14-04.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00000.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00001.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00006.html
- http://rhn.redhat.com/errata/RHSA-2014-0137.html
- http://secunia.com/advisories/56437
- http://secunia.com/advisories/56737
- http://secunia.com/advisories/56780
- http://secunia.com/advisories/56799
- http://secunia.com/advisories/56839
- http://www.exploit-db.com/exploits/33212
- http://www.osvdb.org/102849
- http://www.securityfocus.com/bid/65327
- http://www.securitytracker.com/id/1029715
- https://exchange.xforce.ibmcloud.com/vulnerabilities/90884
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2014-0497
Modified: 2025-04-11
CVE-2014-0498
Stack-based buffer overflow in Adobe Flash Player before 11.7.700.269 and 11.8.x through 12.0.x before 12.0.0.70 on Windows and Mac OS X and before 11.2.202.341 on Linux, Adobe AIR before 4.0.0.1628 on Android, Adobe AIR SDK before 4.0.0.1628, and Adobe AIR SDK & Compiler before 4.0.0.1628 allows attackers to execute arbitrary code via unspecified vectors.
- http://helpx.adobe.com/security/products/flash-player/apsb14-07.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00014.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00015.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00017.html
- http://rhn.redhat.com/errata/RHSA-2014-0196.html
- http://security.gentoo.org/glsa/glsa-201405-04.xml
- http://helpx.adobe.com/security/products/flash-player/apsb14-07.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00014.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00015.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00017.html
- http://rhn.redhat.com/errata/RHSA-2014-0196.html
- http://security.gentoo.org/glsa/glsa-201405-04.xml
Modified: 2025-04-11
CVE-2014-0499
Adobe Flash Player before 11.7.700.269 and 11.8.x through 12.0.x before 12.0.0.70 on Windows and Mac OS X and before 11.2.202.341 on Linux, Adobe AIR before 4.0.0.1628 on Android, Adobe AIR SDK before 4.0.0.1628, and Adobe AIR SDK & Compiler before 4.0.0.1628 do not prevent access to address information, which makes it easier for attackers to bypass the ASLR protection mechanism via unspecified vectors.
- http://helpx.adobe.com/security/products/flash-player/apsb14-07.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00014.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00015.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00017.html
- http://rhn.redhat.com/errata/RHSA-2014-0196.html
- http://security.gentoo.org/glsa/glsa-201405-04.xml
- http://helpx.adobe.com/security/products/flash-player/apsb14-07.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00014.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00015.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00017.html
- http://rhn.redhat.com/errata/RHSA-2014-0196.html
- http://security.gentoo.org/glsa/glsa-201405-04.xml
Modified: 2025-10-22
CVE-2014-0502
Double free vulnerability in Adobe Flash Player before 11.7.700.269 and 11.8.x through 12.0.x before 12.0.0.70 on Windows and Mac OS X and before 11.2.202.341 on Linux, Adobe AIR before 4.0.0.1628 on Android, Adobe AIR SDK before 4.0.0.1628, and Adobe AIR SDK & Compiler before 4.0.0.1628 allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in February 2014.
- http://helpx.adobe.com/security/products/flash-player/apsb14-07.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00014.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00015.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00017.html
- http://rhn.redhat.com/errata/RHSA-2014-0196.html
- http://security.gentoo.org/glsa/glsa-201405-04.xml
- http://www.alienvault.com/open-threat-exchange/blog/analysis-of-an-attack-exploiting-the-adobe-zero-day-cve-2014-0502/
- https://volatility-labs.blogspot.com/2014/04/building-decoder-for-cve-2014-0502.html
- http://helpx.adobe.com/security/products/flash-player/apsb14-07.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00014.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00015.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00017.html
- http://rhn.redhat.com/errata/RHSA-2014-0196.html
- http://security.gentoo.org/glsa/glsa-201405-04.xml
- http://www.alienvault.com/open-threat-exchange/blog/analysis-of-an-attack-exploiting-the-adobe-zero-day-cve-2014-0502/
- https://volatility-labs.blogspot.com/2014/04/building-decoder-for-cve-2014-0502.html
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2014-0502
Modified: 2025-04-12
CVE-2014-0503
Adobe Flash Player before 11.7.700.272 and 11.8.x through 12.0.x before 12.0.0.77 on Windows and OS X, and before 11.2.202.346 on Linux, allows remote attackers to bypass the Same Origin Policy via unspecified vectors.
- http://helpx.adobe.com/security/products/flash-player/apsb14-08.html
- http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00013.html
- http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00014.html
- http://rhn.redhat.com/errata/RHSA-2014-0289.html
- http://security.gentoo.org/glsa/glsa-201405-04.xml
- http://helpx.adobe.com/security/products/flash-player/apsb14-08.html
- http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00013.html
- http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00014.html
- http://rhn.redhat.com/errata/RHSA-2014-0289.html
- http://security.gentoo.org/glsa/glsa-201405-04.xml
Modified: 2025-04-12
CVE-2014-0504
Adobe Flash Player before 11.7.700.272 and 11.8.x through 12.0.x before 12.0.0.77 on Windows and OS X, and before 11.2.202.346 on Linux, allows attackers to read the clipboard via unspecified vectors.
- http://helpx.adobe.com/security/products/flash-player/apsb14-08.html
- http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00013.html
- http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00014.html
- http://rhn.redhat.com/errata/RHSA-2014-0289.html
- http://security.gentoo.org/glsa/glsa-201405-04.xml
- http://helpx.adobe.com/security/products/flash-player/apsb14-08.html
- http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00013.html
- http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00014.html
- http://rhn.redhat.com/errata/RHSA-2014-0289.html
- http://security.gentoo.org/glsa/glsa-201405-04.xml