High severity8.8CISA KEVNVD Advisory· Published Nov 25, 2014· Updated Apr 21, 2026
CVE-2014-8439
CVE-2014-8439
Description
Adobe Flash Player before 13.0.0.258 and 14.x and 15.x before 15.0.0.239 on Windows and OS X and before 11.2.202.424 on Linux, Adobe AIR before 15.0.0.293, Adobe AIR SDK before 15.0.0.302, and Adobe AIR SDK & Compiler before 15.0.0.302 allow attackers to execute arbitrary code or cause a denial of service (invalid pointer dereference) via unspecified vectors.
Affected products
4Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
12- helpx.adobe.com/security/products/flash-player/apsb14-22.htmlnvdVendor Advisory
- helpx.adobe.com/security/products/flash-player/apsb14-26.htmlnvdVendor Advisory
- lists.opensuse.org/opensuse-security-announce/2014-11/msg00020.htmlnvdThird Party Advisory
- lists.opensuse.org/opensuse-security-announce/2014-12/msg00001.htmlnvdThird Party Advisory
- lists.opensuse.org/opensuse-security-announce/2014-12/msg00004.htmlnvdThird Party Advisory
- rhn.redhat.com/errata/RHSA-2014-1915.htmlnvdVendor Advisory
- www.securityfocus.com/bid/71289nvdThird Party AdvisoryVDB Entry
- www.securitytracker.com/id/1031259nvdThird Party AdvisoryVDB Entry
- exchange.xforce.ibmcloud.com/vulnerabilities/98932nvdThird Party AdvisoryVDB Entry
- www.f-secure.com/weblog/archives/00002768.htmlnvdThird Party Advisory
- secunia.com/advisories/60217nvdPermissions Required
- www.cisa.gov/known-exploited-vulnerabilities-catalognvdUS Government Resource
News mentions
0No linked articles in our index yet.