CVE-2014-0515: Flash Player Memory Corruption — Fix & Details
CVE-2014-0515 is a vulnerability of currently unknown severity. Buffer overflow in Adobe Flash Player before 11.7.700.279 and 11.8.x through 13.0.x before 13.0.0.206 on Windows and OS X, and before 11.2.202.356 on Linux, allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in April 2014. EPSS estimates a 94.49% chance of exploitation in the next 30 days.
Description
Buffer overflow in Adobe Flash Player before 11.7.700.279 and 11.8.x through 13.0.x before 13.0.0.206 on Windows and OS X, and before 11.2.202.356 on Linux, allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in April 2014.
Metrics
EPSS Probability 94.49%
99.8th percentile
Probability of exploitation in the next 30 days. Learn more
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Adobe | Flash Player | >= 11.0, < 11.2.202.346 |
| Adobe | Flash Player | >= 11.0, < 11.7.700.279 |
| Adobe | Flash Player | >= 11.8, < 13.0.0.206 |
References
Timeline
Published Apr 29, 2014
Last Modified Jun 17, 2026
Status Modified
Frequently Asked Questions
What is CVE-2014-0515?
How severe is CVE-2014-0515?
Severity scoring for CVE-2014-0515 is pending analysis. The EPSS model estimates a 94.49% probability of exploitation in the next 30 days.
How do I fix CVE-2014-0515?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
Related CVEs from 2014
- CVE-2014-0509 Cross-site scripting (XSS) vulnerability in Adobe Flash Player
- CVE-2014-0510 Heap-based buffer overflow in Adobe Flash Player 12.0.0.77
- CVE-2014-0511 Heap-based buffer overflow in Adobe Reader 11.0.06
- CVE-2014-0512 Adobe Reader 11.0.06 allows attackers to bypass a PDF sandbox
- CVE-2014-0513 Stack-based buffer overflow in Adobe Illustrator CS6 before
- CVE-2014-0514 The Adobe Reader Mobile application before 11.2 for Android
- CVE-2014-0516 Adobe Flash Player before 13.0.0.214
- CVE-2014-0517 Adobe Flash Player before 13.0.0.214
- CVE-2014-0518 Adobe Flash Player before 13.0.0.214
- CVE-2014-0519 Adobe Flash Player before 13.0.0.214
- CVE-2014-0520 Adobe Flash Player before 13.0.0.214
- CVE-2014-0521 Adobe Reader and Acrobat 10.x before 10.1.10 and 11.x before
Source: NVD / NIST