CVE-2014-0515 is a vulnerability of currently unknown severity. Buffer overflow in Adobe Flash Player before 11.7.700.279 and 11.8.x through 13.0.x before 13.0.0.206 on Windows and OS X, and before 11.2.202.356 on Linux, allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in April 2014. EPSS estimates a 94.49% chance of exploitation in the next 30 days.

## Description

Buffer overflow in Adobe Flash Player before 11.7.700.279 and 11.8.x through 13.0.x before 13.0.0.206 on Windows and OS X, and before 11.2.202.356 on Linux, allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in April 2014.

## Metrics

EPSS Probability 94.49%

99.8th percentile

Probability of exploitation in the next 30 days. [Learn more](https://www.first.org/epss/)

## Weakness Enumeration

- [CWE-119](https://cwe.mitre.org/data/definitions/119.html)

## Affected Software

| Vendor | Product | Versions |
| --- | --- | --- |
| Adobe | Flash Player | >= 11.0, < 11.2.202.346 |
| Adobe | Flash Player | >= 11.0, < 11.7.700.279 |
| Adobe | Flash Player | >= 11.8, < 13.0.0.206 |

## References

- [Patch, Vendor Advisory](https://helpx.adobe.com/security/products/flash-player/apsb14-13.html)

- [Mailing List, Third Party Advisory](https://lists.opensuse.org/opensuse-security-announce/2014-04/msg00017.html)

- [Mailing List, Third Party Advisory](https://lists.opensuse.org/opensuse-security-announce/2014-05/msg00000.html)

- [Mailing List, Third Party Advisory](https://lists.opensuse.org/opensuse-security-announce/2014-05/msg00001.html)

- [Third Party Advisory](https://rhn.redhat.com/errata/RHSA-2014-0447.html)

- [Third Party Advisory](https://security.gentoo.org/glsa/glsa-201405-04.xml)

- [Third Party Advisory, VDB Entry](https://www.securityfocus.com/bid/67092)

- [Third Party Advisory, VDB Entry](https://www.securitytracker.com/id/1030155)

## Timeline

Published Apr 29, 2014

Last Modified Jun 17, 2026

Status Modified

## Frequently Asked Questions

### What is CVE-2014-0515?

### How severe is CVE-2014-0515?

Severity scoring for CVE-2014-0515 is pending analysis. The EPSS model estimates a 94.49% probability of exploitation in the next 30 days.

### How do I fix CVE-2014-0515?

Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also [run a Strix scan](https://app.strix.ai/) to test if your systems are affected.

## Related CVEs from 2014

- [CVE-2014-0509](/content/cve/CVE-2014-0509/index.html) Cross-site scripting (XSS) vulnerability in Adobe Flash Player
- [CVE-2014-0510](/content/cve/CVE-2014-0510/index.html) Heap-based buffer overflow in Adobe Flash Player 12.0.0.77
- [CVE-2014-0511](/content/cve/CVE-2014-0511/index.html) Heap-based buffer overflow in Adobe Reader 11.0.06
- [CVE-2014-0512](/content/cve/CVE-2014-0512/index.html) Adobe Reader 11.0.06 allows attackers to bypass a PDF sandbox
- [CVE-2014-0513](/content/cve/CVE-2014-0513/index.html) Stack-based buffer overflow in Adobe Illustrator CS6 before
- [CVE-2014-0514](/content/cve/CVE-2014-0514/index.html) The Adobe Reader Mobile application before 11.2 for Android
- [CVE-2014-0516](/content/cve/CVE-2014-0516/index.html) Adobe Flash Player before 13.0.0.214
- [CVE-2014-0517](/content/cve/CVE-2014-0517/index.html) Adobe Flash Player before 13.0.0.214
- [CVE-2014-0518](/content/cve/CVE-2014-0518/index.html) Adobe Flash Player before 13.0.0.214
- [CVE-2014-0519](/content/cve/CVE-2014-0519/index.html) Adobe Flash Player before 13.0.0.214
- [CVE-2014-0520](/content/cve/CVE-2014-0520/index.html) Adobe Flash Player before 13.0.0.214
- [CVE-2014-0521](/content/cve/CVE-2014-0521/index.html) Adobe Reader and Acrobat 10.x before 10.1.10 and 11.x before

Source: [NVD / NIST](https://nvd.nist.gov/vuln/detail/CVE-2014-0515)
