CVE-2014-0564: Flash Player Vulnerability — Fix & Details
CVE-2014-0564 is a vulnerability of currently unknown severity. Adobe Flash Player before 13.0.0.250 and 14.x and 15.x before 15.0.0.189 on Windows and OS X and before 11.2.202.411 on Linux, Adobe AIR before 15.0.0.293, Adobe AIR SDK before 15.0.0.302, and Adobe AIR SDK & Compiler before 15.0.0.302 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2014-0558. EPSS estimates a 6.19% chance of exploitation in the next 30 days.
Description
Adobe Flash Player before 13.0.0.250 and 14.x and 15.x before 15.0.0.189 on Windows and OS X and before 11.2.202.411 on Linux, Adobe AIR before 15.0.0.293, Adobe AIR SDK before 15.0.0.302, and Adobe AIR SDK & Compiler before 15.0.0.302 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2014-0558.
Metrics
EPSS Probability 6.19%
92.6th percentile
Probability of exploitation in the next 30 days. Learn more
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Adobe | Flash Player | <= 11.2.202.406 | — |
| Adobe | Flash Player | <= 13.0.0.244 | — |
| Adobe | Flash Player | <= 15.0.0.152 | — |
| Adobe | Flash Player | <= 15.0.0.167 | — |
| Adobe | Flash Player Desktop Runtime | <= 15.0.0.167 | — |
| Adobe | Air Desktop Runtime | <= 15.0.0.249 | — |
| Adobe | Air Sdk | <= 15.0.0.249 | — |
| Adobe | Air Sdk | <= 15.0.0.252 | — |
| Opensuse | Evergreen | 11.4 | — |
| Opensuse | Opensuse | 12.3 | — |
| Opensuse | Opensuse | 13.1 | — |
| Suse | Linux Enterprise Desktop | 11 | Sp3 |
References
- Patch, Vendor Advisory
- Mailing List, Third Party Advisory
- Mailing List, Third Party Advisory
- Mailing List, Third Party Advisory
- Broken Link
- Third Party Advisory
- Third Party Advisory, VDB Entry
Timeline
Published Oct 15, 2014
Last Modified Jun 17, 2026
Status Modified
Frequently Asked Questions
What is CVE-2014-0564?
Adobe Flash Player before 13.0.0.250 and 14.x and 15.x before 15.0.0.189 on Windows and OS X and before 11.2.202.411 on Linux, Adobe AIR before 15.0.0.293, Adobe AIR SDK before 15.0.0.302, and Adobe AIR SDK & Compiler before 15.0.0.302 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2014-0558.
How severe is CVE-2014-0564?
Severity scoring for CVE-2014-0564 is pending analysis. The EPSS model estimates a 6.19% probability of exploitation in the next 30 days.
How do I fix CVE-2014-0564?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.