Show plain JSON{"dataType": "CVE_RECORD", "containers": {"adp": [{"title": "CVE Program Container", "references": [{"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/98932", "name": "adobe-flash-cve20148439-code-exec(98932)", "tags": ["vdb-entry", "x_refsource_XF", "x_transferred"]}, {"url": "https://www.f-secure.com/weblog/archives/00002768.html", "tags": ["x_refsource_CONFIRM", "x_transferred"]}, {"url": "http://www.securitytracker.com/id/1031259", "name": "1031259", "tags": ["vdb-entry", "x_refsource_SECTRACK", "x_transferred"]}, {"url": "http://lists.opensuse.org/opensuse-security-announce/2014-12/msg00004.html", "name": "openSUSE-SU-2014:1562", "tags": ["vendor-advisory", "x_refsource_SUSE", "x_transferred"]}, {"url": "http://www.securityfocus.com/bid/71289", "name": "71289", "tags": ["vdb-entry", "x_refsource_BID", "x_transferred"]}, {"url": "http://secunia.com/advisories/60217", "name": "60217", "tags": ["third-party-advisory", "x_refsource_SECUNIA", "x_transferred"]}, {"url": "http://lists.opensuse.org/opensuse-security-announce/2014-12/msg00001.html", "name": "SUSE-SU-2014:1545", "tags": ["vendor-advisory", "x_refsource_SUSE", "x_transferred"]}, {"url": "http://lists.opensuse.org/opensuse-security-announce/2014-11/msg00020.html", "name": "openSUSE-SU-2014:1508", "tags": ["vendor-advisory", "x_refsource_SUSE", "x_transferred"]}, {"url": "http://rhn.redhat.com/errata/RHSA-2014-1915.html", "name": "RHSA-2014:1915", "tags": ["vendor-advisory", "x_refsource_REDHAT", "x_transferred"]}, {"url": "http://helpx.adobe.com/security/products/flash-player/apsb14-22.html", "tags": ["x_refsource_CONFIRM", "x_transferred"]}, {"url": "http://helpx.adobe.com/security/products/flash-player/apsb14-26.html", "tags": ["x_refsource_CONFIRM", "x_transferred"]}], "providerMetadata": {"orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE", "dateUpdated": "2024-08-06T13:18:48.309Z"}}, {"title": "CISA ADP Vulnrichment", "metrics": [{"cvssV3_1": {"scope": "UNCHANGED", "version": "3.1", "baseScore": 8.8, "attackVector": "NETWORK", "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "integrityImpact": "HIGH", "userInteraction": "REQUIRED", "attackComplexity": "LOW", "availabilityImpact": "HIGH", "privilegesRequired": "NONE", "confidentialityImpact": "HIGH"}}, {"other": {"type": "ssvc", "content": {"id": "CVE-2014-8439", "role": "CISA Coordinator", "options": [{"Exploitation": "active"}, {"Automatable": "no"}, {"Technical Impact": "total"}], "version": "2.0.3", "timestamp": "2025-02-10T21:01:00.256036Z"}}}, {"other": {"type": "kev", "content": {"dateAdded": "2022-05-25", "reference": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?search_api_fulltext=CVE-2014-8439"}}}], "problemTypes": [{"descriptions": [{"lang": "en", "type": "CWE", "cweId": "CWE-416", "description": "CWE-416 Use After Free"}]}], "providerMetadata": {"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP", "dateUpdated": "2025-02-10T21:00:33.489Z"}, "timeline": [{"lang": "en", "time": "2022-05-25T00:00:00+00:00", "value": "CVE-2014-8439 added to CISA KEV"}]}], "cna": {"affected": [{"vendor": "n/a", "product": "n/a", "versions": [{"status": "affected", "version": "n/a"}]}], "datePublic": "2014-11-25T00:00:00.000Z", "references": [{"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/98932", "name": "adobe-flash-cve20148439-code-exec(98932)", "tags": ["vdb-entry", "x_refsource_XF"]}, {"url": "https://www.f-secure.com/weblog/archives/00002768.html", "tags": ["x_refsource_CONFIRM"]}, {"url": "http://www.securitytracker.com/id/1031259", "name": "1031259", "tags": ["vdb-entry", "x_refsource_SECTRACK"]}, {"url": "http://lists.opensuse.org/opensuse-security-announce/2014-12/msg00004.html", "name": "openSUSE-SU-2014:1562", "tags": ["vendor-advisory", "x_refsource_SUSE"]}, {"url": "http://www.securityfocus.com/bid/71289", "name": "71289", "tags": ["vdb-entry", "x_refsource_BID"]}, {"url": "http://secunia.com/advisories/60217", "name": "60217", "tags": ["third-party-advisory", "x_refsource_SECUNIA"]}, {"url": "http://lists.opensuse.org/opensuse-security-announce/2014-12/msg00001.html", "name": "SUSE-SU-2014:1545", "tags": ["vendor-advisory", "x_refsource_SUSE"]}, {"url": "http://lists.opensuse.org/opensuse-security-announce/2014-11/msg00020.html", "name": "openSUSE-SU-2014:1508", "tags": ["vendor-advisory", "x_refsource_SUSE"]}, {"url": "http://rhn.redhat.com/errata/RHSA-2014-1915.html", "name": "RHSA-2014:1915", "tags": ["vendor-advisory", "x_refsource_REDHAT"]}, {"url": "http://helpx.adobe.com/security/products/flash-player/apsb14-22.html", "tags": ["x_refsource_CONFIRM"]}, {"url": "http://helpx.adobe.com/security/products/flash-player/apsb14-26.html", "tags": ["x_refsource_CONFIRM"]}], "descriptions": [{"lang": "en", "value": "Adobe Flash Player before 13.0.0.258 and 14.x and 15.x before 15.0.0.239 on Windows and OS X and before 11.2.202.424 on Linux, Adobe AIR before 15.0.0.293, Adobe AIR SDK before 15.0.0.302, and Adobe AIR SDK & Compiler before 15.0.0.302 allow attackers to execute arbitrary code or cause a denial of service (invalid pointer dereference) via unspecified vectors."}], "problemTypes": [{"descriptions": [{"lang": "en", "type": "text", "description": "n/a"}]}], "providerMetadata": {"orgId": "078d4453-3bcd-4900-85e6-15281da43538", "shortName": "adobe", "dateUpdated": "2017-09-07T15:57:01.000Z"}, "x_legacyV4Record": {"affects": {"vendor": {"vendor_data": [{"product": {"product_data": [{"version": {"version_data": [{"version_value": "n/a"}]}, "product_name": "n/a"}]}, "vendor_name": "n/a"}]}}, "data_type": "CVE", "references": {"reference_data": [{"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/98932", "name": "adobe-flash-cve20148439-code-exec(98932)", "refsource": "XF"}, {"url": "https://www.f-secure.com/weblog/archives/00002768.html", "name": "https://www.f-secure.com/weblog/archives/00002768.html", "refsource": "CONFIRM"}, {"url": "http://www.securitytracker.com/id/1031259", "name": "1031259", "refsource": "SECTRACK"}, {"url": "http://lists.opensuse.org/opensuse-security-announce/2014-12/msg00004.html", "name": "openSUSE-SU-2014:1562", "refsource": "SUSE"}, {"url": "http://www.securityfocus.com/bid/71289", "name": "71289", "refsource": "BID"}, {"url": "http://secunia.com/advisories/60217", "name": "60217", "refsource": "SECUNIA"}, {"url": "http://lists.opensuse.org/opensuse-security-announce/2014-12/msg00001.html", "name": "SUSE-SU-2014:1545", "refsource": "SUSE"}, {"url": "http://lists.opensuse.org/opensuse-security-announce/2014-11/msg00020.html", "name": "openSUSE-SU-2014:1508", "refsource": "SUSE"}, {"url": "http://rhn.redhat.com/errata/RHSA-2014-1915.html", "name": "RHSA-2014:1915", "refsource": "REDHAT"}, {"url": "http://helpx.adobe.com/security/products/flash-player/apsb14-22.html", "name": "http://helpx.adobe.com/security/products/flash-player/apsb14-22.html", "refsource": "CONFIRM"}, {"url": "http://helpx.adobe.com/security/products/flash-player/apsb14-26.html", "name": "http://helpx.adobe.com/security/products/flash-player/apsb14-26.html", "refsource": "CONFIRM"}]}, "data_format": "MITRE", "description": {"description_data": [{"lang": "eng", "value": "Adobe Flash Player before 13.0.0.258 and 14.x and 15.x before 15.0.0.239 on Windows and OS X and before 11.2.202.424 on Linux, Adobe AIR before 15.0.0.293, Adobe AIR SDK before 15.0.0.302, and Adobe AIR SDK & Compiler before 15.0.0.302 allow attackers to execute arbitrary code or cause a denial of service (invalid pointer dereference) via unspecified vectors."}]}, "problemtype": {"problemtype_data": [{"description": [{"lang": "eng", "value": "n/a"}]}]}, "data_version": "4.0", "CVE_data_meta": {"ID": "CVE-2014-8439", "STATE": "PUBLIC", "ASSIGNER": "psirt@adobe.com"}}}}, "cveMetadata": {"cveId": "CVE-2014-8439", "state": "PUBLISHED", "dateUpdated": "2025-07-28T19:45:39.576Z", "dateReserved": "2014-10-22T00:00:00.000Z", "assignerOrgId": "078d4453-3bcd-4900-85e6-15281da43538", "datePublished": "2014-11-25T23:00:00.000Z", "assignerShortName": "adobe"}, "dataVersion": "5.1"}