U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Vulnerability Change Records for CVE-2014-5333

Change History

Modified Analysis by NIST 9/22/2015 2:49:11 PM

Action Type Old Value New Value
Changed CPE Configuration
Configuration 1
     OR
          *cpe:2.3:a:adobe:adobe_air_sdk:14.0.0.137:*:*:*:*:*:*:* (and previous)
          *cpe:2.3:a:adobe:adobe_air_sdk:14.0.0.110:*:*:*:*:*:*:*
          *cpe:2.3:a:adobe:adobe_air_sdk:13.0.0.111:*:*:*:*:*:*:*
          *cpe:2.3:a:adobe:adobe_air_sdk:13.0.0.83:*:*:*:*:*:*:*
Configuration 2
     AND
          OR
               *cpe:2.3:a:adobe:flash_player:14.0.0.145:*:*:*:*:*:*:*
               *cpe:2.3:a:adobe:flash_player:14.0.0.125:*:*:*:*:*:*:*
               *cpe:2.3:a:adobe:flash_player:13.0.0.231:*:*:*:*:*:*:* (and previous)
               *cpe:2.3:a:adobe:flash_player:13.0.0.223:*:*:*:*:*:*:*
               *cpe:2.3:a:adobe:flash_player:13.0.0.182:*:*:*:*:*:*:*
               *cpe:2.3:a:adobe:flash_player:13.0.0.201:*:*:*:*:*:*:*
               *cpe:2.3:a:adobe:flash_player:13.0.0.206:*:*:*:*:*:*:*
               *cpe:2.3:a:adobe:flash_player:13.0.0.214:*:*:*:*:*:*:*
          OR
               cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:*
               cpe:2.3:o:microsoft:windows:*:*:*:*:*:*:*:*
Configuration 3
     AND
          OR
               *cpe:2.3:a:adobe:adobe_air:14.0.0.110:*:*:*:*:*:*:* (and previous)
               *cpe:2.3:a:adobe:adobe_air:13.0.0.111:*:*:*:*:*:*:*
               *cpe:2.3:a:adobe:adobe_air:13.0.0.83:*:*:*:*:*:*:*
          OR
               cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:*
               cpe:2.3:o:microsoft:windows:*:*:*:*:*:*:*:*
Configuration 4
     AND
          OR
               *cpe:2.3:a:adobe:flash_player:11.2.202.394:*:*:*:*:*:*:* (and previous)
               *cpe:2.3:a:adobe:flash_player:11.2.202.378:*:*:*:*:*:*:*
               *cpe:2.3:a:adobe:flash_player:11.2.202.356:*:*:*:*:*:*:*
               *cpe:2.3:a:adobe:flash_player:11.2.202.350:*:*:*:*:*:*:*
               *cpe:2.3:a:adobe:flash_player:11.2.202.346:*:*:*:*:*:*:*
               *cpe:2.3:a:adobe:flash_player:11.2.202.341:*:*:*:*:*:*:*
               *cpe:2.3:a:adobe:flash_player:11.2.202.336:*:*:*:*:*:*:*
               *cpe:2.3:a:adobe:flash_player:11.2.202.335:*:*:*:*:*:*:*
               *cpe:2.3:a:adobe:flash_player:11.2.202.332:*:*:*:*:*:*:*
               *cpe:2.3:a:adobe:flash_player:11.2.202.310:*:*:*:*:*:*:*
               *cpe:2.3:a:adobe:flash_player:11.2.202.297:*:*:*:*:*:*:*
               *cpe:2.3:a:adobe:flash_player:11.2.202.291:*:*:*:*:*:*:*
               *cpe:2.3:a:adobe:flash_player:11.2.202.285:*:*:*:*:*:*:*
               *cpe:2.3:a:adobe:flash_player:11.2.202.280:*:*:*:*:*:*:*
               *cpe:2.3:a:adobe:flash_player:11.2.202.275:*:*:*:*:*:*:*
               *cpe:2.3:a:adobe:flash_player:11.2.202.273:*:*:*:*:*:*:*
               *cpe:2.3:a:adobe:flash_player:11.2.202.270:*:*:*:*:*:*:*
               *cpe:2.3:a:adobe:flash_player:11.2.202.262:*:*:*:*:*:*:*
               *cpe:2.3:a:adobe:flash_player:11.2.202.261:*:*:*:*:*:*:*
               *cpe:2.3:a:adobe:flash_player:11.2.202.258:*:*:*:*:*:*:*
               *cpe:2.3:a:adobe:flash_player:11.2.202.251:*:*:*:*:*:*:*
               *cpe:2.3:a:adobe:flash_player:11.2.202.243:*:*:*:*:*:*:*
               *cpe:2.3:a:adobe:flash_player:11.2.202.238:*:*:*:*:*:*:*
               *cpe:2.3:a:adobe:flash_player:11.2.202.236:*:*:*:*:*:*:*
               *cpe:2.3:a:adobe:flash_player:11.2.202.235:*:*:*:*:*:*:*
               *cpe:2.3:a:adobe:flash_player:11.2.202.233:*:*:*:*:*:*:*
               *cpe:2.3:a:adobe:flash_player:11.2.202.228:*:*:*:*:*:*:*
               *cpe:2.3:a:adobe:flash_player:11.2.202.223:*:*:*:*:*:*:*
               *cpe:2.3:a:adobe:flash_player:11.2.202.359:*:*:*:*:*:*:*
          OR
               cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Configuration 5
     AND
          OR
               *cpe:2.3:a:adobe:adobe_air:14.0.0.137:*:*:*:*:*:*:* (and previous)
               *cpe:2.3:a:adobe:adobe_air:14.0.0.110:*:*:*:*:*:*:*
               *cpe:2.3:a:adobe:adobe_air:13.0.0.111:*:*:*:*:*:*:*
               *cpe:2.3:a:adobe:adobe_air:13.0.0.83:*:*:*:*:*:*:*
          OR
               cpe:2.3:o:google:android:*:*:*:*:*:*:*:*
Configuration 1
     AND
          OR
               *cpe:2.3:a:adobe:adobe_air:14.0.0.137:*:*:*:*:*:*:* (and previous)
               *cpe:2.3:a:adobe:adobe_air:14.0.0.110:*:*:*:*:*:*:*
               *cpe:2.3:a:adobe:adobe_air:13.0.0.111:*:*:*:*:*:*:*
               *cpe:2.3:a:adobe:adobe_air:13.0.0.83:*:*:*:*:*:*:*
          OR
               cpe:2.3:o:google:android:*:*:*:*:*:*:*:*
Configuration 2
     AND
          OR
               *cpe:2.3:a:adobe:flash_player:14.0.0.145:*:*:*:*:*:*:*
               *cpe:2.3:a:adobe:flash_player:14.0.0.125:*:*:*:*:*:*:*
               *cpe:2.3:a:adobe:flash_player:13.0.0.231:*:*:*:*:*:*:* (and previous)
               *cpe:2.3:a:adobe:flash_player:13.0.0.223:*:*:*:*:*:*:*
               *cpe:2.3:a:adobe:flash_player:13.0.0.182:*:*:*:*:*:*:*
               *cpe:2.3:a:adobe:flash_player:13.0.0.201:*:*:*:*:*:*:*
               *cpe:2.3:a:adobe:flash_player:13.0.0.206:*:*:*:*:*:*:*
               *cpe:2.3:a:adobe:flash_player:13.0.0.214:*:*:*:*:*:*:*
          OR
               cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:*
               cpe:2.3:o:microsoft:windows:*:*:*:*:*:*:*:*
Configuration 3
     OR
          *cpe:2.3:a:adobe:adobe_air_sdk:14.0.0.137:*:*:*:*:*:*:* (and previous)
          *cpe:2.3:a:adobe:adobe_air_sdk:14.0.0.110:*:*:*:*:*:*:*
          *cpe:2.3:a:adobe:adobe_air_sdk:13.0.0.111:*:*:*:*:*:*:*
          *cpe:2.3:a:adobe:adobe_air_sdk:13.0.0.83:*:*:*:*:*:*:*
Configuration 4
     AND
          OR
               *cpe:2.3:a:adobe:flash_player:11.2.202.394:*:*:*:*:*:*:* (and previous)
               *cpe:2.3:a:adobe:flash_player:11.2.202.378:*:*:*:*:*:*:*
               *cpe:2.3:a:adobe:flash_player:11.2.202.356:*:*:*:*:*:*:*
               *cpe:2.3:a:adobe:flash_player:11.2.202.350:*:*:*:*:*:*:*
               *cpe:2.3:a:adobe:flash_player:11.2.202.346:*:*:*:*:*:*:*
               *cpe:2.3:a:adobe:flash_player:11.2.202.341:*:*:*:*:*:*:*
               *cpe:2.3:a:adobe:flash_player:11.2.202.336:*:*:*:*:*:*:*
               *cpe:2.3:a:adobe:flash_player:11.2.202.335:*:*:*:*:*:*:*
               *cpe:2.3:a:adobe:flash_player:11.2.202.332:*:*:*:*:*:*:*
               *cpe:2.3:a:adobe:flash_player:11.2.202.310:*:*:*:*:*:*:*
               *cpe:2.3:a:adobe:flash_player:11.2.202.297:*:*:*:*:*:*:*
               *cpe:2.3:a:adobe:flash_player:11.2.202.291:*:*:*:*:*:*:*
               *cpe:2.3:a:adobe:flash_player:11.2.202.285:*:*:*:*:*:*:*
               *cpe:2.3:a:adobe:flash_player:11.2.202.280:*:*:*:*:*:*:*
               *cpe:2.3:a:adobe:flash_player:11.2.202.275:*:*:*:*:*:*:*
               *cpe:2.3:a:adobe:flash_player:11.2.202.273:*:*:*:*:*:*:*
               *cpe:2.3:a:adobe:flash_player:11.2.202.270:*:*:*:*:*:*:*
               *cpe:2.3:a:adobe:flash_player:11.2.202.262:*:*:*:*:*:*:*
               *cpe:2.3:a:adobe:flash_player:11.2.202.261:*:*:*:*:*:*:*
               *cpe:2.3:a:adobe:flash_player:11.2.202.258:*:*:*:*:*:*:*
               *cpe:2.3:a:adobe:flash_player:11.2.202.251:*:*:*:*:*:*:*
               *cpe:2.3:a:adobe:flash_player:11.2.202.243:*:*:*:*:*:*:*
               *cpe:2.3:a:adobe:flash_player:11.2.202.238:*:*:*:*:*:*:*
               *cpe:2.3:a:adobe:flash_player:11.2.202.236:*:*:*:*:*:*:*
               *cpe:2.3:a:adobe:flash_player:11.2.202.235:*:*:*:*:*:*:*
               *cpe:2.3:a:adobe:flash_player:11.2.202.233:*:*:*:*:*:*:*
               *cpe:2.3:a:adobe:flash_player:11.2.202.228:*:*:*:*:*:*:*
               *cpe:2.3:a:adobe:flash_player:11.2.202.223:*:*:*:*:*:*:*
               *cpe:2.3:a:adobe:flash_player:11.2.202.359:*:*:*:*:*:*:*
          OR
               cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Configuration 5
     AND
          OR
               *cpe:2.3:a:adobe:adobe_air:14.0.0.110:*:*:*:*:*:*:* (and previous)
               *cpe:2.3:a:adobe:adobe_air:13.0.0.111:*:*:*:*:*:*:*
               *cpe:2.3:a:adobe:adobe_air:13.0.0.83:*:*:*:*:*:*:*
          OR
               cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:*
               cpe:2.3:o:microsoft:windows:*:*:*:*:*:*:*:*
Changed CVSS V2
(AV:N/AC:M/Au:N/C:P/I:P/A:P)
(AV:N/AC:M/Au:N/C:P/I:N/A:N)
Changed Description
Adobe Flash Player before 13.0.0.241 and 14.x before 14.0.0.176 on Windows and OS X and before 11.2.202.400 on Linux, Adobe AIR before 14.0.0.178 on Windows and OS X and before 14.0.0.179 on Android, Adobe AIR SDK before 14.0.0.178, and Adobe AIR SDK & Compiler before 14.0.0.178 do not properly restrict the SWF file format, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks against JSONP endpoints, and obtain sensitive information, via a crafted OBJECT element with SWF content satisfying the character-set requirements of a callback API, in conjunction with a manipulation involving a '$' (dollar sign) or '(' (open parenthesis) character. NOTE: this issue exists because of an incomplete fix for CVE-2014-4671.
Adobe Flash Player before 13.0.0.241 and 14.x before 14.0.0.176 on Windows and OS X and before 11.2.202.400 on Linux, Adobe AIR before 14.0.0.178 on Windows and OS X and before 14.0.0.179 on Android, Adobe AIR SDK before 14.0.0.178, and Adobe AIR SDK & Compiler before 14.0.0.178 do not properly restrict the SWF file format, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks against JSONP endpoints, and obtain sensitive information, via a crafted OBJECT element with SWF content satisfying the character-set requirements of a callback API, in conjunction with a manipulation involving a '{1}apos; (dollar sign) or '(' (open parenthesis) character. NOTE: this issue exists because of an incomplete fix for CVE-2014-4671.