Buffer overflow in Adobe Flash Player before 11.7.700.279 and 11.8.x through 13.0.x before 13.0.0.206 on Windows and OS X, and before 11.2.202.356 on Linux, allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in April 2014.
Conclusion & alert: CVE-2014-0515 is rated High Exploit Risk (91.6/100): CVSS Critical severity, with high exploitation likelihood (EPSS 94.49%, 100th percentile). Core evidence: 1 public exploit reference(s) are indexed (Exploit-DB). EPSS rose +1.63% over the last day, indicating growing attacker interest. Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
| EDB-ID | Source | Kind | Published | Link |
|---|---|---|---|---|
| 33333 | exploit_db | edb | 2014-05-12 | Exploit-DB ↗ |
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 92.85% | 94.49% | +1.63% |
| 2 | 2026-05-24 | 92.65% | 92.85% | +0.20% |
| 3 | 2026-04-01 | — | 92.65% | — |
Full EPSS history (20 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 10.0 | 2.0 | HIGH |
|
10.0 | 10.0 | [email protected] |
| vendor | priority | summary | link |
|---|---|---|---|
gentoo
|
normal | CVE-2014-0515: 1 GLSA(s) (201405-04), 1 atom(s) (www-plugins/adobe-flash); latest impact normal. | https://bugs.gentoo.org/buglist.cgi?quicksearch=CVE-2014-0515 |
redhat
|
critical | — | https://access.redhat.com/security/cve/CVE-2014-0515 |
ubuntu
|
medium | CVE-2014-0515 medium priority: Ubuntu including 2 source packages (adobe-flashplugin, flashplugin-nonfree), 12 status rows across 6 suites (lucid, precise, quantal, saucy, trusty, upstream): released 9, ignored 2, needs-triage 1. | https://ubuntu.com/security/CVE-2014-0515 |
: Per: http://helpx.adobe.com/security/products/flash-player/apsb14-13.html "Affected software versions Adobe Flash Player 13.0.0.182 and earlier versions for Windows Adobe Flash Player 13.0.0.201 and earlier versions for Macintosh Adobe Flash Player 11.2.202.350 and earlier versions for Linux"
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| adobe | flash_player | >= 11.0, < 11.2.202.346 | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:* |
| adobe | flash_player | >= 11.0, < 11.7.700.279 | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:* |
| adobe | flash_player | >= 11.8, < 13.0.0.206 | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| http://helpx.adobe.com/security/products/flash-player/apsb14-13.html | Patch Vendor Advisory |
| http://lists.opensuse.org/opensuse-security-announce/2014-04/msg00017.html | Mailing List Third Party Advisory |
| http://lists.opensuse.org/opensuse-security-announce/2014-05/msg00000.html | Mailing List Third Party Advisory |
| http://lists.opensuse.org/opensuse-security-announce/2014-05/msg00001.html | Mailing List Third Party Advisory |
| http://rhn.redhat.com/errata/RHSA-2014-0447.html | Third Party Advisory |
| http://security.gentoo.org/glsa/glsa-201405-04.xml | Third Party Advisory |
| http://www.securityfocus.com/bid/67092 | Third Party Advisory VDB Entry |
| http://www.securitytracker.com/id/1030155 | Third Party Advisory VDB Entry |