Skip to main content

CVE detail

CVE-2014-0515

Buffer overflow in Adobe Flash Player before 11.7.700.279 and 11.8.x through 13.0.x before 13.0.0.206 on Windows and OS X, and before 11.2.202.356 on Linux, allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in April 2014.

CVSS 10.0 · CriticalBuzz score 36.6

Buzz score

Why this CVE is surfacing

Buzz score total 36.6

This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.

Buzz score components · mention 27.1 · diversity 9.5 · KEV 0.0 · OTX 0.0 · PoC 0.0
Mention score
27.1
14 evidence mentions in the snapshot
Diversity score
9.5
4 sources across 1 categories
KEV score
0.0
No KEV entry observed
OTX score
0.0
0 OTX pulses
PoC score
0.0
0 repos · best confidence N/A
Best PoC traction
0
Maximum stars on a matched PoC repo

Why it matters now

Mention timeline

Total mentions
0
within the 30d window
Peak daily
0
highest bucket

Evidence

Source links by recency

Newest mentions first
14 source links · newest first
  • The evolutions of APT28 attacksSecurity Affairs

    Analyzing how tactics, techniques and procedures of the Russia-linked APT28 cyberespionage group evolve over the time. APT28 is a well known Russian cyber espionage group attributed, with a medium level of confidence, to Russian military intelligence agency GRU (by CrowdStrike). It is also known as Sofacy Group (by Kaspersky) or STRONTIUM (by Microsoft) and it’s used to target Aereospace, Defence, Governmente Agencies, International […]

    newssecurityaffairs.comDec 5, 2019, 6:41 AM
  • New Terror Exploit Kit EmergesSecurityWeek

    After the fall of the Nuclear and Angler exploit kits (EKs), overall activity generated from exploit kits has dropped to only a fraction of what used to be.

    newswww.securityweek.comJan 10, 2017, 4:59 PM
  • Researchers at security firms ESET and Cyphort continue to analyze the malware families believed to have been developed by a French intelligence agency. The latest threat uncovered by experts has been dubbed “Casper.”

    newswww.securityweek.comMar 6, 2015, 12:23 PM
  • 2014 and Beyond Online Threat ReportMalwarebytes Labs

    As the end of 2014 is approaching, it is time to look back at some of the big security threats and…

    newswww.malwarebytes.comDec 18, 2014, 5:00 PM
  • Researchers at Trend Micro have spotted a campaign in which attackers abuse advertising networks and the Flashpack exploit kit in an effort to distribute various pieces of malware, including the information-stealing malware Zeus, the Dofoil Trojan, and the Cryptowall ransomware.

    newswww.securityweek.comNov 18, 2014, 7:38 PM
  • Last week we uncovered a large-scale malvertising attack involving Google’s DoubleClick and Zedo that affected many high-profile sites.Unfortunately, another incident where DoubleClick…

    newswww.malwarebytes.comSep 29, 2014, 5:00 PM
  • We came across a strange new exploitation pattern recently where the payload appeared to be distributed without going through the typical process.With…

    newswww.malwarebytes.comSep 21, 2014, 5:00 PM
  • Update (07/29/2014): Following our notification, the developers in charge of SocialBlade.com have investigated and identified the source of the compromise. The…

    newswww.malwarebytes.comJul 28, 2014, 5:00 PM
  • After analyzing public vulnerabilities and exploit trends in the first half of 2014, Bromium Labs concluded that Internet Explorer is the “sweet spot for attackers.” “Internet Explorer was the most patched and also one of the most exploited products,” the report (pdf) states. Microsoft’s browser “set a record high for reported vulnerabilities in the first […]

    newswww.csoonline.comJul 23, 2014, 3:23 PM
  • A cunning way to deliver malwareMalwarebytes Labs

    Potentially unwanted programs, also known as PUPs, continue to be a real nuisance. A recent blog post by Will Dormann on CERT.org…

    newswww.malwarebytes.comJul 10, 2014, 5:00 PM
  • Researchers at Symantec recently discovered that poplar video-sharing site Dailymotion was redirecting users to the Sweet Orange exploit kit. For its victims, the Sweet Orange kit may be sour to taste. The kit exploits vulnerabilities in Internet Explorer, Java and Adobe Flash Player. The researchers discovered the infection June 28. The site was cleaned last week, and is no longer infected.

    newswww.securityweek.comJul 7, 2014, 4:55 PM
  • 0 0 1 9 57 Wired 1 1 65 14.0 Normal 0 false false false EN-US JA X-NONE Attackers Have High Hopes for Success Around 2014 World Cup Similar to the Sochi 2014 Olympics and all other major sporting events before it, the FIFA World Cup 2014 in Brazil is being leveraged by cybercriminals and scammers as a means to lure victims for their attacks. In recent months, several security vendors have published advisories about the various scams, phishing and malware operations that target Internet users interested in the World Cup. While individuals from all over the world have been targeted, many of the malicious campaigns focus on Brazil and neighboring South American countries. Malware Cybercriminals are relying on the FIFA World Cup to trick users into installing malware on their computers. Trend Micro discovered a campaign targeting customers of a Brazilian ticketing website, where the attackers managed to obtain the personal details of the site’s users and sent them fake raffle emails conta…

    newswww.securityweek.comJun 11, 2014, 4:13 PM
  • Adobe has just released a security updates for Flash Player to fix critical vulnerabilities that are being exploited by hackers to track Syrian dissidents. Adobe has just released security updates for Flash Player to fix critical vulnerabilities that are being exploited in a series of cyber attacks targeting Syrian dissidents complaining about the government. Early April experts at […]

    newssecurityaffairs.comApr 29, 2014, 3:05 PM
  • Adobe has released security updates for its Adobe Flash Player to address vulnerabilities that are being exploited in the wild.

    newswww.securityweek.comApr 28, 2014, 5:31 PM

Exploit code

Public exploit repository references

Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.

0 repository references · best confidence N/A · max 0 stars
No public PoC repositories have been matched yet.

Related records

Similar CVEs

6 related CVEs with shared weakness or product evidence