CVE Database
/

CVE-2014-4671

Back to search

CVE-2014-4671

Published: Jul 9, 2014

Modified: Aug 6, 2024

PUBLISHED

Description

Adobe Flash Player before 13.0.0.231 and 14.x before 14.0.0.145 on Windows and OS X and before 11.2.202.394 on Linux, Adobe AIR before 14.0.0.137 on Android, Adobe AIR SDK before 14.0.0.137, and Adobe AIR SDK & Compiler before 14.0.0.137 do not properly restrict the SWF file format, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks against JSONP endpoints, and obtain sensitive information, via a crafted OBJECT element with SWF content satisfying the character-set requirements of a callback API.

VendorProductVersions

n/a

n/a

affected
n/a

References

RHSA-2014:0860
vendor-advisory
x_refsource_REDHAT
68457
vdb-entry
x_refsource_BID
59774
third-party-advisory
x_refsource_SECUNIA
1030533
vdb-entry
x_refsource_SECTRACK
59837
third-party-advisory
x_refsource_SECUNIA
GLSA-201407-02
vendor-advisory
x_refsource_GENTOO

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now