Double free vulnerability in Adobe Flash Player before 11.7.700.269 and 11.8.x through 12.0.x before 12.0.0.70 on Windows and Mac OS X and before 11.2.202.341 on Linux, Adobe AIR before 4.0.0.1628 on Android, Adobe AIR SDK before 4.0.0.1628, and Adobe AIR SDK & Compiler before 4.0.0.1628 allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in February 2014.
| Software | From | Fixed in |
|---|---|---|
| adobe / adobe_air_sdk | - | 4.0.0.1628 |
| adobe / adobe_air | - | 4.0.0.1628 |
| adobe / flash_player | - | 11.7.700.269 |
| adobe / flash_player | 11.8.800.94 | 12.0.0.70 |
| adobe / flash_player | - | 11.2.202.341 |
| opensuse / opensuse | 11.4 | 11.4.x |
| opensuse / opensuse | 12.3 | 12.3.x |
| opensuse / opensuse | 13.1 | 13.1.x |
| suse / linux_enterprise_desktop | 11-sp3 | 11-sp3.x |
| redhat / enterprise_linux_desktop | 5.0 | 5.0.x |
| redhat / enterprise_linux_desktop | 6.0 | 6.0.x |
| redhat / enterprise_linux_eus | 6.5 | 6.5.x |
| redhat / enterprise_linux_server | 5.0 | 5.0.x |
| redhat / enterprise_linux_server | 6.0 | 6.0.x |
| redhat / enterprise_linux_server_aus | 6.5 | 6.5.x |
| redhat / enterprise_linux_workstation | 5.0 | 5.0.x |
| redhat / enterprise_linux_workstation | 6.0 | 6.0.x |