Vulnerability Database

383,371

Total vulnerabilities in the database

CVE-2014-0559 — adobe / adobe_air

Improper Restriction of Operations within the Bounds of a Memory Buffer

Heap-based buffer overflow in Adobe Flash Player before 13.0.0.244 and 14.x and 15.x before 15.0.0.152 on Windows and OS X and before 11.2.202.406 on Linux, Adobe AIR before 15.0.0.249 on Windows and OS X and before 15.0.0.252 on Android, Adobe AIR SDK before 15.0.0.249, and Adobe AIR SDK & Compiler before 15.0.0.249 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2014-0556.

  • Published: Sep 10, 2014
  • Updated: Sep 13, 2026
  • CVE: CVE-2014-0559
  • Severity: High
  • Exploit:
  • CISA KEV:

CVSS v2:

  • Severity: High
  • Score: 10
  • AV:N/AC:L/Au:N/C:C/I:C/A:C

CWEs:

Software Affected versions
adobe / adobe_air <= 14.0.0.178
adobe / adobe_air = 13.0.0.83
adobe / adobe_air = 13.0.0.111
adobe / adobe_air = 14.0.0.110
adobe / adobe_air = 14.0.0.137
adobe / flash_player <= 13.0.0.241
adobe / flash_player = 13.0.0.182
adobe / flash_player = 13.0.0.201
adobe / flash_player = 13.0.0.206
adobe / flash_player = 13.0.0.214
adobe / flash_player = 13.0.0.223
adobe / flash_player = 13.0.0.231
adobe / flash_player = 14.0.0.125
adobe / flash_player = 14.0.0.145
adobe / flash_player = 14.0.0.176
adobe / flash_player = 14.0.0.179
adobe / flash_player = 15.0.0.144
adobe / adobe_air_sdk <= 14.0.0.178
adobe / adobe_air_sdk = 13.0.0.83
adobe / adobe_air_sdk = 13.0.0.111
adobe / adobe_air_sdk = 14.0.0.110
adobe / adobe_air_sdk = 14.0.0.137
adobe / adobe_air <= 14.0.0.179
adobe / flash_player <= 11.2.202.400
adobe / flash_player = 11.2.202.223
adobe / flash_player = 11.2.202.228
adobe / flash_player = 11.2.202.233
adobe / flash_player = 11.2.202.235
adobe / flash_player = 11.2.202.236
adobe / flash_player = 11.2.202.238
adobe / flash_player = 11.2.202.243
adobe / flash_player = 11.2.202.251
adobe / flash_player = 11.2.202.258
adobe / flash_player = 11.2.202.261
adobe / flash_player = 11.2.202.262
adobe / flash_player = 11.2.202.270
adobe / flash_player = 11.2.202.273
adobe / flash_player = 11.2.202.275
adobe / flash_player = 11.2.202.280
adobe / flash_player = 11.2.202.285
adobe / flash_player = 11.2.202.291
adobe / flash_player = 11.2.202.297
adobe / flash_player = 11.2.202.310
adobe / flash_player = 11.2.202.332
adobe / flash_player = 11.2.202.335
adobe / flash_player = 11.2.202.336
adobe / flash_player = 11.2.202.341
adobe / flash_player = 11.2.202.346
adobe / flash_player = 11.2.202.350
adobe / flash_player = 11.2.202.356
adobe / flash_player = 11.2.202.359
adobe / flash_player = 11.2.202.378
adobe / flash_player = 11.2.202.394

Frequently Asked Questions

A security vulnerability is a weakness in software, hardware, or configuration that can be exploited to compromise confidentiality, integrity, or availability. Many vulnerabilities are tracked as CVEs (Common Vulnerabilities and Exposures), which provide a standardized identifier so teams can coordinate patching, mitigation, and risk assessment across tools and vendors.

CVSS (Common Vulnerability Scoring System) estimates technical severity, but it doesn't automatically equal business risk. Prioritize using context like internet exposure, affected asset criticality, known exploitation (proof-of-concept or in-the-wild), and whether compensating controls exist. A "Medium" CVSS on an exposed, production system can be more urgent than a "Critical" on an isolated, non-production host.

A vulnerability is the underlying weakness. An exploit is the method or code used to take advantage of it. A zero-day is a vulnerability that is unknown to the vendor or has no publicly available fix when attackers begin using it. In practice, risk increases sharply when exploitation becomes reliable or widespread.

Recurring findings usually come from incomplete Asset Discovery, inconsistent patch management, inherited images, and configuration drift. In modern environments, you also need to watch the software supply chain: dependencies, containers, build pipelines, and third-party services can reintroduce the same weakness even after you patch a single host. Unknown or unmanaged assets (often called Shadow IT) are a common reason the same issues resurface.

Use a simple, repeatable triage model: focus first on externally exposed assets, high-value systems (identity, VPN, email, production), vulnerabilities with known exploits, and issues that enable remote code execution or privilege escalation. Then enforce patch SLAs and track progress using consistent metrics so remediation is steady, not reactive.

SynScan combines attack surface monitoring and continuous security auditing to keep your inventory current, flag high-impact vulnerabilities early, and help you turn raw findings into a practical remediation plan.