CVE-2014-9163: Adobe Flash Player Stack-Based Buffer Overflow Vulnerability

High severity, CVSS 7.8. Actively exploited: in CISA KEV since 2022-04-13. EPSS: 20.7% chance of exploitation in the next 30 days.

Stack-based buffer overflow in Adobe Flash Player before 13.0.0.259 and 14.x and 15.x before 15.0.0.246 on Windows and OS X and before 11.2.202.425 on Linux allows attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in December 2014.

Affected products

  • Adobe Flash Player: from 13.0, before 13.0.0.259 (fixed in 13.0.0.259); from 14.0, up to and including 14.0.0.179; from 15.0, before 15.0.0.246 (fixed in 15.0.0.246); from 11.0, before 11.2.202.425 (fixed in 11.2.202.425)

Published 2014-12-10. Last modified 2026-06-17.