CVE-2014-9164: Adobe Flash Player

High severity, CVSS 10.0. EPSS: 3.7% chance of exploitation in the next 30 days.

Adobe Flash Player before 13.0.0.259 and 14.x through 16.x before 16.0.0.235 on Windows and OS X and before 11.2.202.425 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2014-0587.

Affected products

  • Adobe Flash Player: from 13.0, before 13.0.0.259 (fixed in 13.0.0.259); from 14.0, up to and including 14.0.0.179; from 16.0, before 16.0.0.235 (fixed in 16.0.0.235); from 11.0, before 11.2.202.425 (fixed in 11.2.202.425)

Published 2014-12-10. Last modified 2026-06-17.