{"id":"UBUNTU-CVE-2014-5333","details":"Adobe Flash Player before 13.0.0.241 and 14.x before 14.0.0.176 on Windows and OS X and before 11.2.202.400 on Linux, Adobe AIR before 14.0.0.178 on Windows and OS X and before 14.0.0.179 on Android, Adobe AIR SDK before 14.0.0.178, and Adobe AIR SDK & Compiler before 14.0.0.178 do not properly restrict the SWF file format, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks against JSONP endpoints, and obtain sensitive information, via a crafted OBJECT element with SWF content satisfying the character-set requirements of a callback API, in conjunction with a manipulation involving a '$' (dollar sign) or '(' (open parenthesis) character. NOTE: this issue exists because of an incomplete fix for CVE-2014-4671.","modified":"2025-07-16T07:02:09.652926Z","published":"2014-08-19T11:16:00Z","upstream":["CVE-2014-5333"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2014-5333"},{"type":"REPORT","url":"http://helpx.adobe.com/security/products/flash-player/apsb14-18.html"},{"type":"REPORT","url":"http://miki.it/blog/2014/8/15/adobe-really-fixed-rosetta-flash-today/"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2014-5333"}],"affected":[{"package":{"name":"flashplugin-nonfree","ecosystem":"Ubuntu:14.04:LTS","purl":"pkg:deb/ubuntu/flashplugin-nonfree@11.2.202.400ubuntu0.14.04.1?arch=source&distro=trusty"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"11.2.202.400ubuntu0.14.04.1"}]}],"versions":["11.2.202.310ubuntu1","11.2.202.327ubuntu0.13.10.1","11.2.202.332ubuntu1","11.2.202.335ubuntu1","11.2.202.336ubuntu1","11.2.202.341ubuntu1","11.2.202.346ubuntu1","11.2.202.350ubuntu1","11.2.202.356ubuntu0.14.04.1","11.2.202.359ubuntu0.14.04.1","11.2.202.378ubuntu0.14.04.1","11.2.202.394ubuntu0.14.04.1"],"ecosystem_specific":{"binaries":[{"binary_name":"flashplugin-downloader","binary_version":"11.2.202.400ubuntu0.14.04.1"},{"binary_name":"flashplugin-installer","binary_version":"11.2.202.400ubuntu0.14.04.1"}],"availability":"No subscription required"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2014/UBUNTU-CVE-2014-5333.json"}}],"schema_version":"1.7.3","severity":[{"type":"Ubuntu","score":"medium"}]}