CVE-2013-0638
published 2013-02-12CVE-2013-0638: Adobe Flash Player before 10.3.183.63 and 11.x before 11.6.602.168 on Windows, before 10.3.183.61 and 11.x before 11.6.602.167 on Mac OS X, before 10.3.183.61…
PriorityP347critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
6.73%
93.2th percentile
Adobe Flash Player before 10.3.183.63 and 11.x before 11.6.602.168 on Windows, before 10.3.183.61 and 11.x before 11.6.602.167 on Mac OS X, before 10.3.183.61 and 11.x before 11.2.202.270 on Linux, before 11.1.111.43 on Android 2.x and 3.x, and before 11.1.115.47 on Android 4.x; Adobe AIR before 3.6.0.597; and Adobe AIR SDK before 3.6.0.599 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-0647.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | air | < 3.6.0.597 | 3.6.0.597 |
| adobe | air_sdk | < 3.6.0.599 | 3.6.0.599 |
| adobe | flash_player | >= 10.3 < 10.3.183.63 | 10.3.183.63 |
| adobe | flash_player | >= 10.3 < 10.3.183.61 | 10.3.183.61 |
| adobe | flash_player | >= 11.1 < 11.1.111.43 | 11.1.111.43 |
| adobe | flash_player | >= 11.1 < 11.1.115.47 | 11.1.115.47 |
| adobe | flash_player | >= 11.2 < 11.2.202.270 | 11.2.202.270 |
| adobe | flash_player | >= 11.6 < 11.6.602.168 | 11.6.602.168 |
| adobe | flash_player | >= 11.6 < 11.6.602.167 | 11.6.602.167 |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vendor_redhat10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
flash-plugin: multiple code execution flaws (APSB13-05)
vendor_redhat·2013-02-12·CVSS 10.0
CVE-2013-0647 [CRITICAL] flash-plugin: multiple code execution flaws (APSB13-05)
flash-plugin: multiple code execution flaws (APSB13-05)
Adobe Flash Player before 10.3.183.63 and 11.x before 11.6.602.168 on Windows, before 10.3.183.61 and 11.x before 11.6.602.167 on Mac OS X, before 10.3.183.61 and 11.x before 11.2.202.270 on Linux, before 11.1.111.43 on Android 2.x and 3.x, and before 11.1.115.47 on Android 4.x; Adobe AIR before 3.6.0.597; and Adobe AIR SDK before 3.6.0.599 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-0638.
Red Hat
flash-plugin: multiple code execution flaws (APSB13-05)
vendor_redhat·2013-02-12·CVSS 10.0
CVE-2013-0638 [CRITICAL] flash-plugin: multiple code execution flaws (APSB13-05)
flash-plugin: multiple code execution flaws (APSB13-05)
Adobe Flash Player before 10.3.183.63 and 11.x before 11.6.602.168 on Windows, before 10.3.183.61 and 11.x before 11.6.602.167 on Mac OS X, before 10.3.183.61 and 11.x before 11.2.202.270 on Linux, before 11.1.111.43 on Android 2.x and 3.x, and before 11.1.115.47 on Android 4.x; Adobe AIR before 3.6.0.597; and Adobe AIR SDK before 3.6.0.599 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-0647.
GHSA
GHSA-p9w3-rpqw-vc26: Adobe Flash Player before 10
ghsa_unreviewed·2022-05-14·CVSS 10.0
CVE-2013-0638 [CRITICAL] CWE-119 GHSA-p9w3-rpqw-vc26: Adobe Flash Player before 10
Adobe Flash Player before 10.3.183.63 and 11.x before 11.6.602.168 on Windows, before 10.3.183.61 and 11.x before 11.6.602.167 on Mac OS X, before 10.3.183.61 and 11.x before 11.2.202.270 on Linux, before 11.1.111.43 on Android 2.x and 3.x, and before 11.1.115.47 on Android 4.x; Adobe AIR before 3.6.0.597; and Adobe AIR SDK before 3.6.0.599 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-0647.
GHSA
GHSA-2jfw-4f25-h98x: Adobe Flash Player before 10
ghsa_unreviewed·2022-05-14·CVSS 10.0
CVE-2013-0647 [CRITICAL] CWE-119 GHSA-2jfw-4f25-h98x: Adobe Flash Player before 10
Adobe Flash Player before 10.3.183.63 and 11.x before 11.6.602.168 on Windows, before 10.3.183.61 and 11.x before 11.6.602.167 on Mac OS X, before 10.3.183.61 and 11.x before 11.2.202.270 on Linux, before 11.1.111.43 on Android 2.x and 3.x, and before 11.1.115.47 on Android 4.x; Adobe AIR before 3.6.0.597; and Adobe AIR SDK before 3.6.0.599 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-0638.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-0329 jenkins: cross-site request forgery (CSRF) protection mechanism bypass
bugzilla·2013-02-23·CVSS 7.5
CVE-2013-0329 [HIGH] CVE-2013-0329 jenkins: cross-site request forgery (CSRF) protection mechanism bypass
CVE-2013-0329 jenkins: cross-site request forgery (CSRF) protection mechanism bypass
Jenkins Security Advisory 2013-02-16
Another vulnerability allowed an attacker to bypass the CSRF protection
mechanism in place, thereby mounting more CSRF attackes.
https://wiki.jenkins-ci.org/display/SECURITY/Jenkins+Security+Advisory+2013-02-16
Discussion:
This issue has been addressed in following products:
RHEL 6 Version of OpenShift Enterprise
Via RHSA-2013:0638 https://rhn.redhat.com/errata/RHSA-2013-0638.html
Bugzilla
CVE-2013-0330 jenkins: cause building jobs without direct access
bugzilla·2013-02-23·CVSS 4.0
CVE-2013-0330 [MEDIUM] CVE-2013-0330 jenkins: cause building jobs without direct access
CVE-2013-0330 jenkins: cause building jobs without direct access
Jenkins Security Advisory 2013-02-16
A malicious user of Jenkins can trick Jenkins into building jobs that he does
not have direct access to.
https://wiki.jenkins-ci.org/display/SECURITY/Jenkins+Security+Advisory+2013-02-16
Discussion:
This issue has been addressed in following products:
RHEL 6 Version of OpenShift Enterprise
Via RHSA-2013:0638 https://rhn.redhat.com/errata/RHSA-2013-0638.html
Bugzilla
CVE-2013-0327 jenkins: cross-site request forgery (CSRF) on Jenkins master
bugzilla·2013-02-23·CVSS 6.8
CVE-2013-0327 [MEDIUM] CVE-2013-0327 jenkins: cross-site request forgery (CSRF) on Jenkins master
CVE-2013-0327 jenkins: cross-site request forgery (CSRF) on Jenkins master
Jenkins Security Advisory 2013-02-16
One of the vulnerabilities allows cross-site request forgery (CSRF) attacks on
Jenkins master, which causes an user to make unwanted actions on Jenkins.
https://wiki.jenkins-ci.org/display/SECURITY/Jenkins+Security+Advisory+2013-02-16
Discussion:
This issue has been addressed in following products:
RHEL 6 Version of OpenShift Enterprise
Via RHSA-2013:0638 https://rhn.redhat.com/errata/RHSA-2013-0638.html
Bugzilla
CVE-2013-0331 jenkins: denial of service attack by feeding a carefully crafted payload to Jenkins
bugzilla·2013-02-23·CVSS 4.0
CVE-2013-0331 [MEDIUM] CVE-2013-0331 jenkins: denial of service attack by feeding a carefully crafted payload to Jenkins
CVE-2013-0331 jenkins: denial of service attack by feeding a carefully crafted payload to Jenkins
Jenkins Security Advisory 2013-02-16
A vulnerability allows a malicious user of Jenkins to mount a denial of
service attack by feeding a carefully crafted payload to Jenkins.
https://wiki.jenkins-ci.org/display/SECURITY/Jenkins+Security+Advisory+2013-02-16
Discussion:
This issue has been addressed in following products:
RHEL 6 Version of OpenShift Enterprise
Via RHSA-2013:0638 https://rhn.redhat.com/errata/RHSA-2013-0638.html
Bugzilla
CVE-2013-0328 jenkins: XSS
bugzilla·2013-02-23·CVSS 4.3
CVE-2013-0328 [MEDIUM] CVE-2013-0328 jenkins: XSS
CVE-2013-0328 jenkins: XSS
Jenkins Security Advisory 2013-02-16
Another vulnerability enables cross-site scripting (XSS) attacks.
https://wiki.jenkins-ci.org/display/SECURITY/Jenkins+Security+Advisory+2013-02-16
Discussion:
This issue has been addressed in following products:
RHEL 6 Version of OpenShift Enterprise
Via RHSA-2013:0638 https://rhn.redhat.com/errata/RHSA-2013-0638.html
---
Upstream commit is:
https://github.com/jenkinsci/jenkins/commit/f8d2a0ba6c2e261f48287bdd95bd7a2d7a8d2d0e
---
*** Bug 1054557 has been marked as a duplicate of this bug. ***
Bugzilla
flash-plugin: multiple code execution flaws (APSB13-05)
bugzilla·2013-02-12·CVSS 10.0
CVE-2013-1372 [CRITICAL] flash-plugin: multiple code execution flaws (APSB13-05)
flash-plugin: multiple code execution flaws (APSB13-05)
Adobe security bulletin APSB13-05 describes multiple security flaws that could cause Adobe Flash Player to crash and potentially allow an attacker to take control of the affected system:
This update resolves buffer overflow vulnerabilities that could lead to code execution (CVE-2013-1372, CVE-2013-0645, CVE-2013-1373, CVE-2013-1369, CVE-2013-1370, CVE-2013-1366, CVE-2013-1365, CVE-2013-1368, CVE-2013-0642, CVE-2013-1367).
This update resolves use-after-free vulnerabilities that could lead to code execution (CVE-2013-0649, CVE-2013-1374, CVE-2013-0644).
This update resolves an integer overflow vulnerability that could lead to code execution (CVE-2013-0639).
This update resolves memory corruption vulnerabilities that could lead to
Bugzilla
CVE-2013-0262 rubygem-rack: Path sanitization information disclosure
bugzilla·2013-02-08·CVSS 4.3
CVE-2013-0262 [MEDIUM] CVE-2013-0262 rubygem-rack: Path sanitization information disclosure
CVE-2013-0262 rubygem-rack: Path sanitization information disclosure
James Tucker ([email protected]) reports:
CVE: CVE-2013-0262
Software: Rack (rack.github.com)
Type of vulnerability: Information Disclosure
Vulnerable code: https://github.com/rack/rack/blob/master/lib/rack/file.rb#L56
Patch: https://github.com/rack/rack/commit/6f237e4c9fab649d3750482514f0fde76c56ab30
Versions affected: All versions after 1.4.0
Versions fixed: 1.4.5, 1.5.2
Reporter: Ben Murphy
Discussion:
Created rubygem-rack tracking bugs for this issue
Affects: fedora-17 [bug 909075]
---
Created rubygem-rack tracking bugs for this issue
Affects: fedora-18 [bug 909076]
---
This issue has been addressed in following products:
RHEL 6 Version of OpenShift Enterprise
Via RHSA-2013:0638 https://rhn.redhat.com/errat
http://lists.opensuse.org/opensuse-security-announce/2013-02/msg00009.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-02/msg00010.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-02/msg00011.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0254.htmlhttp://www.adobe.com/support/security/bulletins/apsb13-05.htmlhttp://www.us-cert.gov/cas/techalerts/TA13-043A.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-02/msg00009.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-02/msg00010.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-02/msg00011.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0254.htmlhttp://www.adobe.com/support/security/bulletins/apsb13-05.htmlhttp://www.us-cert.gov/cas/techalerts/TA13-043A.html
2013-02-12
Published