CVE-2013-3347Adobe Flash Player vulnerability

CWE-1894 documents4 sources
Severity
10.0CRITICALNVD
EPSS
8.0%
top 7.90%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJul 10
Latest updateMay 17

Description

Integer overflow in Adobe Flash Player before 11.7.700.232 and 11.8.x before 11.8.800.94 on Windows and Mac OS X, before 11.2.202.297 on Linux, before 11.1.111.64 on Android 2.x and 3.x, and before 11.1.115.69 on Android 4.x allows attackers to execute arbitrary code via PCM data that is not properly handled during resampling.

CVSS vector

AV:N/AC:L/C:C/I:C/A:CExploitability: 10.0 | Impact: 10.0

Affected Packages1 packages

NVDadobe/flash_player11.7.700.224+59

Patches

🔴Vulnerability Details

1
GHSA
GHSA-gg7j-4m6j-hpg3: Integer overflow in Adobe Flash Player before 112022-05-17

📋Vendor Advisories

1
Red Hat
flash-plugin: Multiple code execution flaws (APSB13-17)2013-07-09

💬Community

1
Bugzilla
CVE-2013-3344 CVE-2013-3345 CVE-2013-3347 flash-plugin: Multiple code execution flaws (APSB13-17)2013-07-09