CVE-2013-3363
published 2013-09-12CVE-2013-3363: Adobe Flash Player before 11.7.700.242 and 11.8.x before 11.8.800.168 on Windows and Mac OS X, before 11.2.202.310 on Linux, before 11.1.111.73 on Android 2.x…
PriorityP345critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
5.76%
92.2th percentile
Adobe Flash Player before 11.7.700.242 and 11.8.x before 11.8.800.168 on Windows and Mac OS X, before 11.2.202.310 on Linux, before 11.1.111.73 on Android 2.x and 3.x, and before 11.1.115.81 on Android 4.x; Adobe AIR before 3.8.0.1430; and Adobe AIR SDK & Compiler before 3.8.0.1430 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-3361, CVE-2013-3362, and CVE-2013-5324.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | air | < 3.8.0.1430 | 3.8.0.1430 |
| adobe | air_sdk | < 3.8.0.1430 | 3.8.0.1430 |
| adobe | flash_player | >= 11.0 < 11.7.700.242 | 11.7.700.242 |
| adobe | flash_player | >= 11.0 < 11.2.202.310 | 11.2.202.310 |
| adobe | flash_player | >= 11.0 < 11.1.111.73 | 11.1.111.73 |
| adobe | flash_player | >= 11.0 < 11.1.115.81 | 11.1.115.81 |
| adobe | flash_player | >= 11.8 < 11.8.800.168 | 11.8.800.168 |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vendor_redhat10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-49fh-rh46-p46w: Adobe Flash Player before 11
ghsa_unreviewed·2022-05-14·CVSS 10.0
CVE-2013-3362 [CRITICAL] CWE-119 GHSA-49fh-rh46-p46w: Adobe Flash Player before 11
Adobe Flash Player before 11.7.700.242 and 11.8.x before 11.8.800.168 on Windows and Mac OS X, before 11.2.202.310 on Linux, before 11.1.111.73 on Android 2.x and 3.x, and before 11.1.115.81 on Android 4.x; Adobe AIR before 3.8.0.1430; and Adobe AIR SDK & Compiler before 3.8.0.1430 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-3361, CVE-2013-3363, and CVE-2013-5324.
GHSA
GHSA-ffm9-5x5f-p3qq: Adobe Flash Player before 11
ghsa_unreviewed·2022-05-14·CVSS 10.0
CVE-2013-3363 [CRITICAL] CWE-119 GHSA-ffm9-5x5f-p3qq: Adobe Flash Player before 11
Adobe Flash Player before 11.7.700.242 and 11.8.x before 11.8.800.168 on Windows and Mac OS X, before 11.2.202.310 on Linux, before 11.1.111.73 on Android 2.x and 3.x, and before 11.1.115.81 on Android 4.x; Adobe AIR before 3.8.0.1430; and Adobe AIR SDK & Compiler before 3.8.0.1430 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-3361, CVE-2013-3362, and CVE-2013-5324.
GHSA
GHSA-vr4x-7p35-rcfh: Adobe Flash Player before 11
ghsa_unreviewed·2022-05-14·CVSS 10.0
CVE-2013-3361 [CRITICAL] CWE-119 GHSA-vr4x-7p35-rcfh: Adobe Flash Player before 11
Adobe Flash Player before 11.7.700.242 and 11.8.x before 11.8.800.168 on Windows and Mac OS X, before 11.2.202.310 on Linux, before 11.1.111.73 on Android 2.x and 3.x, and before 11.1.115.81 on Android 4.x; Adobe AIR before 3.8.0.1430; and Adobe AIR SDK & Compiler before 3.8.0.1430 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-3362, CVE-2013-3363, and CVE-2013-5324.
GHSA
GHSA-vrhf-j8fq-974v: Adobe Flash Player before 11
ghsa_unreviewed·2022-05-14·CVSS 10.0
CVE-2013-5324 [CRITICAL] CWE-119 GHSA-vrhf-j8fq-974v: Adobe Flash Player before 11
Adobe Flash Player before 11.7.700.242 and 11.8.x before 11.8.800.168 on Windows and Mac OS X, before 11.2.202.310 on Linux, before 11.1.111.73 on Android 2.x and 3.x, and before 11.1.115.81 on Android 4.x; Adobe AIR before 3.8.0.1430; and Adobe AIR SDK & Compiler before 3.8.0.1430 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-3361, CVE-2013-3362, and CVE-2013-3363.
Red Hat
flash-plugin: multiple code execution flaws (APSB13-21)
vendor_redhat·2013-09-10·CVSS 10.0
CVE-2013-3363 [CRITICAL] flash-plugin: multiple code execution flaws (APSB13-21)
flash-plugin: multiple code execution flaws (APSB13-21)
Adobe Flash Player before 11.7.700.242 and 11.8.x before 11.8.800.168 on Windows and Mac OS X, before 11.2.202.310 on Linux, before 11.1.111.73 on Android 2.x and 3.x, and before 11.1.115.81 on Android 4.x; Adobe AIR before 3.8.0.1430; and Adobe AIR SDK & Compiler before 3.8.0.1430 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-3361, CVE-2013-3362, and CVE-2013-5324.
Red Hat
flash-plugin: multiple code execution flaws (APSB13-21)
vendor_redhat·2013-09-10·CVSS 10.0
CVE-2013-3362 [CRITICAL] flash-plugin: multiple code execution flaws (APSB13-21)
flash-plugin: multiple code execution flaws (APSB13-21)
Adobe Flash Player before 11.7.700.242 and 11.8.x before 11.8.800.168 on Windows and Mac OS X, before 11.2.202.310 on Linux, before 11.1.111.73 on Android 2.x and 3.x, and before 11.1.115.81 on Android 4.x; Adobe AIR before 3.8.0.1430; and Adobe AIR SDK & Compiler before 3.8.0.1430 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-3361, CVE-2013-3363, and CVE-2013-5324.
Red Hat
flash-plugin: multiple code execution flaws (APSB13-21)
vendor_redhat·2013-09-10·CVSS 10.0
CVE-2013-5324 [CRITICAL] flash-plugin: multiple code execution flaws (APSB13-21)
flash-plugin: multiple code execution flaws (APSB13-21)
Adobe Flash Player before 11.7.700.242 and 11.8.x before 11.8.800.168 on Windows and Mac OS X, before 11.2.202.310 on Linux, before 11.1.111.73 on Android 2.x and 3.x, and before 11.1.115.81 on Android 4.x; Adobe AIR before 3.8.0.1430; and Adobe AIR SDK & Compiler before 3.8.0.1430 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-3361, CVE-2013-3362, and CVE-2013-3363.
Red Hat
flash-plugin: multiple code execution flaws (APSB13-21)
vendor_redhat·2013-09-10·CVSS 10.0
CVE-2013-3361 [CRITICAL] flash-plugin: multiple code execution flaws (APSB13-21)
flash-plugin: multiple code execution flaws (APSB13-21)
Adobe Flash Player before 11.7.700.242 and 11.8.x before 11.8.800.168 on Windows and Mac OS X, before 11.2.202.310 on Linux, before 11.1.111.73 on Android 2.x and 3.x, and before 11.1.115.81 on Android 4.x; Adobe AIR before 3.8.0.1430; and Adobe AIR SDK & Compiler before 3.8.0.1430 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-3362, CVE-2013-3363, and CVE-2013-5324.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-3361 CVE-2013-3362 CVE-2013-3363 CVE-2013-5324 flash-plugin: multiple code execution flaws (APSB13-21)
bugzilla·2013-09-10·CVSS 10.0
CVE-2013-3361 [CRITICAL] CVE-2013-3361 CVE-2013-3362 CVE-2013-3363 CVE-2013-5324 flash-plugin: multiple code execution flaws (APSB13-21)
CVE-2013-3361 CVE-2013-3362 CVE-2013-3363 CVE-2013-5324 flash-plugin: multiple code execution flaws (APSB13-21)
Adobe has released Flash Player 11.2.202.310 for Linux to correct the following flaws:
* These updates resolve memory corruption vulnerabilities that could lead to code execution (CVE-2013-3361, CVE-2013-3362, CVE-2013-3363, CVE-2013-5324).
External References:
http://www.adobe.com/support/security/bulletins/apsb13-21.html
Discussion:
This issue has been addressed in following products:
Supplementary for Red Hat Enterprise Linux 5
Supplementary for Red Hat Enterprise Linux 6
Via RHSA-2013:1256 https://rhn.redhat.com/errata/RHSA-2013-1256.html
Bugzilla
CVE-2012-3363 moodle: XXE via Zend library (MSA-13-0016)
bugzilla·2013-03-25·CVSS 9.1
CVE-2012-3363 [CRITICAL] CVE-2012-3363 moodle: XXE via Zend library (MSA-13-0016)
CVE-2012-3363 moodle: XXE via Zend library (MSA-13-0016)
An information disclosure flaw was found in the way XML RPC interface of web services of Moodle, a course management system, performed loading of certain XML files. A remote attacker (valid Moodle user) could use this flaw to obtain sensitive information (certain server files).
References:
[1] http://www.openwall.com/lists/oss-security/2013/03/25/2
Relevant upstream patch:
[2] http://git.moodle.org/gw?p=moodle.git;a=commit;h=dfe203c12e4fdb4696b59928f90bb06cb1d8b9a7
Discussion:
This issue affects the versions of the moodle package, as shipped with Fedora release of 18, 17, and Fedora EPEL-6. Please schedule an update.
--
This issue did NOT affect the version of the moodle package, as shipped with Fedora EPEL-5.
---
Created mo
http://lists.opensuse.org/opensuse-security-announce/2013-09/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-09/msg00002.htmlhttp://lists.opensuse.org/opensuse-updates/2013-09/msg00040.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1256.htmlhttp://www.adobe.com/support/security/bulletins/apsb13-21.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-09/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-09/msg00002.htmlhttp://lists.opensuse.org/opensuse-updates/2013-09/msg00040.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1256.htmlhttp://www.adobe.com/support/security/bulletins/apsb13-21.html
2013-09-12
Published