CVE-2013-5329
published 2013-11-13CVE-2013-5329: Adobe Flash Player before 11.7.700.252 and 11.8.x and 11.9.x before 11.9.900.152 on Windows and Mac OS X and before 11.2.202.327 on Linux, Adobe AIR before…
PriorityP345critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
5.76%
92.2th percentile
Adobe Flash Player before 11.7.700.252 and 11.8.x and 11.9.x before 11.9.900.152 on Windows and Mac OS X and before 11.2.202.327 on Linux, Adobe AIR before 3.9.0.1210, Adobe AIR SDK before 3.9.0.1210, and Adobe AIR SDK & Compiler before 3.9.0.1210 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-5330.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | air | < 3.9.0.1210 | 3.9.0.1210 |
| adobe | air_sdk | < 3.9.0.1210 | 3.9.0.1210 |
| adobe | flash_player | >= 11.0 < 11.7.700.252 | 11.7.700.252 |
| adobe | flash_player | >= 11.0 < 11.2.202.327 | 11.2.202.327 |
| adobe | flash_player | >= 11.8 < 11.8.800.175 | 11.8.800.175 |
| adobe | flash_player | >= 11.9 < 11.9.900.152 | 11.9.900.152 |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vulncheck10.0CRITICAL
vendor_redhat10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-jj82-mwc3-9h8h: Adobe Flash Player before 11
ghsa_unreviewed·2022-05-14·CVSS 10.0
CVE-2013-5329 [CRITICAL] CWE-119 GHSA-jj82-mwc3-9h8h: Adobe Flash Player before 11
Adobe Flash Player before 11.7.700.252 and 11.8.x and 11.9.x before 11.9.900.152 on Windows and Mac OS X and before 11.2.202.327 on Linux, Adobe AIR before 3.9.0.1210, Adobe AIR SDK before 3.9.0.1210, and Adobe AIR SDK & Compiler before 3.9.0.1210 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-5330.
GHSA
GHSA-j473-h6vv-fh38: Adobe Flash Player before 11
ghsa_unreviewed·2022-05-14·CVSS 10.0
CVE-2013-5330 [CRITICAL] CWE-119 GHSA-j473-h6vv-fh38: Adobe Flash Player before 11
Adobe Flash Player before 11.7.700.252 and 11.8.x and 11.9.x before 11.9.900.152 on Windows and Mac OS X and before 11.2.202.327 on Linux, Adobe AIR before 3.9.0.1210, Adobe AIR SDK before 3.9.0.1210, and Adobe AIR SDK & Compiler before 3.9.0.1210 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-5329.
VulnCheck
Adobe Flash Player Improper Restriction of Operations within the Bounds of a Memory Buffer
vulncheck·2013·CVSS 10.0
CVE-2013-5330 [CRITICAL] Adobe Flash Player Improper Restriction of Operations within the Bounds of a Memory Buffer
Adobe Flash Player Improper Restriction of Operations within the Bounds of a Memory Buffer
Adobe Flash Player before 11.7.700.252 and 11.8.x and 11.9.x before 11.9.900.152 on Windows and Mac OS X and before 11.2.202.327 on Linux, Adobe AIR before 3.9.0.1210, Adobe AIR SDK before 3.9.0.1210, and Adobe AIR SDK & Compiler before 3.9.0.1210 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-5329.
Affected: Adobe Flash Player
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://www.helpnetsecurity.com/2014/02/11/older-flash-player-vulnerability-exploited
Red Hat
flash-plugin: multiple code execution flaws (APSB13-26)
vendor_redhat·2013-11-12·CVSS 10.0
CVE-2013-5330 [CRITICAL] flash-plugin: multiple code execution flaws (APSB13-26)
flash-plugin: multiple code execution flaws (APSB13-26)
Adobe Flash Player before 11.7.700.252 and 11.8.x and 11.9.x before 11.9.900.152 on Windows and Mac OS X and before 11.2.202.327 on Linux, Adobe AIR before 3.9.0.1210, Adobe AIR SDK before 3.9.0.1210, and Adobe AIR SDK & Compiler before 3.9.0.1210 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-5329.
Red Hat
flash-plugin: multiple code execution flaws (APSB13-26)
vendor_redhat·2013-11-12·CVSS 10.0
CVE-2013-5329 [CRITICAL] flash-plugin: multiple code execution flaws (APSB13-26)
flash-plugin: multiple code execution flaws (APSB13-26)
Adobe Flash Player before 11.7.700.252 and 11.8.x and 11.9.x before 11.9.900.152 on Windows and Mac OS X and before 11.2.202.327 on Linux, Adobe AIR before 3.9.0.1210, Adobe AIR SDK before 3.9.0.1210, and Adobe AIR SDK & Compiler before 3.9.0.1210 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-5330.
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-security-announce/2013-11/msg00015.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-11/msg00016.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-11/msg00019.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1518.htmlhttp://www.adobe.com/support/security/bulletins/apsb13-26.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-11/msg00015.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-11/msg00016.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-11/msg00019.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1518.htmlhttp://www.adobe.com/support/security/bulletins/apsb13-26.html
2013-11-13
Published