CVE-2013-5332Code Injection in Adobe AIR

CWE-94Code Injection5 documents5 sources
Severity
9.3CRITICALNVD
EPSS
7.4%
top 8.23%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 11
Latest updateMay 14

Description

Adobe Flash Player before 11.7.700.257 and 11.8.x and 11.9.x before 11.9.900.170 on Windows and Mac OS X and before 11.2.202.332 on Linux, Adobe AIR before 3.9.0.1380, Adobe AIR SDK before 3.9.0.1380, and Adobe AIR SDK & Compiler before 3.9.0.1380 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.

CVSS vector

AV:N/AC:M/C:C/I:C/A:CExploitability: 8.6 | Impact: 10.0

Affected Packages3 packages

NVDadobe/flash_player11.011.7.700.257+3
NVDadobe/air< 3.9.0.1380
NVDadobe/air_sdk< 3.9.0.1380

Patches

🔴Vulnerability Details

2
GHSA
GHSA-g677-c5v4-98qx: Adobe Flash Player before 112022-05-14
CVEList
CVE-2013-5332: Adobe Flash Player before 112013-12-11

📋Vendor Advisories

1
Red Hat
flash-plugin: multiple code execution flaws (APSB13-28)2013-12-10

💬Community

1
Bugzilla
CVE-2013-5331 CVE-2013-5332 flash-plugin: multiple code execution flaws (APSB13-28)2013-12-10
CVE-2013-5332 — Code Injection in Adobe AIR | cvebase