CVE-2013-5332
published 2013-12-11CVE-2013-5332: Adobe Flash Player before 11.7.700.257 and 11.8.x and 11.9.x before 11.9.900.170 on Windows and Mac OS X and before 11.2.202.332 on Linux, Adobe AIR before…
PriorityP346critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
5.42%
91.8th percentile
Adobe Flash Player before 11.7.700.257 and 11.8.x and 11.9.x before 11.9.900.170 on Windows and Mac OS X and before 11.2.202.332 on Linux, Adobe AIR before 3.9.0.1380, Adobe AIR SDK before 3.9.0.1380, and Adobe AIR SDK & Compiler before 3.9.0.1380 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | air | < 3.9.0.1380 | 3.9.0.1380 |
| adobe | air_sdk | < 3.9.0.1380 | 3.9.0.1380 |
| adobe | flash_player | >= 11.0 < 11.7.700.257 | 11.7.700.257 |
| adobe | flash_player | >= 11.0 < 11.2.202.332 | 11.2.202.332 |
| adobe | flash_player | >= 11.8 < 11.8.800.175 | 11.8.800.175 |
| adobe | flash_player | >= 11.9 < 11.9.900.700 | 11.9.900.700 |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_redhat9.3CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-g677-c5v4-98qx: Adobe Flash Player before 11
ghsa_unreviewed·2022-05-14
CVE-2013-5332 [HIGH] CWE-94 GHSA-g677-c5v4-98qx: Adobe Flash Player before 11
Adobe Flash Player before 11.7.700.257 and 11.8.x and 11.9.x before 11.9.900.170 on Windows and Mac OS X and before 11.2.202.332 on Linux, Adobe AIR before 3.9.0.1380, Adobe AIR SDK before 3.9.0.1380, and Adobe AIR SDK & Compiler before 3.9.0.1380 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.
Red Hat
flash-plugin: multiple code execution flaws (APSB13-28)
vendor_redhat·2013-12-10·CVSS 9.3
CVE-2013-5332 [CRITICAL] flash-plugin: multiple code execution flaws (APSB13-28)
flash-plugin: multiple code execution flaws (APSB13-28)
Adobe Flash Player before 11.7.700.257 and 11.8.x and 11.9.x before 11.9.900.170 on Windows and Mac OS X and before 11.2.202.332 on Linux, Adobe AIR before 3.9.0.1380, Adobe AIR SDK before 3.9.0.1380, and Adobe AIR SDK & Compiler before 3.9.0.1380 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.
No detection rules found.
No public exploits indexed.
http://helpx.adobe.com/security/products/flash-player/apsb13-28.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-12/msg00008.htmlhttp://lists.opensuse.org/opensuse-updates/2013-12/msg00075.htmlhttp://lists.opensuse.org/opensuse-updates/2013-12/msg00084.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1818.htmlhttp://helpx.adobe.com/security/products/flash-player/apsb13-28.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-12/msg00008.htmlhttp://lists.opensuse.org/opensuse-updates/2013-12/msg00075.htmlhttp://lists.opensuse.org/opensuse-updates/2013-12/msg00084.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1818.html
2013-12-11
Published