CVE-2013-5331
Adobe Flash Player - Type Confusion Remote Code Execution
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
Adobe Flash Player before 11.7.700.257 and 11.8.x and 11.9.x before 11.9.900.170 on Windows and Mac OS X and before 11.2.202.332 on Linux, Adobe AIR before 3.9.0.1380, Adobe AIR SDK before 3.9.0.1380, and Adobe AIR SDK & Compiler before 3.9.0.1380 allow remote attackers to execute arbitrary code via crafted .swf content that leverages an unspecified "type confusion," as exploited in the wild in December 2013.
Adobe Flash Player anterior a 11.7.700.257y11.8.x y 11.9.x anterior a 11.9.900.170 en Windows y Mac OS X y en Linux antes de 11.2.202.332 , Adobe AIR anterior a AIR3.9.0.1380 , y Adobe AIR SDK y compilador anterior a 3.9.0.1380 permite a atacantes remotos ejecutar código arbitrario a través de contenido swf manipulado que aprovecha un tipo no especificado "type confusion", como se ha explotado en diciembre de 2013.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2013-08-20 CVE Reserved
- 2013-12-11 CVE Published
- 2014-04-29 First Exploit
- 2024-08-06 CVE Updated
- 2024-10-31 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-94: Improper Control of Generation of Code ('Code Injection')
CAPEC
References (8)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/33095 | 2014-04-29 |
URL | Date | SRC |
---|---|---|
http://helpx.adobe.com/security/products/flash-player/apsb13-28.html | 2018-12-13 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | >= 11.0 < 11.7.700.257 Search vendor "Adobe" for product "Flash Player" and version " >= 11.0 < 11.7.700.257" | - |
Affected
| in | Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | - | - |
Safe
|
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | >= 11.0 < 11.7.700.257 Search vendor "Adobe" for product "Flash Player" and version " >= 11.0 < 11.7.700.257" | - |
Affected
| in | Microsoft Search vendor "Microsoft" | Windows Search vendor "Microsoft" for product "Windows" | - | - |
Safe
|
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | >= 11.8 < 11.8.800.175 Search vendor "Adobe" for product "Flash Player" and version " >= 11.8 < 11.8.800.175" | - |
Affected
| in | Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | - | - |
Safe
|
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | >= 11.8 < 11.8.800.175 Search vendor "Adobe" for product "Flash Player" and version " >= 11.8 < 11.8.800.175" | - |
Affected
| in | Microsoft Search vendor "Microsoft" | Windows Search vendor "Microsoft" for product "Windows" | - | - |
Safe
|
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | >= 11.9 < 11.9.900.700 Search vendor "Adobe" for product "Flash Player" and version " >= 11.9 < 11.9.900.700" | - |
Affected
| in | Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | - | - |
Safe
|
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | >= 11.9 < 11.9.900.700 Search vendor "Adobe" for product "Flash Player" and version " >= 11.9 < 11.9.900.700" | - |
Affected
| in | Microsoft Search vendor "Microsoft" | Windows Search vendor "Microsoft" for product "Windows" | - | - |
Safe
|
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | >= 11.0 < 11.2.202.332 Search vendor "Adobe" for product "Flash Player" and version " >= 11.0 < 11.2.202.332" | - |
Affected
| in | Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | - | - |
Safe
|
Adobe Search vendor "Adobe" | Air Search vendor "Adobe" for product "Air" | < 3.9.0.1380 Search vendor "Adobe" for product "Air" and version " < 3.9.0.1380" | - |
Affected
| ||||||
Adobe Search vendor "Adobe" | Air Sdk Search vendor "Adobe" for product "Air Sdk" | < 3.9.0.1380 Search vendor "Adobe" for product "Air Sdk" and version " < 3.9.0.1380" | - |
Affected
|