CVE-2013-5331

Adobe Flash Player before 11.7.700.257 and 11.8.x and 11.9.x before 11.9.900.170 on Windows and Mac OS X and before 11.2.202.332 on Linux, Adobe AIR before 3.9.0.1380, Adobe AIR SDK before 3.9.0.1380, and Adobe AIR SDK & Compiler before 3.9.0.1380 allow remote attackers to execute arbitrary code via crafted .swf content that leverages an unspecified "type confusion," as exploited in the wild in December 2013.
Code Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:C/I:C/A:C
adobeCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 99%
VendorProductVersion
adobeflash_player
11.0 ≤
𝑥
< 11.7.700.257
adobeflash_player
11.8 ≤
𝑥
< 11.8.800.175
adobeflash_player
11.9 ≤
𝑥
< 11.9.900.700
adobeflash_player
11.0 ≤
𝑥
< 11.2.202.332
adobeair
𝑥
< 3.9.0.1380
adobeair_sdk
𝑥
< 3.9.0.1380
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
adobe-flashplugin
saucy
Fixed 11.2.202.332-0saucy1
released
raring
Fixed 11.2.202.332-0raring2
released
quantal
Fixed 11.2.202.332-0quantal2
released
precise
Fixed 11.2.202.332-0precise2
released
lucid
ignored
flashplugin-nonfree
saucy
Fixed 11.2.202.332ubuntu0.12.10.1
released
raring
Fixed 11.2.202.332ubuntu0.13.04.1
released
quantal
Fixed 11.2.202.332ubuntu0.12.10.1
released
precise
Fixed 11.2.202.332ubuntu0.12.04.1
released
lucid
ignored