← Back to CVE List
Vulnerability Intelligence Report

CVE-2013-2555

Integer overflow in Adobe Flash Player before 10.3.183.75 and 11.x before 11.7.700.169 on Windows and Mac OS X, before 10.3.183.75 and 11.x before 11.2.202.280 on Linux, before 11.1.111.50 on Android 2.x and 3.x, and before 11.1.115.54 on Android 4.x; Adobe AIR before 3.7.0.1530; and Adobe AIR SDK & Compiler before 3.7.0.1530 allows remote attackers to execute arbitrary code via unspecified vectors, as demonstrated by VUPEN during a Pwn2Own competition at CanSecWest 2013.

No Active Exploit Signals
CVSS Base Score
10.0
HIGH
EPSS Probability:8.46%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Affected Products & Versions

Vendor Product Affected Versions
adobe flash_player all
google android all
apple macos all
microsoft windows all
linux linux_kernel all
adobe air all
opensuse opensuse 11.4, 12.1, 12.2, 12.3
suse linux_enterprise_desktop 11
redhat enterprise_linux_desktop 6.0
redhat enterprise_linux_eus 5.9, 6.4
redhat enterprise_linux_server 6.0
redhat enterprise_linux_server_aus 5.9, 6.4
redhat enterprise_linux_workstation 6.0

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
8.458%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityMITRE Corporation · N/A · USA
Reserved2013-03-10T00:00:00
Published2013-03-11T10:00:00
Patch Date2013-03-07
Last Updated2024-08-06T15:44:32

LINK COPIED TO CLIPBOARD