CVE-2013-1379

Adobe Flash Player < 10.3.183.75 and 11.x < 11.7.700.169 - Remote Code Execution

Title source: llm
STIX 2.1

Description

Adobe Flash Player before 10.3.183.75 and 11.x before 11.7.700.169 on Windows and Mac OS X, before 10.3.183.75 and 11.x before 11.2.202.280 on Linux, before 11.1.111.50 on Android 2.x and 3.x, and before 11.1.115.54 on Android 4.x; Adobe AIR before 3.7.0.1530; and Adobe AIR SDK & Compiler before 3.7.0.1530 do not properly initialize pointer arrays, which allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.

References (6)

Core 6
Core References
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2013-0730.html
Patch, Vendor Advisory x_refsource_confirm
http://www.adobe.com/support/security/bulletins/apsb13-11.html
Mailing List vendor-advisory x_refsource_hp
http://marc.info/?l=bugtraq&m=139455789818399&w=2
Mailing List vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-updates/2013-04/msg00081.html

Scores

EPSS 0.0570
EPSS Percentile 90.5%

Details

CWE
CWE-119
Status published
Products (50)
adobe/adobe_air 3.6.0.597
adobe/adobe_air < 3.6.0.6090
adobe/adobe_air_sdk 3.6.0.599
adobe/adobe_air_sdk < 3.6.0.6090
adobe/flash_player 6.0.21.0
adobe/flash_player 6.0.79
adobe/flash_player 7.0
adobe/flash_player 7.0.1
adobe/flash_player 7.0.14.0
adobe/flash_player 7.0.19.0
... and 40 more
Published Apr 10, 2013
Tracked Since Feb 18, 2026