CVE-2013-0633 EXPLOIT
9.3
HIGH · CVSS 2.0 · EPSS 20.9% (pctl 97)
Patch early
A public exploit exists.
Description
Buffer overflow in Adobe Flash Player before 10.3.183.51 and 11.x before 11.5.502.149 on Windows and Mac OS X, before 10.3.183.51 and 11.x before 11.2.202.262 on Linux, before 11.1.111.32 on Android 2.x and 3.x, and before 11.1.115.37 on Android 4.x allows remote attackers to execute arbitrary code via crafted SWF content, as exploited in the wild in February 2013.
Scoring
| CVSS | 9.3 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
| EPSS | 20.88% — more likely to be exploited than 97% of all CVEs |
| Weakness | CWE-119 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2013-02-08 |
| Last modified | 2026-06-16 |
Affected (5)
| Vendor | Product |
|---|---|
| adobe | flash player |
| apple | mac os x |
| android | |
| linux | linux kernel |
| microsoft | windows |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Adobe Flash Player - Regular Expression Heap Overflow (Metasploit) | 2014-04-21 |
References
- http://lists.opensuse.org/opensuse-security-announce/2013-02/msg00004.html
- http://lists.opensuse.org/opensuse-security-announce/2013-02/msg00006.html
- http://lists.opensuse.org/opensuse-security-announce/2013-02/msg00007.html
- http://rhn.redhat.com/errata/RHSA-2013-0243.html
- http://www.adobe.com/support/security/bulletins/apsb13-04.html
- http://lists.opensuse.org/opensuse-security-announce/2013-02/msg00004.html
- http://lists.opensuse.org/opensuse-security-announce/2013-02/msg00006.html
- http://lists.opensuse.org/opensuse-security-announce/2013-02/msg00007.html
- http://rhn.redhat.com/errata/RHSA-2013-0243.html
- http://www.adobe.com/support/security/bulletins/apsb13-04.html
→ the Explorer · watch your stack · NVD