peter bassill · operator
$ cve CVE-2013-5331 JSON

CVE-2013-5331 EXPLOIT

9.3
HIGH · CVSS 2.0 · EPSS 72.5% (pctl 99)

Patch early

A public exploit exists.

Description

Adobe Flash Player before 11.7.700.257 and 11.8.x and 11.9.x before 11.9.900.170 on Windows and Mac OS X and before 11.2.202.332 on Linux, Adobe AIR before 3.9.0.1380, Adobe AIR SDK before 3.9.0.1380, and Adobe AIR SDK & Compiler before 3.9.0.1380 allow remote attackers to execute arbitrary code via crafted .swf content that leverages an unspecified "type confusion," as exploited in the wild in December 2013.

Scoring

CVSS9.3 (HIGH, v2.0)
VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
EPSS72.5% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-94
On CISA KEVno
Public exploityes
Published2013-12-11
Last modified2026-06-16

Affected (6)

VendorProduct
adobeair
adobeair sdk
adobeflash player
applemac os x
linuxlinux kernel
microsoftwindows

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD