Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2013-2555


Integer overflow in Adobe Flash Player before 10.3.183.75 and 11.x before 11.7.700.169 on Windows and Mac OS X, before 10.3.183.75 and 11.x before 11.2.202.280 on Linux, before 11.1.111.50 on Android 2.x and 3.x, and before 11.1.115.54 on Android 4.x; Adobe AIR before 3.7.0.1530; and Adobe AIR SDK & Compiler before 3.7.0.1530 allows remote attackers to execute arbitrary code via unspecified vectors, as demonstrated by VUPEN during a Pwn2Own competition at CanSecWest 2013.


Published

2013-03-11T10:55:01.117

Last Modified

2025-04-11T00:51:21.963

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 10.0 (HIGH)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:C/I:C/A:C

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: COMPLETE
  • Integrity Impact: COMPLETE
  • Availability Impact: COMPLETE
Exploitability Score

10.0

Impact Score

10.0

Weaknesses
  • Type: Primary
    CWE-190

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application adobe flash_player ≤ 11.1.115.48 Yes
Operating System google android ≤ 4.4.4 No
Application adobe flash_player ≤ 11.1.111.44 Yes
Operating System google android ≤ 3.2.6 No
Application adobe flash_player ≤ 11.6.602.180 Yes
Operating System apple macos - No
Operating System microsoft windows - No
Application adobe flash_player ≤ 11.2.202.275 Yes
Operating System linux linux_kernel - No
Application adobe air ≤ 3.6.0.6090 Yes
Operating System apple macos - No
Operating System google android - No
Operating System microsoft windows - No
Operating System opensuse opensuse 11.4 Yes
Operating System opensuse opensuse 12.1 Yes
Operating System opensuse opensuse 12.2 Yes
Operating System opensuse opensuse 12.3 Yes
Operating System suse linux_enterprise_desktop 11 Yes
Operating System redhat enterprise_linux_desktop 6.0 Yes
Operating System redhat enterprise_linux_eus 5.9 Yes
Operating System redhat enterprise_linux_eus 6.4 Yes
Operating System redhat enterprise_linux_server 6.0 Yes
Operating System redhat enterprise_linux_server_aus 5.9 Yes
Operating System redhat enterprise_linux_server_aus 6.4 Yes
Operating System redhat enterprise_linux_workstation 6.0 Yes
Application adobe flash_player < 10.3.183.75 Yes
Operating System apple macos - No
Operating System microsoft windows - No
Application adobe flash_player ≤ 10.3.183.75 Yes
Operating System linux linux_kernel - No

References