Lucene search

K
cveAdobeCVE-2013-0644
HistoryFeb 12, 2013 - 8:55 p.m.

CVE-2013-0644

2013-02-1220:55:04
CWE-399
adobe
web.nvd.nist.gov
38
adobe flash player
cve-2013-0644
use-after-free
vulnerability
security
adobe air
adobe air sdk

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

7.3

Confidence

Low

EPSS

0.012

Percentile

85.5%

Use-after-free vulnerability in Adobe Flash Player before 10.3.183.63 and 11.x before 11.6.602.168 on Windows, before 10.3.183.61 and 11.x before 11.6.602.167 on Mac OS X, before 10.3.183.61 and 11.x before 11.2.202.270 on Linux, before 11.1.111.43 on Android 2.x and 3.x, and before 11.1.115.47 on Android 4.x; Adobe AIR before 3.6.0.597; and Adobe AIR SDK before 3.6.0.599 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2013-0649 and CVE-2013-1374.

Affected configurations

Nvd
Node
adobeflash_playerRange10.310.3.183.63
OR
adobeflash_playerRange11.611.6.602.168
AND
microsoftwindowsMatch-
Node
adobeflash_playerRange10.310.3.183.61
OR
adobeflash_playerRange11.211.2.202.270
AND
linuxlinux_kernelMatch-
Node
adobeflash_playerRange11.111.1.111.43
AND
googleandroidRange2.02.3.7
OR
googleandroidRange3.03.2.6
Node
adobeflash_playerRange11.111.1.115.47
AND
googleandroidRange4.04.4.4
Node
adobeairRange<3.6.0.597
OR
adobeair_sdkRange<3.6.0.599
Node
adobeflash_playerRange10.310.3.183.61
OR
adobeflash_playerRange11.611.6.602.167
AND
applemac_os_xMatch-
VendorProductVersionCPE
adobeflash_player*cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:*
microsoftwindows-cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
linuxlinux_kernel-cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
googleandroid*cpe:2.3:o:google:android:*:*:*:*:*:*:*:*
adobeair*cpe:2.3:a:adobe:air:*:*:*:*:*:*:*:*
adobeair_sdk*cpe:2.3:a:adobe:air_sdk:*:*:*:*:*:*:*:*
applemac_os_x-cpe:2.3:o:apple:mac_os_x:-:*:*:*:*:*:*:*

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

7.3

Confidence

Low

EPSS

0.012

Percentile

85.5%