CVE Vulnerabilities

CVE-2013-0648

Published: Feb 27, 2013 | Modified: Dec 20, 2024
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS 2.x
9.3 HIGH
AV:N/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
6.8 CRITICAL
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V3
Ubuntu
MEDIUM

Unspecified vulnerability in the ExternalInterface ActionScript functionality in Adobe Flash Player before 10.3.183.67 and 11.x before 11.6.602.171 on Windows and Mac OS X, and before 10.3.183.67 and 11.x before 11.2.202.273 on Linux, allows remote attackers to execute arbitrary code via crafted SWF content, as exploited in the wild in February 2013.

Affected Software

Name Vendor Start Version End Version
Flash_player Adobe * 10.3.183.67 (excluding)
Flash_player Adobe 11.0 (including) 11.6.602.171 (excluding)
Supplementary for Red Hat Enterprise Linux 5 RedHat flash-plugin-0:11.2.202.273-1.el5 *
Supplementary for Red Hat Enterprise Linux 6 RedHat flash-plugin-0:11.2.202.273-1.el6 *
Adobe-flashplugin Ubuntu hardy *
Adobe-flashplugin Ubuntu lucid *
Adobe-flashplugin Ubuntu oneiric *
Adobe-flashplugin Ubuntu precise *
Adobe-flashplugin Ubuntu quantal *
Adobe-flashplugin Ubuntu upstream *
Flashplugin-nonfree Ubuntu devel *
Flashplugin-nonfree Ubuntu hardy *
Flashplugin-nonfree Ubuntu lucid *
Flashplugin-nonfree Ubuntu oneiric *
Flashplugin-nonfree Ubuntu precise *
Flashplugin-nonfree Ubuntu quantal *
Flashplugin-nonfree Ubuntu upstream *

References