CVE-2013-3347

critical
Published 2013-07-10 · Modified 2026-04-29
CVSS v3
CVSS v2
10.0
VIR risk
10.0

Description

Integer overflow in Adobe Flash Player before 11.7.700.232 and 11.8.x before 11.8.800.94 on Windows and Mac OS X, before 11.2.202.297 on Linux, before 11.1.111.64 on Android 2.x and 3.x, and before 11.1.115.69 on Android 4.x allows attackers to execute arbitrary code via PCM data that is not properly handled during resampling.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: psirt@adobe.com — http://www.adobe.com/support/security/bulletins/apsb13-17.html

OS impact

OSVersionStatusFixed in
macos macosnot-affected
linux linux-kernelnot-affected

Application impact

VendorProductVersionsFixed
adobeflash_player{"endIncluding":"11.7.700.224"}
adobeflash_player11.0
adobeflash_player11.0.1.152
adobeflash_player11.0.1.153
adobeflash_player11.1
adobeflash_player11.1.102.55
adobeflash_player11.1.102.59
adobeflash_player11.1.102.62
adobeflash_player11.1.102.63
adobeflash_player11.1.111.8
adobeflash_player11.1.111.44
adobeflash_player11.1.111.50
adobeflash_player11.1.111.54
adobeflash_player11.1.115.7
adobeflash_player11.1.115.34
adobeflash_player11.1.115.48
adobeflash_player11.1.115.54
adobeflash_player11.1.115.58
adobeflash_player11.2.202.223
adobeflash_player11.2.202.228
adobeflash_player11.2.202.233
adobeflash_player11.2.202.235
adobeflash_player11.2.202.236
adobeflash_player11.2.202.238
adobeflash_player11.2.202.243
adobeflash_player11.2.202.251
adobeflash_player11.2.202.258
adobeflash_player11.2.202.261
adobeflash_player11.2.202.262
adobeflash_player11.2.202.270
adobeflash_player11.2.202.273
adobeflash_player11.2.202.275
adobeflash_player11.2.202.280
adobeflash_player11.2.202.285
adobeflash_player11.3.300.257
adobeflash_player11.3.300.262
adobeflash_player11.3.300.265
adobeflash_player11.3.300.268
adobeflash_player11.3.300.270
adobeflash_player11.3.300.271
adobeflash_player11.3.300.273
adobeflash_player11.4.402.265
adobeflash_player11.4.402.278
adobeflash_player11.4.402.287
adobeflash_player11.5.502.110
adobeflash_player11.5.502.135
adobeflash_player11.5.502.136
adobeflash_player11.5.502.146
adobeflash_player11.5.502.149
adobeflash_player11.6.602.167
adobeflash_player11.6.602.168
adobeflash_player11.6.602.171
adobeflash_player11.6.602.180
adobeflash_player11.7.700.169
adobeflash_player11.7.700.202
adobeflash_player11.7.700.224

References

CWEs

CWE-189

Verify integrity in audit chain (admin only). AS-IS.