CVE-2013-5329

critical
Published 2013-11-13 · Modified 2026-04-29
CVSS v3
CVSS v2
10.0
VIR risk
10.0

Description

Adobe Flash Player before 11.7.700.252 and 11.8.x and 11.9.x before 11.9.900.152 on Windows and Mac OS X and before 11.2.202.327 on Linux, Adobe AIR before 3.9.0.1210, Adobe AIR SDK before 3.9.0.1210, and Adobe AIR SDK & Compiler before 3.9.0.1210 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-5330.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: psirt@adobe.com — http://www.adobe.com/support/security/bulletins/apsb13-26.html

OS impact

OSVersionStatusFixed in
linux linux-kernel-not-affected
macos macos-not-affected

Application impact

VendorProductVersionsFixed
adobeflash_player{"startIncluding":"11.0","endExcluding":"11.7.700.252"}11.7.700.252
adobeair{"endExcluding":"3.9.0.1210"}3.9.0.1210
adobeair_sdk{"endExcluding":"3.9.0.1210"}3.9.0.1210

References

CWEs

CWE-119

Verify integrity in audit chain (admin only). AS-IS.