CVE-2013-5332

critical
Published 2013-12-11 · Modified 2026-04-29
CVSS v3
VIR risk
9.3

Description

Adobe Flash Player before 11.7.700.257 and 11.8.x and 11.9.x before 11.9.900.170 on Windows and Mac OS X and before 11.2.202.332 on Linux, Adobe AIR before 3.9.0.1380, Adobe AIR SDK before 3.9.0.1380, and Adobe AIR SDK & Compiler before 3.9.0.1380 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

No vendor mitigations ingested yet for this CVE. The mitigation-content worker queues fetches as references arrive — check back in a few minutes, or see the references list below.

OS impact

OSVersionStatusFixed in
linux linux-kernel-not-affected
macos macos-not-affected

Application impact

VendorProductVersionsFixed
adobe adobeflash_player{"startIncluding":"11.0","endExcluding":"11.7.700.257"}11.7.700.257
adobe adobeair{"endExcluding":"3.9.0.1380"}3.9.0.1380
adobe adobeair_sdk{"endExcluding":"3.9.0.1380"}3.9.0.1380

References

CWEs

CWE-94

💬 Discuss CVE-2013-5332 on VIR Community →

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.