CVE-2013-0633 describes a critical buffer overflow vulnerability in Adobe Flash Player across Windows, Mac OS X, Linux, and Android platforms. This flaw allowed remote attackers to execute arbitrary code through specially crafted SWF content. With a CVSS score of 9.3, it was highly severe, requiring no authentication and moderate attack complexity, leading to complete compromise of confidentiality, integrity, and availability. This vulnerability was actively exploited in the wild in February 2013, with public exploit code available (EDB-32959) and significant community and media attention, including its use in the Blackhole Exploit Kit and DaVinci surveillance malware.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 10.3, < 10.3.183.51CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:* | ||
>= 11.5, < 11.5.502.149CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:* | ||
>= 11.2, < 11.2.202.262CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:* | ||
>= 11.1, < 11.1.111.32CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:* | ||
>= 11.1, < 11.1.115.37CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.