CVE-2013-0642 describes a critical buffer overflow vulnerability in multiple versions of Adobe Flash Player and Adobe AIR across various operating systems including Windows, Mac OS X, Linux, and Android. This flaw allows unauthenticated remote attackers to execute arbitrary code on affected systems with low attack complexity. While the vulnerability carries a CVSS score of 10.0, indicating maximum severity and impact (confidentiality, integrity, and availability are all compromised), it is not listed in CISA's KEV catalog and has no known public exploits or significant community discussion. Despite its high theoretical risk, there is no evidence of active exploitation or readily available exploit intelligence.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 10.3, < 10.3.183.63CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:* | ||
>= 11.6, < 11.6.602.168CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:* | ||
>= 10.3, < 10.3.183.61CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:* | ||
>= 11.2, < 11.2.202.270CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:* | ||
>= 11.1, < 11.1.111.43CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.