CVE-2013-3347 describes an integer overflow vulnerability in Adobe Flash Player across multiple versions and operating systems, including Windows, macOS, Linux, and Android. This flaw allows unauthenticated attackers to achieve arbitrary code execution by crafting malicious PCM data that is mishandled during resampling. With a CVSS score of 10.0, this vulnerability is critical, indicating a network-based attack with low complexity and complete compromise of confidentiality, integrity, and availability. Despite its severity, there is no evidence of active exploitation, publicly available exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 11.7.700.224CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:* | ||
11.0CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:11.0:*:*:*:*:*:*:* | ||
11.0.1.152CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:11.0.1.152:*:*:*:*:*:*:* | ||
11.0.1.153CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:11.0.1.153:*:*:*:*:*:*:* | ||
11.1CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:11.1:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.