Integer overflow in Adobe Flash Player before 11.7.700.232 and 11.8.x before 11.8.800.94 on Windows and Mac OS X, before 11.2.202.297 on Linux, before 11.1.111.64 on Android 2.x and 3.x, and before 11.1.115.69 on Android 4.x allows attackers to execute arbitrary code via PCM data that is not properly handled during resampling.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Adobe Air | — | Upgrade to the latest version of Adobe AIR | Jul 29, 2013 | Jul 10, 2013 |
| Adobe Flash Apsb13 17 | — | Upgrade to Adobe Flash Player version 11.8.800.94 for Mac OS XUpgrade to Adobe Flash Player version 11.7.700.232 for WindowsUpgrade to Adobe Flash Player version 11.8.800.94 for WindowsUpgrade to Adobe Flash Player version 11.2.202.297 for LinuxUpgrade to Adobe Flash Player version 11.7.700.232 for Mac OS X | Jul 9, 2013 | Jul 9, 2013 |
| Freebsd | — | Upgrade linux-f10-flashplugin | Dec 10, 2025 | Jul 15, 2013 |
| Gentoo Linux | — | Upgrade www-plugins/adobe-flash. | Oct 30, 2017 | Jul 10, 2013 |
| Suse | — | Upgrade flash-player-kde4Upgrade flash-player-gnomeUpgrade flash-player | Feb 17, 2015 | Jul 10, 2013 |
| Ubuntu | — | Upgrade flashplugin-nonfreeUpgrade adobe-flashplugin | Nov 19, 2024 | Jul 10, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub