Adobe Flash Player before 10.3.183.51 and 11.x before 11.5.502.149 on Windows and Mac OS X, before 10.3.183.51 and 11.x before 11.2.202.262 on Linux, before 11.1.111.32 on Android 2.x and 3.x, and before 11.1.115.37 on Android 4.x allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted SWF content, as exploited in the wild in February 2013.
CVSS Details
- CVSS 3.1 Base Score: 8.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Adobe Air | — | Upgrade to the latest version of Adobe AIR | Feb 15, 2013 | Feb 8, 2013 |
| Adobe Flash Apsb13 04 | — | Upgrade to Adobe Flash Player version 10.3.183.51 for LinuxUpgrade to Adobe Flash Player version 10.3.183.51 for WindowsUpgrade to Adobe Flash Player version 11.5.502.149 for Mac OS XUpgrade to Adobe Flash Player version 10.3.183.51 for Mac OS XUpgrade to Adobe Flash Player version 11.5.502.149 for WindowsUpgrade to Adobe Flash Player version 11.2.202.262 for Linux | Feb 8, 2013 | Feb 7, 2013 |
| Freebsd | — | Upgrade linux-f10-flashplugin | Dec 10, 2025 | Feb 8, 2013 |
| Gentoo Linux | — | Upgrade www-plugins/adobe-flash. | Oct 30, 2017 | Feb 8, 2013 |
| Suse | — | Upgrade flash-playerUpgrade flash-player-kde4Upgrade flash-player-gnome | Feb 17, 2015 | Feb 8, 2013 |
| Ubuntu | — | Upgrade flashplugin-nonfreeUpgrade adobe-flashplugin | Nov 19, 2024 | Feb 8, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub