First published: Fri Jan 11 2013(Updated: )
Buffer overflow in Adobe Flash Player before 10.3.183.50 and 11.x before 11.5.502.146 on Windows and Mac OS X, before 10.3.183.50 and 11.x before 11.2.202.261 on Linux, before 11.1.111.31 on Android 2.x and 3.x, and before 11.1.115.36 on Android 4.x; Adobe AIR before 3.5.0.1060; and Adobe AIR SDK before 3.5.0.1060 allows attackers to execute arbitrary code via unspecified vectors.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Macromedia Flash Player | <=10.3.183.48 | |
Macromedia Flash Player | =10.3.181.14 | |
Macromedia Flash Player | =10.3.181.16 | |
Macromedia Flash Player | =10.3.181.22 | |
Macromedia Flash Player | =10.3.181.23 | |
Macromedia Flash Player | =10.3.181.26 | |
Macromedia Flash Player | =10.3.181.34 | |
Macromedia Flash Player | =10.3.183.5 | |
Macromedia Flash Player | =10.3.183.7 | |
Macromedia Flash Player | =10.3.183.10 | |
Macromedia Flash Player | =10.3.183.11 | |
Macromedia Flash Player | =10.3.183.15 | |
Macromedia Flash Player | =10.3.183.16 | |
Macromedia Flash Player | =10.3.183.18 | |
Macromedia Flash Player | =10.3.183.19 | |
Macromedia Flash Player | =10.3.183.20 | |
Macromedia Flash Player | =10.3.183.23 | |
Macromedia Flash Player | =10.3.183.25 | |
Macromedia Flash Player | =10.3.183.29 | |
Macromedia Flash Player | =10.3.183.43 | |
Apple iOS and macOS | ||
Linux Kernel | ||
Microsoft Windows | ||
Macromedia Flash Player | <=11.5.502.136 | |
Macromedia Flash Player | =11.5.502.110 | |
Macromedia Flash Player | =11.5.502.135 | |
Macromedia Flash Player | <=11.2.202.258 | |
Macromedia Flash Player | =11.2.202.223 | |
Macromedia Flash Player | =11.2.202.228 | |
Macromedia Flash Player | =11.2.202.233 | |
Macromedia Flash Player | =11.2.202.235 | |
Macromedia Flash Player | =11.2.202.236 | |
Macromedia Flash Player | =11.2.202.238 | |
Macromedia Flash Player | =11.2.202.243 | |
Adobe Flash Player | <=11.1.115.34 | |
Adobe Flash Player | =11.1.115.6 | |
Adobe Flash Player | =11.1.115.7 | |
Adobe Flash Player | =11.1.115.8 | |
Adobe Flash Player | =11.1.115.11 | |
Adobe Flash Player | =11.1.115.12 | |
Adobe Flash Player | =11.1.115.17 | |
Adobe Flash Player | =11.1.115.20 | |
Adobe Flash Player | =11.1.115.27 | |
Android | =4.0 | |
Android | =4.0.1 | |
Android | =4.0.2 | |
Android | =4.0.3 | |
Android | =4.0.4 | |
Android | =4.1 | |
Android | =4.2 | |
Adobe Flash Player | <=11.1.111.29 | |
Adobe Flash Player | =11.0.1.153 | |
Adobe Flash Player | =11.1.102.59 | |
Adobe Flash Player | =11.1.111.5 | |
Adobe Flash Player | =11.1.111.6 | |
Adobe Flash Player | =11.1.111.7 | |
Adobe Flash Player | =11.1.111.8 | |
Adobe Flash Player | =11.1.111.9 | |
Adobe Flash Player | =11.1.111.10 | |
Adobe Flash Player | =11.1.111.16 | |
Adobe Flash Player | =11.1.111.19 | |
Adobe Flash Player | =11.1.111.24 | |
Android | =2.0 | |
Android | =2.0.1 | |
Android | =2.1 | |
Android | =2.2 | |
Android | =2.2-rev1 | |
Android | =2.2.1 | |
Android | =2.2.2 | |
Android | =2.2.3 | |
Android | =2.3 | |
Android | =2.3-rev1 | |
Android | =2.3.1 | |
Android | =2.3.2 | |
Android | =2.3.3 | |
Android | =2.3.4 | |
Android | =2.3.5 | |
Android | =2.3.6 | |
Android | =2.3.7 | |
Android | =3.0 | |
Android | =3.1 | |
Android | =3.2 | |
Android | =3.2.1 | |
Android | =3.2.2 | |
Android | =3.2.4 | |
Android | =3.2.6 | |
Adobe | <=3.5.0.890 | |
Adobe | =3.5.0.600 | |
Adobe | =3.5.0.880 | |
Adobe AIR SDK | <=3.5.0.890 | |
Adobe AIR SDK | =3.5.0.600 | |
Adobe AIR SDK | =3.5.0.880 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-0630 is classified as a critical severity vulnerability due to the buffer overflow vulnerability it introduces.
To fix CVE-2013-0630, users should update Adobe Flash Player to versions 10.3.183.50 or later for Windows and Mac OS X, and corresponding versions for other affected platforms.
CVE-2013-0630 affects Adobe Flash Player on Windows, Mac OS X, Linux, and Android devices, as well as Adobe AIR on various platforms.
Exploiting CVE-2013-0630 can allow attackers to execute arbitrary code, potentially compromising the affected system.
CVE-2013-0630 was published in January 2013.