CVE-2013-3347

critical
Published 2013-07-10 ยท Modified 2026-04-29
CVSS v3
โ€”
CVSS v4 NEW
โ€”
not yet in upstream
VIR risk
10.0

Description

Integer overflow in Adobe Flash Player before 11.7.700.232 and 11.8.x before 11.8.800.94 on Windows and Mac OS X, before 11.2.202.297 on Linux, before 11.1.111.64 on Android 2.x and 3.x, and before 11.1.115.69 on Android 4.x allows attackers to execute arbitrary code via PCM data that is not properly handled during resampling.

Predictions

Exploit likelihood
20%
Patch ETA
โ€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

No mitigations published for this CVE yet.

The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or โ€” if you've already worked around this in production โ€” publish your fix to the community-verified tier.

โœš Propose a mitigation on Community โ†’ Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here with source_tier=community-verified.

OS impact

linux Linux kernel Fixed 1 release
VersionStatusFixed in
โ€” Not affected โ€”
macos macOS Fixed 1 release
VersionStatusFixed in
โ€” Not affected โ€”

Application impact

VendorProductVersionsFixed
adobe adobeflash_player{"endIncluding":"11.7.700.224"}
adobe adobeflash_player11.0
adobe adobeflash_player11.0.1.152
adobe adobeflash_player11.0.1.153
adobe adobeflash_player11.1
adobe adobeflash_player11.1.102.55
adobe adobeflash_player11.1.102.59
adobe adobeflash_player11.1.102.62
adobe adobeflash_player11.1.102.63
adobe adobeflash_player11.1.111.8
adobe adobeflash_player11.1.111.44
adobe adobeflash_player11.1.111.50
adobe adobeflash_player11.1.111.54
adobe adobeflash_player11.1.115.7
adobe adobeflash_player11.1.115.34
adobe adobeflash_player11.1.115.48
adobe adobeflash_player11.1.115.54
adobe adobeflash_player11.1.115.58
adobe adobeflash_player11.2.202.223
adobe adobeflash_player11.2.202.228
adobe adobeflash_player11.2.202.233
adobe adobeflash_player11.2.202.235
adobe adobeflash_player11.2.202.236
adobe adobeflash_player11.2.202.238
adobe adobeflash_player11.2.202.243
adobe adobeflash_player11.2.202.251
adobe adobeflash_player11.2.202.258
adobe adobeflash_player11.2.202.261
adobe adobeflash_player11.2.202.262
adobe adobeflash_player11.2.202.270
adobe adobeflash_player11.2.202.273
adobe adobeflash_player11.2.202.275
adobe adobeflash_player11.2.202.280
adobe adobeflash_player11.2.202.285
adobe adobeflash_player11.3.300.257
adobe adobeflash_player11.3.300.262
adobe adobeflash_player11.3.300.265
adobe adobeflash_player11.3.300.268
adobe adobeflash_player11.3.300.270
adobe adobeflash_player11.3.300.271
adobe adobeflash_player11.3.300.273
adobe adobeflash_player11.4.402.265
adobe adobeflash_player11.4.402.278
adobe adobeflash_player11.4.402.287
adobe adobeflash_player11.5.502.110
adobe adobeflash_player11.5.502.135
adobe adobeflash_player11.5.502.136
adobe adobeflash_player11.5.502.146
adobe adobeflash_player11.5.502.149
adobe adobeflash_player11.6.602.167
adobe adobeflash_player11.6.602.168
adobe adobeflash_player11.6.602.171
adobe adobeflash_player11.6.602.180
adobe adobeflash_player11.7.700.169
adobe adobeflash_player11.7.700.202
adobe adobeflash_player11.7.700.224

References

CWEs

CWE-189

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.