Skip to main content

CVE detail

CVE-2013-0648

Unspecified vulnerability in the ExternalInterface ActionScript functionality in Adobe Flash Player before 10.3.183.67 and 11.x before 11.6.602.171 on Windows and Mac OS X, and before 10.3.183.67 and 11.x before 11.2.202.273 on Linux, allows remote attackers to execute arbitrary code via crafted SWF content, as exploited in the wild in February 2013.

CVSS 8.8 · HighBuzz score 46.9KEV listed

Buzz score

Why this CVE is surfacing

Buzz score total 46.9

This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.

Buzz score components · mention 13.9 · diversity 8.0 · KEV 25.0 · OTX 0.0 · PoC 0.0
Mention score
13.9
3 evidence mentions in the snapshot
Diversity score
8.0
3 sources across 1 categories
KEV score
25.0
Known exploited vulnerability present
OTX score
0.0
0 OTX pulses
PoC score
0.0
0 repos · best confidence N/A
Best PoC traction
0
Maximum stars on a matched PoC repo

Why it matters now

Mention timeline

Total mentions
0
within the 30d window
Peak daily
0
highest bucket

Evidence

Source links by recency

Newest mentions first
3 source links · newest first
  • Adobe is urging users to update their Flash Player for the third time this month, as once again the company is aware of vulnerabilities being exploited in the wild in targeted attacks. The attackers are trying to trick users into clicking a link which directs to a website serving malicious Flash (SWF) content and, according to the security bulletin released by Adobe, Firefox users are particularly at risk. The update fixes three vulnerabilities in total … More →

    newswww.helpnetsecurity.comFeb 27, 2013, 6:54 AM
  • Adobe Systems plugged multiple security holes in Flash Player that today have come under attack in the wild, marking the third security update issued for the product this month.

    newswww.securityweek.comFeb 26, 2013, 9:07 PM
  • Adobe today patched new vulnerabilities in Flash Player that hackers are now exploiting in attacks aimed at Firefox users, the company said. Today’s surprise update to Flash Player was the second emergency fix this month, the third overall for February, and the fourth since the start of 2013. In the accompanying advisory, Adobe confirmed it […]

    newswww.csoonline.comFeb 26, 2013, 3:00 PM

Exploit code

Public exploit repository references

Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.

0 repository references · best confidence N/A · max 0 stars
No public PoC repositories have been matched yet.

Related records

Similar CVEs

6 related CVEs with shared weakness or product evidence