← Back to browse · API

CVE-2013-0648

Severity
HIGH
CVSS
8.8
EPSS
0.11094
Risk score
64.08
CISA KEV
Yes
PoC
No
Published
2013-02-27
Modified
2026-01-12
First seen
2026-08-07
Aliases
EUVD-2013-0659, GHSA-5M8P-88M5-5QQP
Products
Adobe:Flash Player, n/a:n/a n/a
Sources
euvd EUVD-2013-0659
cisa.gov CVE-2013-0648

Description

Unspecified vulnerability in the ExternalInterface ActionScript functionality in Adobe Flash Player before 10.3.183.67 and 11.x before 11.6.602.171 on Windows and Mac OS X, and before 10.3.183.67 and 11.x before 11.2.202.273 on Linux, allows remote attackers to execute arbitrary code via crafted SWF content, as exploited in the wild in February 2013.

References