← Vulnerability feed

Vulnerability record · CVE-2013-0634 · published 8 February 2013

CVE-2013-0634: Adobe Flash Player memory corruption via crafted SWF content

Adobe · Flash Player

Adobe Flash Player contains a memory corruption flaw (CWE-119) reachable through crafted SWF content. The description states it was exploited in the wild in February 2013, and it affects multiple platform-specific versions across Windows, Mac OS X, Linux and Android. Because Flash content is routinely embedded in web pages, this is a remotely reachable code execution issue with a broad install base.

9.3 CVSS 2.0 High EPSS 78% · top 0.5% CWE-119 · Memory buffer overflow
9.3CVSS 2.0 base score
78%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
10References
16 Jun 2026Last modified by NVD

Description

Adobe Flash Player before 10.3.183.51 and 11.x before 11.5.502.149 on Windows and Mac OS X, before 10.3.183.51 and 11.x before 11.2.202.262 on Linux, before 11.1.111.32 on Android 2.x and 3.x, and before 11.1.115.37 on Android 4.x allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted SWF content, as exploited in the wild in February 2013.

AV:N/AC:M/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

high priorityRemote unauthenticated code execution with confirmed in-the-wild exploitation and a very high EPSS score, though the product is legacy and largely retired.

What it is

Adobe Flash Player contains a memory corruption flaw (CWE-119) reachable through crafted SWF content. The description states it was exploited in the wild in February 2013, and it affects multiple platform-specific versions across Windows, Mac OS X, Linux and Android. Because Flash content is routinely embedded in web pages, this is a remotely reachable code execution issue with a broad install base.

Impact

An attacker can execute arbitrary code in the context of the Flash Player process, or crash it to cause a denial of service. Successful code execution typically gives the attacker the privileges of the user running the browser or Flash runtime.

Attack surface

Reached remotely over the network by delivering a malicious SWF file, for example via a web page or embedded content. The CVSS vector (AV:N/AC:M/Au:N) indicates no authentication is required and that some user action, such as loading the page or file, is needed.

Exploitation

The description explicitly states the flaw was exploited in the wild in February 2013. It is not listed in CISA KEV, but EPSS is very high (0.776, 99.5th percentile), consistent with active historical exploitation.

What to do

  • Apply the vendor patch per Adobe security bulletin APSB13-04 and update to the fixed Flash Player versions listed for each platform.
  • Apply the referenced Linux distribution updates (Red Hat RHSA-2013-0243 and openSUSE advisories) where Flash is packaged by the OS vendor.
  • If Flash cannot be patched or is no longer needed, disable or uninstall Flash Player and block SWF content at the browser and proxy level.
  • Restrict browsing to trusted sites and enforce click-to-play for plug-in content to reduce exposure to malicious SWF files.

Detection

  • Monitor for Flash Player process crashes or memory corruption events, which may indicate exploitation attempts.
  • Inspect proxy, IDS and web logs for SWF file downloads from untrusted or newly registered domains.
  • Hunt for suspicious child processes spawned by browser or Flash Player processes, a common post-exploitation pattern.
  • Review endpoint telemetry for anomalous behavior originating from the Flash Player process, such as unexpected network connections or file writes.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2013-0634 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2016-4171Adobe Flash Player unspecified remote code execution flawCVE-2016-4171 is an unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier that allows remote attackers to execute arbitrary code thr…KEVEPSS 20%analysed9.8CVE-2016-4117Adobe Flash Player unspecified vectors allow arbitrary code executionAdobe Flash Player 21.0.0.226 and earlier contains a critical flaw that lets remote attackers execute arbitrary code through unspecified vectors. Ado…KEVEPSS 94%analysed9.8CVE-2016-1019Adobe Flash Player memory corruption allows code executionAdobe Flash Player 21.0.0.197 and earlier contains an unspecified memory corruption flaw that can crash the application or allow arbitrary code execu…KEVEPSS 22%analysed9.8CVE-2015-5123Adobe Flash Player ActionScript 3 BitmapData use-after-freeAdobe Flash Player contains a use-after-free in the ActionScript 3 BitmapData class, triggered by crafted Flash content that overrides a valueOf func…KEVEPSS 19%analysed9.8CVE-2015-5122Adobe Flash Player ActionScript 3 Use-After-Free in DisplayObjectA use-after-free flaw in the DisplayObject class of Adobe Flash Player's ActionScript 3 implementation is triggered by crafted Flash content that mis…KEVEPSS 94%analysed9.8CVE-2015-5119Adobe Flash Player ActionScript 3 ByteArray use-after-freeA use-after-free flaw exists in the ByteArray class of the ActionScript 3 implementation in Adobe Flash Player. Crafted Flash content that overrides …KEVEPSS 99%analysed9.8CVE-2015-3113Adobe Flash Player heap buffer overflow allows remote code executionAdobe Flash Player contains a heap-based buffer overflow (CWE-122/CWE-787) reachable through unspecified vectors. It affects Flash Player before 13.0…KEVEPSS 100%analysed9.8CVE-2015-3043Adobe Flash Player memory corruption allows arbitrary code executionAdobe Flash Player contains an out-of-bounds write (CWE-787) that corrupts memory and can lead to arbitrary code execution or a denial of service. Th…KEVEPSS 74%analysed

Source: NIST National Vulnerability Database (record CVE-2013-0634), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.