CVE-2013-1371: Adobe Air

High severity, CVSS 10.0. EPSS: 5.1% chance of exploitation in the next 30 days.

Adobe Flash Player before 10.3.183.68 and 11.x before 11.6.602.180 on Windows and Mac OS X, before 10.3.183.68 and 11.x before 11.2.202.275 on Linux, before 11.1.111.44 on Android 2.x and 3.x, and before 11.1.115.48 on Android 4.x; Adobe AIR before 3.6.0.6090; Adobe AIR SDK before 3.6.0.6090; and Adobe AIR SDK & Compiler before 3.6.0.6090 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.

Affected products

  • Adobe Adobe Air: any version; up to and including 3.6.0.597; version 1.0 only; version 1.0.1 only; version 1.0.8.4990 only; version 1.0.4990 only; …
  • Adobe Adobe Air SDK: up to and including 3.6.0.597; version 3.0.0.4080 only; version 3.1.0.488 only; version 3.2.0.2070 only; version 3.3.0.3650 only; version 3.3.0.3690 only; …
  • Adobe Adobe Air SDK And Compiler: up to and including 3.6.0.599
  • Adobe Flash Player: up to and including 11.6.602.171; version 11.0 only; version 11.0.1.152 only; version 11.0.1.153 only; version 11.1 only; version 11.1.102.55 only; …
  • Adobe Flash Player For Android: up to and including 11.1.111.43; version 10.1.106.17 only; version 10.2.157.51 only; version 10.3.186.7 only; version 11.0.1.153 only; version 11.1.102.59 only; …

Published 2013-03-13. Last modified 2026-06-16.