[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247768

 
 

909

 
 

194555

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2013-1491Date: (C)2013-03-15   (M)2023-12-22


The Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, 6 Update 43 and earlier, 5.0 Update 41 and earlier, and JavaFX 2.2.7 and earlier allows remote attackers to execute arbitrary code via vectors related to 2D, as demonstrated by Joshua Drake during a Pwn2Own competition at CanSecWest 2013.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 10.0
Exploit Score: 10.0
Impact Score: 10.0
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: LOW
Authentication: NONE
Confidentiality: COMPLETE
Integrity: COMPLETE
Availability: COMPLETE
  
Reference:
APPLE-SA-2013-04-16-2
RHSA-2013:0757
RHSA-2013:0758
RHSA-2013:1455
RHSA-2013:1456
SSRT101252
SSRT101305
SUSE-SU-2013:0835
SUSE-SU-2013:0871
SUSE-SU-2013:0934
TA13-107A
http://h30499.www3.hp.com/t5/HP-Security-Research-Blog/Pwn2Own-2013/ba-p/5981157
http://www.oracle.com/technetwork/topics/security/javacpuapr2013-1928497.html
http://www.zdnet.com/pwn2own-down-go-all-the-browsers-7000012283/
https://twitter.com/thezdi/status/309438311112507392
oval:org.mitre.oval:def:16663
oval:org.mitre.oval:def:19482
oval:org.mitre.oval:def:19553

CPE    2
cpe:/a:oracle:jdk:1.7.0:update17
cpe:/a:oracle:jre:1.7.0:update17
CWE    1
CWE-94
OVAL    8
oval:org.secpod.oval:def:505435
oval:org.secpod.oval:def:505590
oval:org.secpod.oval:def:10782
oval:org.secpod.oval:def:505625
...

© SecPod Technologies