[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248392

 
 

909

 
 

195452

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2013-2451Date: (C)2013-06-18   (M)2023-12-22


Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier and 6 Update 45 and earlier, and OpenJDK 7, allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Networking. NOTE: the previous information is from the June 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to improper enforcement of exclusive port binds when running on Windows, which allows attackers to bind to ports that are already in use.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 3.7
Exploit Score: 1.9
Impact Score: 6.4
 
CVSS V2 Metrics:
Access Vector: LOCAL
Access Complexity: HIGH
Authentication: NONE
Confidentiality: PARTIAL
Integrity: PARTIAL
Availability: PARTIAL
  
Reference:
SECUNIA-54154
BID-60625
GLSA-201406-32
HPSBUX02908
RHSA-2013:0963
RHSA-2013:1059
RHSA-2013:1060
RHSA-2013:1455
RHSA-2013:1456
RHSA-2014:0414
SUSE-SU-2013:1255
SUSE-SU-2013:1257
SUSE-SU-2013:1305
TA13-169A
http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=975146
http://hg.openjdk.java.net/jdk7u/jdk7u-dev/jdk/rev/8dd8266a2f4b
http://www-01.ibm.com/support/docview.wss?uid=swg21642336
http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html
oval:org.mitre.oval:def:17265
oval:org.mitre.oval:def:19535

CPE    70
cpe:/a:sun:jre:1.6.0:update_21
cpe:/a:sun:jre:1.6.0:update_20
cpe:/a:sun:jre:1.6.0:update_16
cpe:/a:sun:jre:1.6.0:update_15
...
OVAL    12
oval:org.secpod.oval:def:15567
oval:org.secpod.oval:def:14222
oval:org.secpod.oval:def:14242
oval:org.secpod.oval:def:701364
...

© SecPod Technologies