[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248268

 
 

909

 
 

195051

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2013-1480Date: (C)2013-02-02   (M)2024-04-19


Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, 5.0 through Update 38, and 1.4.2_40 and earlier, and OpenJDK 6 and 7, allows remote attackers to affect confidentiality, integrity, and availability via vectors related to AWT. NOTE: the previous information is from the February 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to "insufficient validation of raster parameters" in awt_parseImage.c, which triggers memory corruption.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 10.0
Exploit Score: 10.0
Impact Score: 10.0
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: LOW
Authentication: NONE
Confidentiality: COMPLETE
Integrity: COMPLETE
Availability: COMPLETE
  
Reference:
BID-57691
GLSA-201406-32
HPSBMU02874
HPSBUX02857
MDVSA-2013:095
RHSA-2013:0236
RHSA-2013:0237
RHSA-2013:0245
RHSA-2013:0246
RHSA-2013:0247
RHSA-2013:1455
RHSA-2013:1456
SSRT101156
SUSE-SU-2013:0478
TA13-032A
VU#858729
http://icedtea.classpath.org/hg/release/icedtea6-1.11/file/icedtea6-1.11.6/NEWS
http://icedtea.classpath.org/hg/release/icedtea7-forest-2.3/jdk/rev/50e268c1fb1f
http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html
https://bugzilla.redhat.com/show_bug.cgi?id=906904
https://wiki.mageia.org/en/Support/Advisories/MGASA-2013-0056
openSUSE-SU-2013:0377
oval:org.mitre.oval:def:16045
oval:org.mitre.oval:def:18845
oval:org.mitre.oval:def:19351
oval:org.mitre.oval:def:19504

CPE    207
cpe:/a:sun:jre:1.5.0:update19
cpe:/a:sun:jre:1.5.0:update18
cpe:/a:sun:jre:1.5.0:update17
cpe:/a:sun:jre:1.5.0:update23
...
OVAL    29
oval:org.secpod.oval:def:202552
oval:org.secpod.oval:def:9130
oval:org.secpod.oval:def:202549
oval:org.secpod.oval:def:202548
...

© SecPod Technologies