[Forgot Password]
Login  Register Subscribe

30389

 
 

423868

 
 

244411

 
 

909

 
 

193363

 
 

277

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2013-2470Date: (C)2013-06-18   (M)2023-12-22


Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier, and OpenJDK 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D. NOTE: the previous information is from the June 2013 CPU. Oracle has not commented on claims from another vendor that this issue allows remote attackers to bypass the Java sandbox via vectors related to "ImagingLib byte lookup processing."

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 10.0
Exploit Score: 10.0
Impact Score: 10.0
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: LOW
Authentication: NONE
Confidentiality: COMPLETE
Integrity: COMPLETE
Availability: COMPLETE
  
Reference:
SECUNIA-54154
BID-60651
GLSA-201406-32
HPSBUX02907
HPSBUX02908
MDVSA-2013:183
RHSA-2013:0963
RHSA-2013:1059
RHSA-2013:1060
RHSA-2013:1081
RHSA-2013:1455
RHSA-2013:1456
RHSA-2014:0414
SSRT101305
SUSE-SU-2013:1255
SUSE-SU-2013:1256
SUSE-SU-2013:1257
SUSE-SU-2013:1263
SUSE-SU-2013:1264
SUSE-SU-2013:1293
SUSE-SU-2013:1305
TA13-169A
http://advisories.mageia.org/MGASA-2013-0185.html
http://hg.openjdk.java.net/jdk7u/jdk7u-dev/jdk/rev/89d9ec9e80c1
http://www-01.ibm.com/support/docview.wss?uid=swg21642336
http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html
https://bugzilla.redhat.com/show_bug.cgi?id=975099
oval:org.mitre.oval:def:16806
oval:org.mitre.oval:def:19348
oval:org.mitre.oval:def:19517
oval:org.mitre.oval:def:19655

CPE    136
cpe:/a:sun:jre:1.5.0:update19
cpe:/a:sun:jre:1.5.0:update18
cpe:/a:sun:jre:1.5.0:update17
cpe:/a:sun:jre:1.5.0:update23
...
OVAL    25
oval:org.secpod.oval:def:501095
oval:org.secpod.oval:def:1500225
oval:org.secpod.oval:def:1600297
oval:org.secpod.oval:def:1500229
...

© SecPod Technologies