7.5

CVE-2013-2461

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier and 6 Update 45 and earlier; the Oracle JRockit component in Oracle Fusion Middleware R27.7.5 and earlier and R28.2.7 and earlier; and OpenJDK 7 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries.  NOTE: the previous information is from the June and July 2013 CPU. Oracle has not commented on claims from another vendor that this issue allows remote attackers to bypass verification of XML signatures via vectors related to a "Missing check for [a] valid DOMCanonicalizationMethod canonicalization algorithm."

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
OracleJdk Version1.6.0 Updateupdate22
OracleJdk Version1.6.0 Updateupdate23
OracleJdk Version1.6.0 Updateupdate24
OracleJdk Version1.6.0 Updateupdate25
OracleJdk Version1.6.0 Updateupdate26
OracleJdk Version1.6.0 Updateupdate27
OracleJdk Version1.6.0 Updateupdate29
OracleJdk Version1.6.0 Updateupdate30
OracleJdk Version1.6.0 Updateupdate31
OracleJdk Version1.6.0 Updateupdate32
OracleJdk Version1.6.0 Updateupdate33
OracleJdk Version1.6.0 Updateupdate34
OracleJdk Version1.6.0 Updateupdate35
OracleJdk Version1.6.0 Updateupdate37
OracleJdk Version1.6.0 Updateupdate38
OracleJdk Version1.6.0 Updateupdate39
OracleJdk Version1.6.0 Updateupdate41
OracleJdk Version1.6.0 Updateupdate43
SunJdk Version1.6.0
SunJdk Version1.6.0 Updateupdate_10
SunJdk Version1.6.0 Updateupdate_11
SunJdk Version1.6.0 Updateupdate_12
SunJdk Version1.6.0 Updateupdate_13
SunJdk Version1.6.0 Updateupdate_14
SunJdk Version1.6.0 Updateupdate_15
SunJdk Version1.6.0 Updateupdate_16
SunJdk Version1.6.0 Updateupdate_17
SunJdk Version1.6.0 Updateupdate_18
SunJdk Version1.6.0 Updateupdate_19
SunJdk Version1.6.0 Updateupdate_20
SunJdk Version1.6.0 Updateupdate_21
SunJdk Version1.6.0 Updateupdate_3
SunJdk Version1.6.0 Updateupdate_4
SunJdk Version1.6.0 Updateupdate_5
SunJdk Version1.6.0 Updateupdate_6
SunJdk Version1.6.0 Updateupdate_7
SunJdk Version1.6.0 Updateupdate1
SunJdk Version1.6.0 Updateupdate1_b06
SunJdk Version1.6.0 Updateupdate2
OracleJre Version1.7.0
OracleJre Version1.7.0 Updateupdate1
OracleJre Version1.7.0 Updateupdate10
OracleJre Version1.7.0 Updateupdate11
OracleJre Version1.7.0 Updateupdate13
OracleJre Version1.7.0 Updateupdate15
OracleJre Version1.7.0 Updateupdate17
OracleJre Version1.7.0 Updateupdate2
OracleJre Version1.7.0 Updateupdate3
OracleJre Version1.7.0 Updateupdate4
OracleJre Version1.7.0 Updateupdate5
OracleJre Version1.7.0 Updateupdate6
OracleJre Version1.7.0 Updateupdate7
OracleJre Version1.7.0 Updateupdate9
OracleJrockit Version >= r27.7.1 <= r27.7.5
OracleJrockit Version >= r28.0.0 <= r28.2.7
OracleOpenjdk Version1.7.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 64.06% 0.982
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
http://seclists.org/fulldisclosure/2014/Dec/23
Third Party Advisory
Mailing List
http://marc.info/?l=bugtraq&m=137545592101387&w=2
Third Party Advisory
Mailing List
http://www.us-cert.gov/ncas/alerts/TA13-169A
Third Party Advisory
US Government Resource
http://marc.info/?l=bugtraq&m=137545505800971&w=2
Third Party Advisory
Mailing List
http://www.securityfocus.com/bid/60645
Third Party Advisory
VDB Entry
https://bugzilla.redhat.com/show_bug.cgi?id=975126
Third Party Advisory
Issue Tracking