7.5

CVE-2013-2461

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier and 6 Update 45 and earlier; the Oracle JRockit component in Oracle Fusion Middleware R27.7.5 and earlier and R28.2.7 and earlier; and OpenJDK 7 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries.  NOTE: the previous information is from the June and July 2013 CPU. Oracle has not commented on claims from another vendor that this issue allows remote attackers to bypass verification of XML signatures via vectors related to a "Missing check for [a] valid DOMCanonicalizationMethod canonicalization algorithm."
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Oracle ≫ Jdk Version 1.6.0 Update update22
Oracle ≫ Jdk Version 1.6.0 Update update23
Oracle ≫ Jdk Version 1.6.0 Update update24
Oracle ≫ Jdk Version 1.6.0 Update update25
Oracle ≫ Jdk Version 1.6.0 Update update26
Oracle ≫ Jdk Version 1.6.0 Update update27
Oracle ≫ Jdk Version 1.6.0 Update update29
Oracle ≫ Jdk Version 1.6.0 Update update30
Oracle ≫ Jdk Version 1.6.0 Update update31
Oracle ≫ Jdk Version 1.6.0 Update update32
Oracle ≫ Jdk Version 1.6.0 Update update33
Oracle ≫ Jdk Version 1.6.0 Update update34
Oracle ≫ Jdk Version 1.6.0 Update update35
Oracle ≫ Jdk Version 1.6.0 Update update37
Oracle ≫ Jdk Version 1.6.0 Update update38
Oracle ≫ Jdk Version 1.6.0 Update update39
Oracle ≫ Jdk Version 1.6.0 Update update41
Oracle ≫ Jdk Version 1.6.0 Update update43
Sun ≫ Jdk Version 1.6.0
Sun ≫ Jdk Version 1.6.0 Update update_10
Sun ≫ Jdk Version 1.6.0 Update update_11
Sun ≫ Jdk Version 1.6.0 Update update_12
Sun ≫ Jdk Version 1.6.0 Update update_13
Sun ≫ Jdk Version 1.6.0 Update update_14
Sun ≫ Jdk Version 1.6.0 Update update_15
Sun ≫ Jdk Version 1.6.0 Update update_16
Sun ≫ Jdk Version 1.6.0 Update update_17
Sun ≫ Jdk Version 1.6.0 Update update_18
Sun ≫ Jdk Version 1.6.0 Update update_19
Sun ≫ Jdk Version 1.6.0 Update update_20
Sun ≫ Jdk Version 1.6.0 Update update_21
Sun ≫ Jdk Version 1.6.0 Update update_3
Sun ≫ Jdk Version 1.6.0 Update update_4
Sun ≫ Jdk Version 1.6.0 Update update_5
Sun ≫ Jdk Version 1.6.0 Update update_6
Sun ≫ Jdk Version 1.6.0 Update update_7
Sun ≫ Jdk Version 1.6.0 Update update1
Sun ≫ Jdk Version 1.6.0 Update update1_b06
Sun ≫ Jdk Version 1.6.0 Update update2
Oracle ≫ Jre Version 1.7.0
Oracle ≫ Jre Version 1.7.0 Update update1
Oracle ≫ Jre Version 1.7.0 Update update10
Oracle ≫ Jre Version 1.7.0 Update update11
Oracle ≫ Jre Version 1.7.0 Update update13
Oracle ≫ Jre Version 1.7.0 Update update15
Oracle ≫ Jre Version 1.7.0 Update update17
Oracle ≫ Jre Version 1.7.0 Update update2
Oracle ≫ Jre Version 1.7.0 Update update3
Oracle ≫ Jre Version 1.7.0 Update update4
Oracle ≫ Jre Version 1.7.0 Update update5
Oracle ≫ Jre Version 1.7.0 Update update6
Oracle ≫ Jre Version 1.7.0 Update update7
Oracle ≫ Jre Version 1.7.0 Update update9
Oracle ≫ Jrockit Version >= r27.7.1 <= r27.7.5
Oracle ≫ Jrockit Version >= r28.0.0 <= r28.2.7
Oracle ≫ Openjdk Version 1.7.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 6.75% 0.931
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://www.oracle.com/technetwork/topics/security/cpujuly2013-1899826.html
Vendor Advisory
http://security.gentoo.org/glsa/glsa-201406-32.xml
Third Party Advisory
http://seclists.org/fulldisclosure/2014/Dec/23
Third Party Advisory
Mailing List
http://www.oracle.com/technetwork/topics/security/cpujul2014-1972956.html
Vendor Advisory
http://www.securityfocus.com/archive/1/534161/100/0/threaded
Third Party Advisory
VDB Entry
http://www.vmware.com/security/advisories/VMSA-2014-0012.html
Third Party Advisory
http://marc.info/?l=bugtraq&m=137545592101387&w=2
Third Party Advisory
Mailing List
http://advisories.mageia.org/MGASA-2013-0185.html
Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2013-0963.html
Third Party Advisory
http://secunia.com/advisories/54154
Third Party Advisory
http://www.mandriva.com/security/advisories?name=MDVSA-2013:183
Third Party Advisory
http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html
Vendor Advisory
http://www.us-cert.gov/ncas/alerts/TA13-169A
Third Party Advisory
US Government Resource
https://access.redhat.com/errata/RHSA-2014:0414
Third Party Advisory
http://marc.info/?l=bugtraq&m=137545505800971&w=2
Third Party Advisory
Mailing List
http://hg.openjdk.java.net/jdk7u/jdk7u-dev/jdk/rev/abe9ea5a50d2
Third Party Advisory
http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html
Vendor Advisory
http://www.securityfocus.com/bid/60645
Third Party Advisory
VDB Entry
https://bugzilla.redhat.com/show_bug.cgi?id=975126
Third Party Advisory
Issue Tracking
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16887
Third Party Advisory
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19565
Third Party Advisory
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19582
Third Party Advisory