10

CVE-2013-2465

Warnung
Exploit
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier, and OpenJDK 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D.  NOTE: the previous information is from the June 2013 CPU. Oracle has not commented on claims from another vendor that this issue allows remote attackers to bypass the Java sandbox via vectors related to "Incorrect image channel verification" in 2D.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Oracle ≫ Jre Version 1.7.0 Update -
Oracle ≫ Jre Version 1.7.0 Update update1
Oracle ≫ Jre Version 1.7.0 Update update10
Oracle ≫ Jre Version 1.7.0 Update update11
Oracle ≫ Jre Version 1.7.0 Update update13
Oracle ≫ Jre Version 1.7.0 Update update15
Oracle ≫ Jre Version 1.7.0 Update update17
Oracle ≫ Jre Version 1.7.0 Update update2
Oracle ≫ Jre Version 1.7.0 Update update21
Oracle ≫ Jre Version 1.7.0 Update update3
Oracle ≫ Jre Version 1.7.0 Update update4
Oracle ≫ Jre Version 1.7.0 Update update5
Oracle ≫ Jre Version 1.7.0 Update update6
Oracle ≫ Jre Version 1.7.0 Update update7
Oracle ≫ Jre Version 1.7.0 Update update9
Oracle ≫ Jre Version 1.6.0 Update -
Oracle ≫ Jre Version 1.6.0 Update update22
Oracle ≫ Jre Version 1.6.0 Update update23
Oracle ≫ Jre Version 1.6.0 Update update24
Oracle ≫ Jre Version 1.6.0 Update update25
Oracle ≫ Jre Version 1.6.0 Update update26
Oracle ≫ Jre Version 1.6.0 Update update27
Oracle ≫ Jre Version 1.6.0 Update update29
Oracle ≫ Jre Version 1.6.0 Update update30
Oracle ≫ Jre Version 1.6.0 Update update31
Oracle ≫ Jre Version 1.6.0 Update update32
Oracle ≫ Jre Version 1.6.0 Update update33
Oracle ≫ Jre Version 1.6.0 Update update34
Oracle ≫ Jre Version 1.6.0 Update update35
Oracle ≫ Jre Version 1.6.0 Update update37
Oracle ≫ Jre Version 1.6.0 Update update38
Oracle ≫ Jre Version 1.6.0 Update update39
Oracle ≫ Jre Version 1.6.0 Update update41
Oracle ≫ Jre Version 1.6.0 Update update43
Oracle ≫ Jre Version 1.6.0 Update update45
Sun ≫ Jre Version 1.6.0 Update update_1
Sun ≫ Jre Version 1.6.0 Update update_10
Sun ≫ Jre Version 1.6.0 Update update_11
Sun ≫ Jre Version 1.6.0 Update update_12
Sun ≫ Jre Version 1.6.0 Update update_13
Sun ≫ Jre Version 1.6.0 Update update_14
Sun ≫ Jre Version 1.6.0 Update update_15
Sun ≫ Jre Version 1.6.0 Update update_16
Sun ≫ Jre Version 1.6.0 Update update_17
Sun ≫ Jre Version 1.6.0 Update update_18
Sun ≫ Jre Version 1.6.0 Update update_19
Sun ≫ Jre Version 1.6.0 Update update_20
Sun ≫ Jre Version 1.6.0 Update update_21
Sun ≫ Jre Version 1.6.0 Update update_3
Sun ≫ Jre Version 1.6.0 Update update_4
Sun ≫ Jre Version 1.6.0 Update update_5
Sun ≫ Jre Version 1.6.0 Update update_6
Sun ≫ Jre Version 1.6.0 Update update_7
Sun ≫ Jre Version 1.6.0 Update update_9
Oracle ≫ Jre Version 1.5.0 Update -
Oracle ≫ Jre Version 1.5.0 Update update36
Oracle ≫ Jre Version 1.5.0 Update update38
Oracle ≫ Jre Version 1.5.0 Update update39
Oracle ≫ Jre Version 1.5.0 Update update40
Oracle ≫ Jre Version 1.5.0 Update update41
Oracle ≫ Jre Version 1.5.0 Update update45
Sun ≫ Jre Version 1.5.0 Update update1
Sun ≫ Jre Version 1.5.0 Update update10
Sun ≫ Jre Version 1.5.0 Update update11
Sun ≫ Jre Version 1.5.0 Update update12
Sun ≫ Jre Version 1.5.0 Update update13
Sun ≫ Jre Version 1.5.0 Update update14
Sun ≫ Jre Version 1.5.0 Update update15
Sun ≫ Jre Version 1.5.0 Update update16
Sun ≫ Jre Version 1.5.0 Update update17
Sun ≫ Jre Version 1.5.0 Update update18
Sun ≫ Jre Version 1.5.0 Update update19
Sun ≫ Jre Version 1.5.0 Update update2
Sun ≫ Jre Version 1.5.0 Update update20
Sun ≫ Jre Version 1.5.0 Update update21
Sun ≫ Jre Version 1.5.0 Update update22
Sun ≫ Jre Version 1.5.0 Update update23
Sun ≫ Jre Version 1.5.0 Update update24
Sun ≫ Jre Version 1.5.0 Update update25
Sun ≫ Jre Version 1.5.0 Update update26
Sun ≫ Jre Version 1.5.0 Update update27
Sun ≫ Jre Version 1.5.0 Update update28
Sun ≫ Jre Version 1.5.0 Update update29
Sun ≫ Jre Version 1.5.0 Update update3
Sun ≫ Jre Version 1.5.0 Update update31
Sun ≫ Jre Version 1.5.0 Update update33
Sun ≫ Jre Version 1.5.0 Update update4
Sun ≫ Jre Version 1.5.0 Update update5
Sun ≫ Jre Version 1.5.0 Update update6
Sun ≫ Jre Version 1.5.0 Update update7
Sun ≫ Jre Version 1.5.0 Update update8
Sun ≫ Jre Version 1.5.0 Update update9
Suse ≫ Linux Enterprise Desktop Version 10 Update sp4 SwEdition -
Suse ≫ Linux Enterprise Java Version 10 Update sp4
Suse ≫ Linux Enterprise Java Version 11 Update sp2
Suse ≫ Linux Enterprise Java Version 11 Update sp3
Suse ≫ Linux Enterprise Server Version 10 Update sp3 SwEdition ltss
Suse ≫ Linux Enterprise Server Version 10 Update sp4 SwEdition -
Suse ≫ Linux Enterprise Server Version 11 Update sp2 SwPlatform -
Suse ≫ Linux Enterprise Server Version 11 Update sp2 SwPlatform vmware
Suse ≫ Linux Enterprise Server Version 11 Update sp3 SwPlatform -
Suse ≫ Linux Enterprise Server Version 11 Update sp3 SwPlatform vmware

28.03.2022: CISA Known Exploited Vulnerabilities (KEV) Catalog

Oracle Java SE Unspecified Vulnerability

Schwachstelle

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE allows remote attackers to affect confidentiality, integrity, and availability via Unknown vectors related to 2D

Beschreibung

Apply updates per vendor instructions.

Erforderliche Maßnahmen
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 98.7% 0.999
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C
CISA-ADP 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-693 Protection Mechanism Failure

The product does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product.

http://security.gentoo.org/glsa/glsa-201406-32.xml
Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2013-1455.html
Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2013-1456.html
Third Party Advisory
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c03898880
Broken Link
http://marc.info/?l=bugtraq&m=137545592101387&w=2
Third Party Advisory
Mailing List
http://advisories.mageia.org/MGASA-2013-0185.html
Broken Link
http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00026.html
Third Party Advisory
Mailing List
http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00028.html
Third Party Advisory
Mailing List
http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00029.html
Third Party Advisory
Mailing List
http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00031.html
Third Party Advisory
Mailing List
http://lists.opensuse.org/opensuse-security-announce/2013-08/msg00000.html
Third Party Advisory
Mailing List
http://lists.opensuse.org/opensuse-security-announce/2013-08/msg00003.html
Third Party Advisory
Mailing List
http://rhn.redhat.com/errata/RHSA-2013-0963.html
Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2013-1059.html
Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2013-1060.html
Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2013-1081.html
Third Party Advisory
http://secunia.com/advisories/54154
Not Applicable
http://www-01.ibm.com/support/docview.wss?uid=swg21642336
Third Party Advisory
http://www.mandriva.com/security/advisories?name=MDVSA-2013:183
Not Applicable
http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html
Vendor Advisory
http://www.us-cert.gov/ncas/alerts/TA13-169A
Third Party Advisory
US Government Resource
https://access.redhat.com/errata/RHSA-2014:0414
Third Party Advisory
http://marc.info/?l=bugtraq&m=137545505800971&w=2
Third Party Advisory
Mailing List
http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00027.html
Third Party Advisory
Mailing List
http://hg.openjdk.java.net/jdk7u/jdk7u-dev/jdk/rev/2a9c79db0040
Patch
http://www.securityfocus.com/bid/60657
Third Party Advisory
Broken Link
VDB Entry
https://bugzilla.redhat.com/show_bug.cgi?id=975118
Issue Tracking
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A17106
Broken Link
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19074
Broken Link
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19455
Broken Link
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19703
Broken Link
https://www.vicarius.io/vsociety/posts/cve-2013-2465-detect-java-vulnerability
Third Party Advisory
Exploit
https://www.vicarius.io/vsociety/posts/cve-2013-2465-mitigate-java-vulnerability
Third Party Advisory
Exploit
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2013-2465
US Government Resource