oracle jre CVE-2013-2465 in Oracle and Sun Products
Published on June 18, 2013

product logo product logo
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier, and OpenJDK 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D. NOTE: the previous information is from the June 2013 CPU. Oracle has not commented on claims from another vendor that this issue allows remote attackers to bypass the Java sandbox via vectors related to "Incorrect image channel verification" in 2D.

Vendor Advisory NVD

Known Exploited Vulnerability

This Oracle Java SE Unspecified Vulnerability is part of CISA's list of Known Exploited Vulnerabilities. Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D.

The following remediation steps are recommended / required by April 18, 2022: Apply updates per vendor instructions.

Vulnerability Analysis


Products Associated with CVE-2013-2465

You can be notified by stack.watch whenever vulnerabilities like CVE-2013-2465 are published in these products:

 
 
 
 

What versions are vulnerable to CVE-2013-2465?