Логотип exploitDog
bind:"GHSA-wq4h-35pf-mp23" OR bind:"CVE-2013-2423"
Консоль
Логотип exploitDog

exploitDog

bind:"GHSA-wq4h-35pf-mp23" OR bind:"CVE-2013-2423"

Количество 8

Количество 8

github логотип

GHSA-wq4h-35pf-mp23

больше 3 лет назад

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, and OpenJDK 7, allows remote attackers to affect integrity via unknown vectors related to HotSpot. NOTE: the previous information is from the April 2013 CPU. Oracle has not commented on claims from the original researcher that this vulnerability allows remote attackers to bypass permission checks by the MethodHandles method and modify arbitrary public final fields using reflection and type confusion, as demonstrated using integer and double fields to disable the security manager.

CVSS3: 3.7
EPSS: Критический
ubuntu логотип

CVE-2013-2423

больше 12 лет назад

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, and OpenJDK 7, allows remote attackers to affect integrity via unknown vectors related to HotSpot. NOTE: the previous information is from the April 2013 CPU. Oracle has not commented on claims from the original researcher that this vulnerability allows remote attackers to bypass permission checks by the MethodHandles method and modify arbitrary public final fields using reflection and type confusion, as demonstrated using integer and double fields to disable the security manager.

CVSS3: 3.7
EPSS: Критический
redhat логотип

CVE-2013-2423

больше 12 лет назад

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, and OpenJDK 7, allows remote attackers to affect integrity via unknown vectors related to HotSpot. NOTE: the previous information is from the April 2013 CPU. Oracle has not commented on claims from the original researcher that this vulnerability allows remote attackers to bypass permission checks by the MethodHandles method and modify arbitrary public final fields using reflection and type confusion, as demonstrated using integer and double fields to disable the security manager.

CVSS2: 4.3
EPSS: Критический
nvd логотип

CVE-2013-2423

больше 12 лет назад

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, and OpenJDK 7, allows remote attackers to affect integrity via unknown vectors related to HotSpot. NOTE: the previous information is from the April 2013 CPU. Oracle has not commented on claims from the original researcher that this vulnerability allows remote attackers to bypass permission checks by the MethodHandles method and modify arbitrary public final fields using reflection and type confusion, as demonstrated using integer and double fields to disable the security manager.

CVSS3: 3.7
EPSS: Критический
debian логотип

CVE-2013-2423

больше 12 лет назад

Unspecified vulnerability in the Java Runtime Environment (JRE) compon ...

CVSS3: 3.7
EPSS: Критический
fstec логотип

BDU:2022-03796

больше 12 лет назад

Уязвимость программной платформы Java Runtime Environment, вызванная выходом операции за границы буфера в памяти, позволяющая нарушителю повлиять на целостность или отключить диспетчера безопасности

CVSS3: 5.3
EPSS: Критический
oracle-oval логотип

ELSA-2013-0752

больше 12 лет назад

ELSA-2013-0752: java-1.7.0-openjdk security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2013-0751

больше 12 лет назад

ELSA-2013-0751: java-1.7.0-openjdk security update (CRITICAL)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-wq4h-35pf-mp23

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, and OpenJDK 7, allows remote attackers to affect integrity via unknown vectors related to HotSpot. NOTE: the previous information is from the April 2013 CPU. Oracle has not commented on claims from the original researcher that this vulnerability allows remote attackers to bypass permission checks by the MethodHandles method and modify arbitrary public final fields using reflection and type confusion, as demonstrated using integer and double fields to disable the security manager.

CVSS3: 3.7
93%
Критический
больше 3 лет назад
ubuntu логотип
CVE-2013-2423

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, and OpenJDK 7, allows remote attackers to affect integrity via unknown vectors related to HotSpot. NOTE: the previous information is from the April 2013 CPU. Oracle has not commented on claims from the original researcher that this vulnerability allows remote attackers to bypass permission checks by the MethodHandles method and modify arbitrary public final fields using reflection and type confusion, as demonstrated using integer and double fields to disable the security manager.

CVSS3: 3.7
93%
Критический
больше 12 лет назад
redhat логотип
CVE-2013-2423

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, and OpenJDK 7, allows remote attackers to affect integrity via unknown vectors related to HotSpot. NOTE: the previous information is from the April 2013 CPU. Oracle has not commented on claims from the original researcher that this vulnerability allows remote attackers to bypass permission checks by the MethodHandles method and modify arbitrary public final fields using reflection and type confusion, as demonstrated using integer and double fields to disable the security manager.

CVSS2: 4.3
93%
Критический
больше 12 лет назад
nvd логотип
CVE-2013-2423

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, and OpenJDK 7, allows remote attackers to affect integrity via unknown vectors related to HotSpot. NOTE: the previous information is from the April 2013 CPU. Oracle has not commented on claims from the original researcher that this vulnerability allows remote attackers to bypass permission checks by the MethodHandles method and modify arbitrary public final fields using reflection and type confusion, as demonstrated using integer and double fields to disable the security manager.

CVSS3: 3.7
93%
Критический
больше 12 лет назад
debian логотип
CVE-2013-2423

Unspecified vulnerability in the Java Runtime Environment (JRE) compon ...

CVSS3: 3.7
93%
Критический
больше 12 лет назад
fstec логотип
BDU:2022-03796

Уязвимость программной платформы Java Runtime Environment, вызванная выходом операции за границы буфера в памяти, позволяющая нарушителю повлиять на целостность или отключить диспетчера безопасности

CVSS3: 5.3
93%
Критический
больше 12 лет назад
oracle-oval логотип
ELSA-2013-0752

ELSA-2013-0752: java-1.7.0-openjdk security update (IMPORTANT)

больше 12 лет назад
oracle-oval логотип
ELSA-2013-0751

ELSA-2013-0751: java-1.7.0-openjdk security update (CRITICAL)

больше 12 лет назад

Уязвимостей на страницу