Куда я попал?
SECURITM это SGRC система, ? автоматизирующая процессы в службах информационной безопасности. SECURITM помогает построить и управлять ИСПДн, КИИ, ГИС, СМИБ/СУИБ, банковскими системами защиты.
А еще SECURITM это место для обмена опытом и наработками для служб безопасности.

CVE-2013-2465

PUBLISHED 22.10.2025

CNA: oracle

Обновлено: 04.01.2018
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier, and OpenJDK 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D. NOTE: the previous information is from the June 2013 CPU. Oracle has not commented on claims from another vendor that this issue allows remote attackers to bypass the Java sandbox via vectors related to "Incorrect image channel verification" in 2D.

EPSS

Вероятность Severity Процентиль ? Дата расчёта
93.22% CRITICAL 99.81 23.05.2026

Exploits & Shellcodes

Идентификатор Тип Описание Дата публикации
EDB-27705 Exploit Java - 'storeImageArray()' Invalid Array Indexing (Metasploit) 19.08.2013

Доп. Информация

Product Status

n/a
Product: n/a
Vendor: n/a
Default status: Не определен
Версии:
Затронутые версии Статус
Наблюдалось в версии n/a affected
 

Ссылки

http://rhn.redhat.com/errata/RHSA-2013-1060.html
http://marc.info/?l=bugtraq&m=137545592101387&w=2
https://access.redhat.com/errata/RHSA-2014:0414
http://security.gentoo.org/glsa/glsa-201406-32.xml
http://www.securityfocus.com/bid/60657
http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html
http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00031.html
http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00028.html
http://marc.info/?l=bugtraq&m=137545505800971&w=2
http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00027.html
http://secunia.com/advisories/54154
http://rhn.redhat.com/errata/RHSA-2013-1455.html
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c03898880
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19455
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19703
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c03898880
http://hg.openjdk.java.net/jdk7u/jdk7u-dev/jdk/rev/2a9c79db0040
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19074
http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00029.html
http://rhn.redhat.com/errata/RHSA-2013-1059.html
http://lists.opensuse.org/opensuse-security-announce/2013-08/msg00000.html
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A17106
http://rhn.redhat.com/errata/RHSA-2013-1081.html
http://www.us-cert.gov/ncas/alerts/TA13-169A
http://advisories.mageia.org/MGASA-2013-0185.html
http://rhn.redhat.com/errata/RHSA-2013-0963.html
http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00026.html
https://bugzilla.redhat.com/show_bug.cgi?id=975118
http://rhn.redhat.com/errata/RHSA-2013-1456.html
http://www.mandriva.com/security/advisories?name=MDVSA-2013:183
http://www-01.ibm.com/support/docview.wss?uid=swg21642336
http://lists.opensuse.org/opensuse-security-announce/2013-08/msg00003.html

CVE Program Container

Обновлено: 06.05.2025
SSVC and KEV, plus CVSS and CWE if not provided by the CNA.

Ссылки

https://www.vicarius.io/vsociety/posts/cve-2013-2465-detect-java-vulnerability
https://www.vicarius.io/vsociety/posts/cve-2013-2465-mitigate-java-vulnerability
http://rhn.redhat.com/errata/RHSA-2013-1060.html
http://marc.info/?l=bugtraq&m=137545592101387&w=2
https://access.redhat.com/errata/RHSA-2014:0414
http://security.gentoo.org/glsa/glsa-201406-32.xml
http://www.securityfocus.com/bid/60657
http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html
http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00031.html
http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00028.html
http://marc.info/?l=bugtraq&m=137545505800971&w=2
http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00027.html
http://secunia.com/advisories/54154
http://rhn.redhat.com/errata/RHSA-2013-1455.html
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c03898880
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19455
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19703
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c03898880
http://hg.openjdk.java.net/jdk7u/jdk7u-dev/jdk/rev/2a9c79db0040
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19074
http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00029.html
http://rhn.redhat.com/errata/RHSA-2013-1059.html
http://lists.opensuse.org/opensuse-security-announce/2013-08/msg00000.html
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A17106
http://rhn.redhat.com/errata/RHSA-2013-1081.html
http://www.us-cert.gov/ncas/alerts/TA13-169A
http://advisories.mageia.org/MGASA-2013-0185.html
http://rhn.redhat.com/errata/RHSA-2013-0963.html
http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00026.html
https://bugzilla.redhat.com/show_bug.cgi?id=975118
http://rhn.redhat.com/errata/RHSA-2013-1456.html
http://www.mandriva.com/security/advisories?name=MDVSA-2013:183
http://www-01.ibm.com/support/docview.wss?uid=swg21642336
http://lists.opensuse.org/opensuse-security-announce/2013-08/msg00003.html

CISA ADP Vulnrichment

Обновлено: 22.10.2025
Этот блок содержит дополнительную информацию, предоставленную программой CVE для этой уязвимости.

CVSS

Оценка Severity Версия Базовый вектор
9.8 CRITICAL 3.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

SSVC

Exploitation Automatable Technical Impact Версия Дата доступа
active yes total 2.0.3 10.02.2025

Ссылки

Мы используем cookie-файлы, чтобы получить статистику, которая помогает нам улучшить сервис для вас с целью персонализации сервисов и предложений. Вы может прочитать подробнее о cookie-файлах или изменить настройки браузера. Продолжая пользоваться сайтом, вы даёте согласие на использование ваших cookie-файлов и соглашаетесь с Политикой обработки персональных данных.