CVE-2013-0957
published 2013-09-19CVE-2013-0957: Data Protection in Apple iOS before 7 allows attackers to bypass intended limits on incorrect passcode entry, and consequently avoid a configured Erase Data…
PriorityP426medium5.8CVSS 2.0
AVNACMAuNCPIPAN
EPSS
1.33%
68.3th percentile
Data Protection in Apple iOS before 7 allows attackers to bypass intended limits on incorrect passcode entry, and consequently avoid a configured Erase Data setting, by leveraging the presence of an app in the third-party sandbox.
Affected
48 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | iphone_os | <= 6.1.4 | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-2453 OpenJDK: MBeanServer Introspector package access (JMX, 8008124)
bugzilla·2013-06-17·CVSS 5.0
CVE-2013-2453 [MEDIUM] CVE-2013-2453 OpenJDK: MBeanServer Introspector package access (JMX, 8008124)
CVE-2013-2453 OpenJDK: MBeanServer Introspector package access (JMX, 8008124)
It was discovered that the MBeanServer Introspector of the JMX component did not properly verify the package access. An untrusted Java application or applet could possibly use this flaw to bypass intended package restrictions.
Discussion:
External References:
http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 5
Via RHSA-2013:0958 https://rhn.redhat.com/errata/RHSA-2013-0958.html
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 6
Via RHSA-2013:0957 https://rhn.redhat.com/errata/RHSA-2013-0957.html
---
OpenJDK7 upstream repositories commit:
http://hg.openjdk.ja
Bugzilla
CVE-2013-2445 OpenJDK: Better handling of memory allocation errors (Hotspot, 7158805)
bugzilla·2013-06-17·CVSS 7.8
CVE-2013-2445 [HIGH] CVE-2013-2445 OpenJDK: Better handling of memory allocation errors (Hotspot, 7158805)
CVE-2013-2445 OpenJDK: Better handling of memory allocation errors (Hotspot, 7158805)
Various memory allocating parts of the Hotspot component did not correctly handle out-of-memory errors. An untrusted Java application or applet could possibly use these flaws to terminate the Java VM.
Discussion:
External References:
http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 5
Via RHSA-2013:0958 https://rhn.redhat.com/errata/RHSA-2013-0958.html
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 6
Via RHSA-2013:0957 https://rhn.redhat.com/errata/RHSA-2013-0957.html
---
OpenJDK7 upstream repositories commit:
http://hg.openjdk.java.net/jdk7u/jdk7u
Bugzilla
CVE-2013-2455 OpenJDK: getEnclosing* checks (Libraries, 8007812)
bugzilla·2013-06-17·CVSS 5.0
CVE-2013-2455 [MEDIUM] CVE-2013-2455 OpenJDK: getEnclosing* checks (Libraries, 8007812)
CVE-2013-2455 OpenJDK: getEnclosing* checks (Libraries, 8007812)
It was discovered that access checks for getEnclosingClass, getEnclosingMethod and getEnclosingConstructor were not performed properly. An untrusted Java application or applet could possibly use this flaw to disclose potentially sensitive information.
Discussion:
External References:
http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 5
Via RHSA-2013:0958 https://rhn.redhat.com/errata/RHSA-2013-0958.html
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 6
Via RHSA-2013:0957 https://rhn.redhat.com/errata/RHSA-2013-0957.html
---
OpenJDK7 upstream repositories commit:
http://h
Bugzilla
CVE-2013-2448 OpenJDK: Better access restrictions (Sound, 8006328)
bugzilla·2013-06-17·CVSS 7.6
CVE-2013-2448 [HIGH] CVE-2013-2448 OpenJDK: Better access restrictions (Sound, 8006328)
CVE-2013-2448 OpenJDK: Better access restrictions (Sound, 8006328)
It was discovered that various parts of the Sound component did not implement proper access restrictions. An untrusted Java application or applet could possibly use this flaw to bypass Java sandbox restrictions.
Discussion:
External References:
http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 5
Via RHSA-2013:0958 https://rhn.redhat.com/errata/RHSA-2013-0958.html
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 6
Via RHSA-2013:0957 https://rhn.redhat.com/errata/RHSA-2013-0957.html
---
OpenJDK7 upstream repositories commit:
http://hg.openjdk.java.net/jdk7u/jdk7u-dev/jdk
Bugzilla
CVE-2013-2461 OpenJDK: Missing check for valid DOMCanonicalizationMethod canonicalization algorithm (Libraries, 8014281)
bugzilla·2013-06-17·CVSS 7.5
CVE-2013-2461 [HIGH] CVE-2013-2461 OpenJDK: Missing check for valid DOMCanonicalizationMethod canonicalization algorithm (Libraries, 8014281)
CVE-2013-2461 OpenJDK: Missing check for valid DOMCanonicalizationMethod canonicalization algorithm (Libraries, 8014281)
It was discovered that the DOMCanonicalizationMethod did not properly verify the canonicalization algorithm. A remote attacker could possibly exploit this flaw to bypass correct XML signature verification.
Discussion:
External References:
http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 5
Via RHSA-2013:0958 https://rhn.redhat.com/errata/RHSA-2013-0958.html
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 6
Via RHSA-2013:0957 https://rhn.redhat.com/errata/RHSA-2013-0957.html
---
OpenJDK7 upstream repositories commit:
Bugzilla
CVE-2013-2454 OpenJDK: SerialJavaObject package restriction (JDBC, 8009554)
bugzilla·2013-06-17·CVSS 5.8
CVE-2013-2454 [MEDIUM] CVE-2013-2454 OpenJDK: SerialJavaObject package restriction (JDBC, 8009554)
CVE-2013-2454 OpenJDK: SerialJavaObject package restriction (JDBC, 8009554)
The SerialJavaObject class of the JDBC component did not properly restrict access to certain class packages. An untrusted Java application or applet could possibly use this flaw to bypass Java sandbox restrictions.
Discussion:
External References:
http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 5
Via RHSA-2013:0958 https://rhn.redhat.com/errata/RHSA-2013-0958.html
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 6
Via RHSA-2013:0957 https://rhn.redhat.com/errata/RHSA-2013-0957.html
---
OpenJDK7 upstream repositories commit:
http://hg.openjdk.java.net/jdk7u/j
Bugzilla
CVE-2013-2444 OpenJDK: Resource denial of service (AWT, 8001038)
bugzilla·2013-06-17·CVSS 5.0
CVE-2013-2444 [MEDIUM] CVE-2013-2444 OpenJDK: Resource denial of service (AWT, 8001038)
CVE-2013-2444 OpenJDK: Resource denial of service (AWT, 8001038)
It was discovered that the AWT component did not properly manage and restrict certain resources related to the processing of fonts. An untrusted Java application or applet could possibly use this flaw to exhaust available resources and cause a denial of service.
Discussion:
External References:
http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 5
Via RHSA-2013:0958 https://rhn.redhat.com/errata/RHSA-2013-0958.html
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 6
Via RHSA-2013:0957 https://rhn.redhat.com/errata/RHSA-2013-0957.html
---
OpenJDK7 upstream repositories commit
Bugzilla
CVE-2013-2449 OpenJDK: GnomeFileTypeDetector path access check (Libraries, 8004288)
bugzilla·2013-06-17·CVSS 4.3
CVE-2013-2449 [MEDIUM] CVE-2013-2449 OpenJDK: GnomeFileTypeDetector path access check (Libraries, 8004288)
CVE-2013-2449 OpenJDK: GnomeFileTypeDetector path access check (Libraries, 8004288)
It was discovered that the GnomeFileTypeDetector did not check for read permissions. An untrusted Java application or applet could possibly use this flaw to disclose potentially sensitive information.
Discussion:
External References:
http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 5
Via RHSA-2013:0958 https://rhn.redhat.com/errata/RHSA-2013-0958.html
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 6
Via RHSA-2013:0957 https://rhn.redhat.com/errata/RHSA-2013-0957.html
---
OpenJDK7 upstream repositories commit:
http://hg.openjdk.java.net/jdk7u/jdk7u-d
2013-09-19
Published