cbcvebase.
CVE-2013-2471
published 2013-06-18

CVE-2013-2471: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45…

PriorityP278critical10CVSS 2.0
AVNACLAuNCCICAC
ITWVulnCheck KEV
Exploited in the wild
EPSS
14.75%
96.3th percentile
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier, and OpenJDK 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D. NOTE: the previous information is from the June 2013 CPU. Oracle has not commented on claims from another vendor that this issue allows remote attackers to bypass the Java sandbox via vectors related to "Incorrect IntegerComponentRaster size checks."

Affected

16 ranges
VendorProductVersion rangeFixed in
oraclejdk<= 1.7.0
oraclejdk<= 1.6.0
oraclejdk<= 1.5.0
oraclejdk
oraclejdk
oraclejdk
oraclejre<= 1.7.0
oraclejre<= 1.6.0
oraclejre<= 1.5.0
oraclejre
oraclejre
oraclejre
sunjdk
sunjdk
sunjre
sunjre

Detection & IOCsextracted from sources · hover to see the quote

  • The vulnerability involves incorrect size checks in the IntegerComponentRaster class — detect exploitation attempts by monitoring Java applet/application sandbox escapes related to 2D raster manipulation
  • Flag execution of untrusted Java applets or applications on affected JRE versions: Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, 5.0 Update 45 and earlier, and OpenJDK 7
  • Monitor for the upstream OpenJDK7 patch commit to identify the exact code change and build signatures around the vulnerable code path
  • ·The attack vector and exploit payload are unspecified by Oracle; detection must rely on behavioral/version-based indicators rather than specific network signatures
  • ·The vulnerability affects the 2D component (IntegerComponentRaster) and is exploitable by both untrusted Java applications and applets, broadening the attack surface beyond browser-based delivery

CVSS provenance

nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vulncheck10.0CRITICAL
vendor_redhat10.0CRITICAL
vendor_ubuntu3.6LOW
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.