cbcvebase.
CVE-2013-2473
published 2013-06-18

CVE-2013-2473: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45…

PriorityP353critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
7.44%
93.8th percentile
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier, and OpenJDK 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D. NOTE: the previous information is from the June 2013 CPU. Oracle has not commented on claims from another vendor that this issue allows remote attackers to bypass the Java sandbox via vectors related to "Incorrect ByteBandedRaster size checks" in 2D.

Affected

16 ranges
VendorProductVersion rangeFixed in
oraclejdk<= 1.7.0
oraclejdk<= 1.6.0
oraclejdk<= 1.5.0
oraclejdk
oraclejdk
oraclejdk
oraclejre<= 1.7.0
oraclejre<= 1.6.0
oraclejre<= 1.5.0
oraclejre
oraclejre
oraclejre
sunjdk
sunjdk
sunjre
sunjre

Detection & IOCsextracted from sources · hover to see the quote

  • The vulnerability involves incorrect size checks in the ByteBandedRaster class of the Java 2D component; monitor for Java applet or application activity that manipulates ByteBandedRaster objects with mismatched data buffer sizes relative to raster attributes, which could indicate sandbox escape attempts.
  • Attack vector is remote and delivered via untrusted Java applets or applications; detection should focus on browser-launched JVM processes loading applets from untrusted origins, particularly those exercising 2D/raster APIs.
  • ·Affected versions are Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, 5.0 Update 45 and earlier, and OpenJDK 7; exploitation requires the target to be running one of these unpatched versions.
  • ·The exact attack vectors are unspecified by Oracle; detection rules cannot rely on specific payload patterns disclosed by the vendor.

CVSS provenance

nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vendor_redhat10.0CRITICAL
vendor_ubuntu3.6LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.