CVE-2013-5797

8 documents6 sources
Severity
3.5LOW
EPSS
0.2%
top 55.10%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 16
Latest updateMay 14

Description

Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, JRockit R28.2.8 and earlier, JRockit R27.7.6 and earlier, and JavaFX 2.2.40 and earlier allows remote authenticated users to affect integrity via unknown vectors related to Javadoc.

CVSS vector

AV:N/AC:M/C:N/I:P/A:NExploitability: 6.8 | Impact: 2.9

Affected Packages6 packages

NVDoracle/javafx2.2.40+10
NVDoracle/jrockitr28.2.8+19
NVDoracle/jdk1.5.0+5
NVDoracle/jre1.6.0+5
NVDsun/jdk1.5.0, 1.6.0+1

🔴Vulnerability Details

2
GHSA
GHSA-cxh8-c38w-rhhm: Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 52022-05-14
CVEList
CVE-2013-5797: Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 52013-10-16

📋Vendor Advisories

3
Ubuntu
OpenJDK 7 vulnerabilities2014-01-23
Ubuntu
OpenJDK 6 vulnerabilities2013-11-21
Red Hat
OpenJDK: insufficient escaping of window title string (Javadoc, 8016675)2013-10-15

💬Community

2
Bugzilla
CVE-2014-2398 OpenJDK: insufficient escaping of window title string (Javadoc, 8026736)2014-04-11
Bugzilla
CVE-2013-5797 OpenJDK: insufficient escaping of window title string (Javadoc, 8016675)2013-10-14