CVE
- Id
- 60371
- CVE No.
- CVE-2013-0424
- Status
- Candidate
- Description
- Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, 5.0 through Update 38, and 1.4.2_40 and earlier, and OpenJDK 7, allows remote attackers to affect integrity via vectors related to RMI. NOTE: the previous information is from the February 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to cross-site scripting (XSS) in the sun.rmi.transport.proxy CGIHandler class that does not properly handle error messages in a (1) command or (2) port number.
- Phase
- Assigned (20121207)
- Votes
- None (candidate not yet proposed)
- Comments
Related CVE References
Id | CVE Id | CVE No. | Reference | Actions |
---|---|---|---|---|
608927 | 60371 | CVE-2013-0424 | CONFIRM:http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html | View |
608928 | 60371 | CVE-2013-0424 | CONFIRM:http://icedtea.classpath.org/hg/release/icedtea6-1.11/file/icedtea6-1.11.6/NEWS | View |
608929 | 60371 | CVE-2013-0424 | CONFIRM:http://icedtea.classpath.org/hg/release/icedtea7-forest-2.3/jdk/rev/6e173569e1e7 | View |
608930 | 60371 | CVE-2013-0424 | CONFIRM:https://bugzilla.redhat.com/show_bug.cgi?id=906813 | View |
608931 | 60371 | CVE-2013-0424 | CONFIRM:https://wiki.mageia.org/en/Support/Advisories/MGASA-2013-0056 | View |
608932 | 60371 | CVE-2013-0424 | GENTOO:GLSA-201406-32 | View |
608933 | 60371 | CVE-2013-0424 | URL:http://security.gentoo.org/glsa/glsa-201406-32.xml | View |
608934 | 60371 | CVE-2013-0424 | HP:HPSBUX02864 | View |
608935 | 60371 | CVE-2013-0424 | URL:http://marc.info/?l=bugtraq&m=136570436423916&w=2 | View |
608936 | 60371 | CVE-2013-0424 | HP:SSRT101156 | View |
608937 | 60371 | CVE-2013-0424 | URL:http://marc.info/?l=bugtraq&m=136570436423916&w=2 | View |
608938 | 60371 | CVE-2013-0424 | HP:HPSBMU02874 | View |
608939 | 60371 | CVE-2013-0424 | URL:http://marc.info/?l=bugtraq&m=136733161405818&w=2 | View |
608940 | 60371 | CVE-2013-0424 | HP:HPSBUX02857 | View |
608941 | 60371 | CVE-2013-0424 | URL:http://marc.info/?l=bugtraq&m=136439120408139&w=2 | View |
608942 | 60371 | CVE-2013-0424 | HP:SSRT101103 | View |
608943 | 60371 | CVE-2013-0424 | URL:http://marc.info/?l=bugtraq&m=136439120408139&w=2 | View |
608944 | 60371 | CVE-2013-0424 | HP:SSRT101184 | View |
608945 | 60371 | CVE-2013-0424 | URL:http://marc.info/?l=bugtraq&m=136733161405818&w=2 | View |
608946 | 60371 | CVE-2013-0424 | MANDRIVA:MDVSA-2013:095 | View |
608947 | 60371 | CVE-2013-0424 | URL:http://www.mandriva.com/security/advisories?name=MDVSA-2013:095 | View |
608948 | 60371 | CVE-2013-0424 | REDHAT:RHSA-2013:0236 | View |
608949 | 60371 | CVE-2013-0424 | URL:http://rhn.redhat.com/errata/RHSA-2013-0236.html | View |
608950 | 60371 | CVE-2013-0424 | REDHAT:RHSA-2013:0237 | View |
608951 | 60371 | CVE-2013-0424 | URL:http://rhn.redhat.com/errata/RHSA-2013-0237.html | View |
608952 | 60371 | CVE-2013-0424 | REDHAT:RHSA-2013:0245 | View |
608953 | 60371 | CVE-2013-0424 | URL:http://rhn.redhat.com/errata/RHSA-2013-0245.html | View |
608954 | 60371 | CVE-2013-0424 | REDHAT:RHSA-2013:0246 | View |
608955 | 60371 | CVE-2013-0424 | URL:http://rhn.redhat.com/errata/RHSA-2013-0246.html | View |
608956 | 60371 | CVE-2013-0424 | REDHAT:RHSA-2013:0247 | View |
608957 | 60371 | CVE-2013-0424 | URL:http://rhn.redhat.com/errata/RHSA-2013-0247.html | View |
608958 | 60371 | CVE-2013-0424 | REDHAT:RHSA-2013:1455 | View |
608959 | 60371 | CVE-2013-0424 | URL:http://rhn.redhat.com/errata/RHSA-2013-1455.html | View |
608960 | 60371 | CVE-2013-0424 | REDHAT:RHSA-2013:1456 | View |
608961 | 60371 | CVE-2013-0424 | URL:http://rhn.redhat.com/errata/RHSA-2013-1456.html | View |
608962 | 60371 | CVE-2013-0424 | SUSE:openSUSE-SU-2013:0312 | View |
608963 | 60371 | CVE-2013-0424 | URL:http://lists.opensuse.org/opensuse-security-announce/2013-02/msg00014.html | View |
608964 | 60371 | CVE-2013-0424 | SUSE:openSUSE-SU-2013:0377 | View |
608965 | 60371 | CVE-2013-0424 | URL:http://lists.opensuse.org/opensuse-security-announce/2013-03/msg00001.html | View |
608966 | 60371 | CVE-2013-0424 | SUSE:SUSE-SU-2013:0478 | View |
608967 | 60371 | CVE-2013-0424 | URL:http://lists.opensuse.org/opensuse-security-announce/2013-03/msg00034.html | View |
608968 | 60371 | CVE-2013-0424 | CERT:TA13-032A | View |
608969 | 60371 | CVE-2013-0424 | URL:http://www.us-cert.gov/cas/techalerts/TA13-032A.html | View |
608970 | 60371 | CVE-2013-0424 | CERT-VN:VU#858729 | View |
608971 | 60371 | CVE-2013-0424 | URL:http://www.kb.cert.org/vuls/id/858729 | View |
608972 | 60371 | CVE-2013-0424 | OVAL:oval:org.mitre.oval:def:16519 | View |
608973 | 60371 | CVE-2013-0424 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:16519 | View |
608974 | 60371 | CVE-2013-0424 | OVAL:oval:org.mitre.oval:def:19131 | View |
608975 | 60371 | CVE-2013-0424 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:19131 | View |
608976 | 60371 | CVE-2013-0424 | OVAL:oval:org.mitre.oval:def:19423 | View |
608977 | 60371 | CVE-2013-0424 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:19423 | View |
608978 | 60371 | CVE-2013-0424 | OVAL:oval:org.mitre.oval:def:19522 | View |
Related JVN
Id | JVN No. | Title | Summary | CVE No. | CVE Id | CVSS_v2 | CVSS_v3 | JVN URL | Actions |
---|---|---|---|---|---|---|---|---|---|
19822 | JVNDB-2013-001397 | Oracle Java SE の Java Runtime Environment における CORBA の処理に関する脆弱性 | Oracle Java SE の Java Runtime Environment (JRE) には、CORBA に関する処理に不備があるため、機密性、完全性、可用性に影響のある脆弱性が存在します。 | CVE-2013-0429 | 60371 | 7.6 | http://jvndb.jvn.jp/ja/contents/2013/JVNDB-2013-001397.html | View |