CVE
- Id
- 61435
- CVE No.
- CVE-2013-1488
- Status
- Candidate
- Description
- The Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, and OpenJDK 6 and 7, allows remote attackers to execute arbitrary code via unspecified vectors involving reflection, Libraries, "improper toString calls," and the JDBC driver manager, as demonstrated by James Forshaw during a Pwn2Own competition at CanSecWest 2013.
- Phase
- Assigned (20130130)
- Votes
- None (candidate not yet proposed)
- Comments
Related CVE References
Related JVN
Id | JVN No. | Title | Summary | CVE No. | CVE Id | CVSS_v2 | CVSS_v3 | JVN URL | Actions |
---|---|---|---|---|---|---|---|---|---|
20173 | JVNDB-2013-001748 | Oracle Java SE の Java Runtime Environment の 2D における任意のコードを実行される脆弱性 | Oracle Java SE の Java Runtime Environment の 2D における色の管理 (CMM) 機能には、任意のコードを実行される、またはサービス運用妨害 (クラッシュ) 状態となる脆弱性が存在します。 | CVE-2013-1493 | 61435 | 10 | http://jvndb.jvn.jp/ja/contents/2013/JVNDB-2013-001748.html | View |