CVE
- Id
- 61438
- CVE No.
- CVE-2013-1491
- Status
- Candidate
- Description
- The Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, 6 Update 43 and earlier, 5.0 Update 41 and earlier, and JavaFX 2.2.7 and earlier allows remote attackers to execute arbitrary code via vectors related to 2D, as demonstrated by Joshua Drake during a Pwn2Own competition at CanSecWest 2013.
- Phase
- Assigned (20130130)
- Votes
- None (candidate not yet proposed)
- Comments
Related CVE References
Id | CVE Id | CVE No. | Reference | Actions |
---|---|---|---|---|
615187 | 61438 | CVE-2013-1491 | MISC:http://h30499.www3.hp.com/t5/HP-Security-Research-Blog/Pwn2Own-2013/ba-p/5981157 | View |
615188 | 61438 | CVE-2013-1491 | MISC:http://www.zdnet.com/pwn2own-down-go-all-the-browsers-7000012283/ | View |
615189 | 61438 | CVE-2013-1491 | MISC:https://twitter.com/thezdi/status/309438311112507392 | View |
615190 | 61438 | CVE-2013-1491 | CONFIRM:http://www.oracle.com/technetwork/topics/security/javacpuapr2013-1928497.html | View |
615191 | 61438 | CVE-2013-1491 | APPLE:APPLE-SA-2013-04-16-2 | View |
615192 | 61438 | CVE-2013-1491 | URL:http://lists.apple.com/archives/security-announce/2013/Apr/msg00001.html | View |
615193 | 61438 | CVE-2013-1491 | HP:HPSBUX02889 | View |
615194 | 61438 | CVE-2013-1491 | URL:http://marc.info/?l=bugtraq&m=137283787217316&w=2 | View |
615195 | 61438 | CVE-2013-1491 | HP:SSRT101252 | View |
615196 | 61438 | CVE-2013-1491 | URL:http://marc.info/?l=bugtraq&m=137283787217316&w=2 | View |
615197 | 61438 | CVE-2013-1491 | HP:HPSBUX02922 | View |
615198 | 61438 | CVE-2013-1491 | URL:http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c03898880 | View |
615199 | 61438 | CVE-2013-1491 | HP:SSRT101305 | View |
615200 | 61438 | CVE-2013-1491 | URL:http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c03898880 | View |
615201 | 61438 | CVE-2013-1491 | REDHAT:RHSA-2013:0757 | View |
615202 | 61438 | CVE-2013-1491 | URL:http://rhn.redhat.com/errata/RHSA-2013-0757.html | View |
615203 | 61438 | CVE-2013-1491 | REDHAT:RHSA-2013:0758 | View |
615204 | 61438 | CVE-2013-1491 | URL:http://rhn.redhat.com/errata/RHSA-2013-0758.html | View |
615205 | 61438 | CVE-2013-1491 | REDHAT:RHSA-2013:1455 | View |
615206 | 61438 | CVE-2013-1491 | URL:http://rhn.redhat.com/errata/RHSA-2013-1455.html | View |
615207 | 61438 | CVE-2013-1491 | REDHAT:RHSA-2013:1456 | View |
615208 | 61438 | CVE-2013-1491 | URL:http://rhn.redhat.com/errata/RHSA-2013-1456.html | View |
615209 | 61438 | CVE-2013-1491 | SUSE:SUSE-SU-2013:0835 | View |
615210 | 61438 | CVE-2013-1491 | URL:http://lists.opensuse.org/opensuse-security-announce/2013-05/msg00013.html | View |
615211 | 61438 | CVE-2013-1491 | SUSE:SUSE-SU-2013:0871 | View |
615212 | 61438 | CVE-2013-1491 | URL:http://lists.opensuse.org/opensuse-security-announce/2013-06/msg00001.html | View |
615213 | 61438 | CVE-2013-1491 | SUSE:SUSE-SU-2013:0934 | View |
615214 | 61438 | CVE-2013-1491 | URL:http://lists.opensuse.org/opensuse-security-announce/2013-06/msg00007.html | View |
615215 | 61438 | CVE-2013-1491 | CERT:TA13-107A | View |
615216 | 61438 | CVE-2013-1491 | URL:http://www.us-cert.gov/ncas/alerts/TA13-107A | View |
615217 | 61438 | CVE-2013-1491 | OVAL:oval:org.mitre.oval:def:16663 | View |
615218 | 61438 | CVE-2013-1491 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:16663 | View |
615219 | 61438 | CVE-2013-1491 | OVAL:oval:org.mitre.oval:def:19482 | View |
615220 | 61438 | CVE-2013-1491 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:19482 | View |
615221 | 61438 | CVE-2013-1491 | OVAL:oval:org.mitre.oval:def:19553 | View |
Related JVN
Id | JVN No. | Title | Summary | CVE No. | CVE Id | CVSS_v2 | CVSS_v3 | JVN URL | Actions |
---|---|---|---|---|---|---|---|---|---|
20687 | JVNDB-2013-002262 | Oracle Sun Solaris 10 および 11 における Kernel/IO の処理に関する脆弱性 | Oracle Sun Solaris 10 および 11 には、Kernel/IO に関する処理に不備があるため、可用性に影響のある脆弱性が存在します。 | CVE-2013-1496 | 61438 | 4.9 | http://jvndb.jvn.jp/ja/contents/2013/JVNDB-2013-002262.html | View |