CVE-2013-0402
Last modified
CVE-2013-0402 is a vulnerability of currently unknown severity. Heap-based buffer overflow in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier and JavaFX 2.2.7 and earlier allows remote attackers to execute arbitrary code via unspecified vectors related to JavaFX, as demonstrated by VUPEN during a Pwn2Own competition at CanSecWest 2013.. EPSS estimates a 9.63% chance of exploitation in the next 30 days.
Description
Heap-based buffer overflow in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier and JavaFX 2.2.7 and earlier allows remote attackers to execute arbitrary code via unspecified vectors related to JavaFX, as demonstrated by VUPEN during a Pwn2Own competition at CanSecWest 2013.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Oracle | Javafx | <= 2.2.7 | — |
| Oracle | Jdk | 1.7.0 | Update17 |
| Oracle | Jre | 1.7.0 | Update17 |
References
- http://rhn.redhat.com/errata/RHSA-2013-0757.htmlVendor Advisory
- http://www.us-cert.gov/ncas/alerts/TA13-107AUS Government Resource
- http://rhn.redhat.com/errata/RHSA-2013-0757.htmlVendor Advisory
- http://www.us-cert.gov/ncas/alerts/TA13-107AUS Government Resource
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2013-0402?
How severe is CVE-2013-0402?
How do I fix CVE-2013-0402?
Are you affected by CVE-2013-0402?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
