CVE-2013-0445
Last modified
CVE-2013-0445 is a vulnerability of currently unknown severity. Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, and 5.0 through Update 38, and OpenJDK 6 and 7, allows remote attackers to affect confidentiality, integrity, and availability via vectors related to AWT. NOTE: the previous information is from the February 2013 CPU. EPSS estimates a 8.09% chance of exploitation in the next 30 days.
Description
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, and 5.0 through Update 38, and OpenJDK 6 and 7, allows remote attackers to affect confidentiality, integrity, and availability via vectors related to AWT. NOTE: the previous information is from the February 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to an improper check of "privileges of the code" that bypasses the sandbox.
Metrics
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Oracle | Jre | 1.7.0 | — |
| Oracle | Jdk | 1.7.0 | — |
| Oracle | Jre | 1.6.0 | Update22 |
| Sun | Jre | 1.6.0 | — |
| Oracle | Jdk | 1.6.0 | Update22 |
| Sun | Jdk | 1.6.0 | — |
| Oracle | Jre | 1.5.0 | Update36 |
| Sun | Jre | 1.5.0 | — |
| Oracle | Jdk | 1.5.0 | Update36 |
| Sun | Jdk | 1.5.0 | — |
References
- http://www.kb.cert.org/vuls/id/858729US Government Resource
- http://www.us-cert.gov/cas/techalerts/TA13-032A.htmlUS Government Resource
- http://www.kb.cert.org/vuls/id/858729US Government Resource
- http://www.us-cert.gov/cas/techalerts/TA13-032A.htmlUS Government Resource
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2013-0445?
How severe is CVE-2013-0445?
How do I fix CVE-2013-0445?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2013
- CVE-2013-0439Unspecified vulnerability in the JavaFX component in Oracle …
- CVE-2013-0440Unspecified vulnerability in the Java Runtime Environment (J…
- CVE-2013-0441Unspecified vulnerability in the Java Runtime Environment (J…
- CVE-2013-0442Unspecified vulnerability in the Java Runtime Environment (J…
- CVE-2013-0443Unspecified vulnerability in the Java Runtime Environment (J…
- CVE-2013-0444Unspecified vulnerability in the Java Runtime Environment (J…
- CVE-2013-0446Unspecified vulnerability in the Java Runtime Environment (J…
- CVE-2013-0447Unspecified vulnerability in the JavaFX component in Oracle …
- CVE-2013-0448Unspecified vulnerability in the Java Runtime Environment (J…
- CVE-2013-0449Unspecified vulnerability in the Java Runtime Environment (J…
- CVE-2013-0450Unspecified vulnerability in the Java Runtime Environment (J…
- CVE-2013-0451SQL injection vulnerability in IBM Maximo Asset Management 6…
Are you affected by CVE-2013-0445?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
