CVE-2013-2416

EXPLOITED

Oracle Java SE <7.17 - Info Disclosure

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2013-2416 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 1 public exploit.

AI-analyzed exploit summary This advisory provides a detailed technical analysis of CVE-2013-2419, a memory corruption vulnerability in the Java Web Start Launcher's ActiveX control. It includes disassembly snippets, root cause analysis, and a proof-of-concept HTML/JS exploit that crashes javaws.exe.

Description

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier allows remote attackers to affect integrity via unknown vectors related to Deployment.

Exploits (1)

exploitdb WRITEUP
doswindows
https://www.exploit-db.com/exploits/24966

This advisory provides a detailed technical analysis of CVE-2013-2419, a memory corruption vulnerability in the Java Web Start Launcher's ActiveX control. It includes disassembly snippets, root cause analysis, and a proof-of-concept HTML/JS exploit that crashes javaws.exe.

Classification
Writeup 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Theoretical
Target: Java(TM) Web Start Launcher (deployJava1.dll) in Java SE 7 Update 17 and earlier, Java SE 6 Update 43 and earlier, Java SE 5.0 Update 41 and earlier
No auth needed
Prerequisites: Victim must use Internet Explorer with the Java ActiveX control enabled · Attacker must deliver malicious HTML/JS to the victim
devstral-2 · analyzed Feb 19, 2026 Full analysis →

References (4)

Core 4
Core References
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2013-0757.html
US Government Resource third-party-advisory x_refsource_cert
http://www.us-cert.gov/ncas/alerts/TA13-107A
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16464

Scores

EPSS 0.3762
EPSS Percentile 97.3%

Details

VulnCheck KEV 2024-05-06
Status published
Products (4)
oracle/jdk 1.7.0 (13 CPE variants)
oracle/jdk < 1.7.0
oracle/jre 1.7.0 (13 CPE variants)
oracle/jre < 1.7.0
Published Apr 17, 2013
Tracked Since Feb 18, 2026