CVE-2013-5801

Oracle JDK < 1.5.0 and JRE < 1.6.0 - Remote Information Disclosure in 2D Component

Title source: llm
STIX 2.1

Description

Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, and Java SE Embedded 7u40 and earlier allows remote attackers to affect confidentiality via unknown vectors related to 2D.

References (17)

Core 17
Core References
Mailing List vendor-advisory x_refsource_apple
http://lists.apple.com/archives/security-announce/2013/Oct/msg00001.html
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2013-1440.html
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2013-1508.html
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2013-1793.html
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2013-1509.html
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2013-1507.html
Vendor Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2014:0414
Various Sources x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21655201
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18894
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/56338
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/63147
Mailing List vendor-advisory x_refsource_hp
http://marc.info/?l=bugtraq&m=138674073720143&w=2
Mailing List vendor-advisory x_refsource_hp
http://marc.info/?l=bugtraq&m=138674031212883&w=2
Vendor Advisory x_refsource_confirm
http://support.apple.com/kb/HT5982

Scores

EPSS 0.0232
EPSS Percentile 85.0%

Details

Status published
Products (7)
oracle/jdk 1.5.0 update36 (5 CPE variants)
oracle/jdk 1.6.0 update22 (20 CPE variants)
oracle/jdk 1.7.0 (16 CPE variants)
oracle/jdk < 1.5.0
oracle/jdk < 1.6.0
oracle/jdk < 1.7.0
oracle/jre 1.6.0 update22 (6 CPE variants)
Published Oct 16, 2013
Tracked Since Feb 18, 2026