CVE-2013-5825

Oracle JDK and JRE - Denial of Service via JAXP

Title source: llm
STIX 2.1

Description

Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, JRockit R28.2.8 and earlier, JRockit R27.7.6 and earlier, and Java SE Embedded 7u40 and earlier allows remote attackers to affect availability via vectors related to JAXP.

References (25)

Core 25
Core References
Mailing List vendor-advisory x_refsource_apple
http://lists.apple.com/archives/security-announce/2013/Oct/msg00001.html
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2013-1447.html
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2013-1440.html
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2013-1508.html
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2013-1505.html
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2013-1793.html
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2013-1509.html
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2013-1507.html
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2013-1451.html
Vendor Advisory vendor-advisory x_refsource_ubuntu
http://www.ubuntu.com/usn/USN-2033-1
Vendor Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2014:0414
Third Party Advisory vendor-advisory x_refsource_gentoo
http://security.gentoo.org/glsa/glsa-201406-32.xml
Vendor Advisory vendor-advisory x_refsource_ubuntu
http://www.ubuntu.com/usn/USN-2089-1
Mailing List vendor-advisory x_refsource_hp
http://marc.info/?l=bugtraq&m=138674073720143&w=2
Various Sources x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21655201
Mailing List vendor-advisory x_refsource_hp
http://marc.info/?l=bugtraq&m=138674031212883&w=2
Mailing List vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-updates/2013-11/msg00023.html
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19046
Vendor Advisory x_refsource_confirm
http://support.apple.com/kb/HT5982
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/63101
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/56338

Scores

EPSS 0.0576
EPSS Percentile 90.6%

Details

Status published
Products (8)
oracle/jdk 1.6.0 update22 (20 CPE variants)
oracle/jdk 1.7.0 (16 CPE variants)
oracle/jdk 1.5.0 update36 (5 CPE variants)
oracle/jdk < 1.5.0
oracle/jdk < 1.6.0
oracle/jdk < 1.7.0
oracle/jre 1.5.0 update36 (5 CPE variants)
oracle/jre 1.7.0
Published Oct 16, 2013
Tracked Since Feb 18, 2026