← back
CVE-2013-2465

CVE-2013-2465

CVSS 9.8 CRITICALEPSS 98.7%● KEVCWE-693
In short

A flaw in Java's 2D graphics component allows attackers to break out of the Java sandbox and run malicious code on your computer just by visiting a website or opening a file. This is critical because Java is used by millions of people worldwide.

Technical detail

CVE-2013-2465 is a sandbox bypass vulnerability in the 2D graphics rendering component of Java SE (versions 7u21, 6u45, 5u45 and OpenJDK 7) related to incorrect image channel verification. Remote attackers can deliver malicious applets or JNLP applications that exploit this flaw to execute arbitrary code with user privileges, bypassing Java's security model and affecting confidentiality, integrity, and availability.

Summary generated and translated by AI from the official description.
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier, and OpenJDK 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D. NOTE: the previous information is from the June 2013 CPU. Oracle has not commented on claims from another vendor that this issue allows remote attackers to bypass the Java sandbox via vectors related to "Incorrect image channel verification" in 2D.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →