Oracle JRE Sandbox Bypass Vulnerability
Medium CVSS 5.3 Listed in CISA KEV
Summary
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle allows remote attackers to bypass the Java security sandbox.
In-depth triage · Auto channel
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Affected products
- Oracle:Java Runtime Environment (JRE)
- :
- :
Sources
- CISA KEV DATABASE
- NVD DATABASE
Original Links
- https://nvd.nist.gov/vuln/detail/CVE-2013-0431 advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog kev
- http://arstechnica.com/security/2013/01/critical-java-vulnerabilies-confirmed-in-latest-version/ Third Party Advisory
- http://blogs.computerworld.com/malware-and-vulnerabilities/21693/yet-another-java-security-flaw-discovered-number-53 Not Applicable
- http://lists.opensuse.org/opensuse-security-announce/2013-03/msg00001.html Third Party Advisory
- http://marc.info/?l=bugtraq&m=136439120408139&w=2 Mailing List
- http://marc.info/?l=bugtraq&m=136733161405818&w=2 Mailing List
- http://rhn.redhat.com/errata/RHSA-2013-0237.html Third Party Advisory
- http://rhn.redhat.com/errata/RHSA-2013-0247.html Third Party Advisory
- http://seclists.org/fulldisclosure/2013/Jan/142 Mailing List
- http://seclists.org/fulldisclosure/2013/Jan/195 Mailing List
- http://security.gentoo.org/glsa/glsa-201406-32.xml Third Party Advisory
- http://www.informationweek.com/security/application-security/java-hacker-uncovers-two-flaws-in-latest/240146717 Broken Link
- http://www.kb.cert.org/vuls/id/858729 Third Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2013:095 Not Applicable
- http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html Vendor Advisory
- http://www.securityfocus.com/archive/1/525387/30/0/threaded Third Party Advisory
- http://www.us-cert.gov/cas/techalerts/TA13-032A.html Third Party Advisory
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16579 Broken Link
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19418 Broken Link
- https://wiki.mageia.org/en/Support/Advisories/MGASA-2013-0056 Third Party Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2013-0431 US Government Resource
Timeline
- kev_added CISA KEV
- kev_ingest CISA KEV
- nvd_ingest NVD