V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsDocs
CVE-2013-1489
DEB
Critical

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 10 and Update 11, when running on Wind…

CVSS
10.0
Critical
EPSS
0.17
p94
Published
2013-01-01
Updated
2013-01-01
Description

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 10 and Update 11, when running on Windows using Internet Explorer, Firefox, Opera, and Google Chrome, allows remote attackers to bypass the "Very High" security level of the Java Control Panel and execute unsigned Java code without prompting the user via unknown vectors, aka "Issue 53" and the "Java Security Slider" vulnerability.

Affected products
Java-1.7.0-oracleJava-1.7.0-oracleOpenjdk-6Openjdk-7JdkJre
CVSS vector
AV:N/AC:L/Au:N/C:C/I:C/A:C
Timeline
2013-01-01
Published
2013-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Authentication
Au: N
None (N)
Confidentiality Impact
C: C
Complete
Integrity Impact
I: C
Complete
Availability Impact
A: C
Complete
Exploit indicators
EPSS
0.173 · p94
Known exploited (KEV)
No
Known exploits — Сканер-ВС
No Сканер-ВС checks registered for this vulnerability yet.
Affected software
ProductVendorStatus
java-1.7.0-oracleTracked
java-1.7.0-oracleTracked
openjdk-6Tracked
openjdk-7Tracked
jdk*Tracked
jre*Tracked
Source databases
DEB
CVE
RED