CVE-2013-0809 is an unspecified vulnerability in the 2D component of Oracle Java SE, affecting versions 7 Update 15 and earlier, 6 Update 41 and earlier, and 5.0 Update 40 and earlier. This critical vulnerability has a CVSS score of 10.0, indicating a severe risk where remote attackers can execute arbitrary code with full confidentiality, integrity, and availability impact without authentication. While no public exploit code is listed for Metasploit, Nuclei, or ExploitDB, the vulnerability has garnered some community discussion and media coverage, including an analysis on Hacker News regarding a Java integer overflow. Despite its age, its high FAUCET Risk Score of 88/100 suggests continued relevance for systems that have not been patched.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.6.0CPE matchmatch criteria | cpe:2.3:a:oracle:jre:*:update41:*:*:*:*:*:* | ||
1.6.0CPE matchmatch criteria | cpe:2.3:a:oracle:jre:1.6.0:update22:*:*:*:*:*:* | ||
1.6.0CPE matchmatch criteria | cpe:2.3:a:oracle:jre:1.6.0:update23:*:*:*:*:*:* | ||
1.6.0CPE matchmatch criteria | cpe:2.3:a:oracle:jre:1.6.0:update24:*:*:*:*:*:* | ||
1.6.0CPE matchmatch criteria | cpe:2.3:a:oracle:jre:1.6.0:update25:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.