CVE-2013-2463 is an unspecified vulnerability within the 2D component of Oracle Java SE (versions 7u21 and earlier, 6u45 and earlier, 5.0u45 and earlier) and OpenJDK 7, allowing remote attackers to compromise confidentiality, integrity, and availability. With a CVSS score of 10.0 (AV:N/AC:L/Au:N/C:C/I:C/A:C), it represents a critical risk, indicating it can be exploited remotely with low complexity and lead to complete compromise. While Oracle did not confirm details, other vendors claimed it allowed sandbox bypass via incorrect image attribute verification. This vulnerability has been actively exploited, with exploit code integrated into attack kits like Neutrino, and has garnered significant community and media attention, including coverage by SecurityWeek.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.7.0CPE matchmatch criteria | cpe:2.3:a:oracle:jre:*:update21:*:*:*:*:*:* | ||
1.7.0CPE matchmatch criteria | cpe:2.3:a:oracle:jre:1.7.0:*:*:*:*:*:*:* | ||
1.7.0CPE matchmatch criteria | cpe:2.3:a:oracle:jre:1.7.0:update1:*:*:*:*:*:* | ||
1.7.0CPE matchmatch criteria | cpe:2.3:a:oracle:jre:1.7.0:update10:*:*:*:*:*:* | ||
1.7.0CPE matchmatch criteria | cpe:2.3:a:oracle:jre:1.7.0:update11:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.