CVE-2013-2471 is an unspecified vulnerability in Oracle Java SE and OpenJDK versions, particularly affecting the 2D component, which allows remote attackers to impact confidentiality, integrity, and availability. With a CVSS score of 10.0, it represents a critical threat due to its network-based attack vector, low attack complexity, and complete compromise potential across all three security pillars. Although Oracle did not confirm specific details, other vendors suggested it could bypass the Java sandbox through incorrect integer component raster size checks. Despite its high risk scores (FAUCET 97/100, EPSS 0.40067), there is no public exploit code available in Metasploit, Nuclei, or ExploitDB, and it is not listed in the KEV catalog. Community discussion and media coverage are present but do not indicate widespread active exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.7.0CPE matchmatch criteria | cpe:2.3:a:oracle:jre:*:update21:*:*:*:*:*:* | ||
1.7.0CPE matchmatch criteria | cpe:2.3:a:oracle:jre:1.7.0:*:*:*:*:*:*:* | ||
1.7.0CPE matchmatch criteria | cpe:2.3:a:oracle:jre:1.7.0:update1:*:*:*:*:*:* | ||
1.7.0CPE matchmatch criteria | cpe:2.3:a:oracle:jre:1.7.0:update10:*:*:*:*:*:* | ||
1.7.0CPE matchmatch criteria | cpe:2.3:a:oracle:jre:1.7.0:update11:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.