CVE-2013-2472 is an unspecified vulnerability in the 2D component of Oracle Java SE (versions 7u21 and earlier, 6u45 and earlier, 5.0u45 and earlier) and OpenJDK 7. This critical flaw carries a CVSS score of 10.0, indicating that an unauthenticated remote attacker can achieve complete compromise of confidentiality, integrity, and availability with low attack complexity. While Oracle has not confirmed claims of a sandbox bypass via "Incorrect ShortBandedRaster size checks," an exploit for memory corruption related to ShortComponentRaster.verify() exists on ExploitDB. Despite its high severity and available exploit, the vulnerability is not listed in CISA's KEV catalog, has no Metasploit or Nuclei modules, and shows no significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.7.0CPE matchmatch criteria | cpe:2.3:a:oracle:jre:*:update21:*:*:*:*:*:* | ||
1.7.0CPE matchmatch criteria | cpe:2.3:a:oracle:jre:1.7.0:*:*:*:*:*:*:* | ||
1.7.0CPE matchmatch criteria | cpe:2.3:a:oracle:jre:1.7.0:update1:*:*:*:*:*:* | ||
1.7.0CPE matchmatch criteria | cpe:2.3:a:oracle:jre:1.7.0:update10:*:*:*:*:*:* | ||
1.7.0CPE matchmatch criteria | cpe:2.3:a:oracle:jre:1.7.0:update11:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.