Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2013-5791

22
FAUCET Score

CVE-2013-5791 is an unspecified vulnerability within Oracle Outside In Technology components of Oracle Fusion Middleware versions 8.4.0 and 8.4.1, potentially affecting availability. While Oracle's official description is vague, third-party claims suggest it's a stack-based buffer overflow in the Microsoft Access 1.x parser (vsacs.dll) exploitable via long field names. With a CVSS score of 1.5, it has a low attack complexity and requires local access and authentication, primarily impacting availability. Although not in CISA's KEV catalog, a Proof-of-Concept exploit is publicly available on ExploitDB, and it has garnered significant community discussion and media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
8.4CPE matchmatch criteria
cpe:2.3:a:oracle:fusion_middleware:8.4:*:*:*:*:*:*:*
8.4.1CPE matchmatch criteria
cpe:2.3:a:oracle:fusion_middleware:8.4.1:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

1.5LOW

AV:L/AC:M/Au:S/C:N/I:N/A:P

Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
PARTIAL
Access Vector
LOCAL
Access Complexity
MEDIUM
Authentication
SINGLE
Exploitability Score
2.7
Impact Score
2.9
CvssVersion
2.0

Exploit Intelligence

EPSS Score
1.90%
Probability of exploitation in next 30 days
EPSS Percentile
77.5%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
ExploitDB: EDB-31222 · Jan 27, 2014
This CVE's current EPSS score of 0.0190 is in the 99th percentile among its peer group of 223 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Patches (1)

oraclevendor investigatingvia nvd_reference
View patch

References

docs.microsoft.com / en-us/security-updates/securitybulletins/2013/ms13-105
secunia.com / advisories/56237
secunia.com / advisories/56241
secunia.com / advisories/56243
www-01.ibm.com / support/docview.wss
citadelo.com / en/ms13-105-oracle-outside-in-mdb-parsing-vulnerability-cve-2013-5791
exploit-db.com / exploits/31222
kb.cert.org / vuls/id/953241
US Government Resource
oracle.com / technetwork/topics/security/cpuoct2013-1899837.html
Vendor Advisory
securityfocus.com / bid/63076
securitytracker.com / id/1029190