CVE-2013-1489

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 10 and Update 11, when running on Windows using Internet Explorer, Firefox, Opera, and Google Chrome, allows remote attackers to bypass the "Very High" security level of the Java Control Panel and execute unsigned Java code without prompting the user via unknown vectors, aka "Issue 53" and the "Java Security Slider" vulnerability.
References
Link Resource
http://blogs.computerworld.com/malware-and-vulnerabilities/21693/yet-another-java-security-flaw-discovered-number-53
http://marc.info/?l=bugtraq&m=136439120408139&w=2
http://marc.info/?l=bugtraq&m=136439120408139&w=2
http://marc.info/?l=bugtraq&m=136733161405818&w=2
http://marc.info/?l=bugtraq&m=136733161405818&w=2
http://rhn.redhat.com/errata/RHSA-2013-0237.html
http://seclists.org/fulldisclosure/2013/Jan/241
http://thenextweb.com/insider/2013/01/28/new-vulnerability-bypasses-oracles-attempt-to-stop-malware-drive-by-downloads-via-java-applets/
http://www.informationweek.com/security/application-security/java-security-work-remains-bug-hunter-sa/240147150
http://www.kb.cert.org/vuls/id/858729 US Government Resource
http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html Vendor Advisory
http://www.scmagazine.com.au/News/330453%2Cjava-still-unsafe-new-flaws-discovered.aspx
http://www.us-cert.gov/cas/techalerts/TA13-032A.html US Government Resource
http://www.zdnet.com/java-update-doesnt-prevent-silent-exploits-at-all-7000010422/
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A15906
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19171
http://blogs.computerworld.com/malware-and-vulnerabilities/21693/yet-another-java-security-flaw-discovered-number-53
http://marc.info/?l=bugtraq&m=136439120408139&w=2
http://marc.info/?l=bugtraq&m=136439120408139&w=2
http://marc.info/?l=bugtraq&m=136733161405818&w=2
http://marc.info/?l=bugtraq&m=136733161405818&w=2
http://rhn.redhat.com/errata/RHSA-2013-0237.html
http://seclists.org/fulldisclosure/2013/Jan/241
http://thenextweb.com/insider/2013/01/28/new-vulnerability-bypasses-oracles-attempt-to-stop-malware-drive-by-downloads-via-java-applets/
http://www.informationweek.com/security/application-security/java-security-work-remains-bug-hunter-sa/240147150
http://www.kb.cert.org/vuls/id/858729 US Government Resource
http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html Vendor Advisory
http://www.scmagazine.com.au/News/330453%2Cjava-still-unsafe-new-flaws-discovered.aspx
http://www.us-cert.gov/cas/techalerts/TA13-032A.html US Government Resource
http://www.zdnet.com/java-update-doesnt-prevent-silent-exploits-at-all-7000010422/
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A15906
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19171
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:a:oracle:jdk:1.7.0:update10:*:*:*:windows:*:*
cpe:2.3:a:oracle:jdk:1.7.0:update11:*:*:*:windows:*:*
cpe:2.3:a:oracle:jre:1.7.0:update10:*:*:*:windows:*:*
cpe:2.3:a:oracle:jre:1.7.0:update11:*:*:*:windows:*:*
OR cpe:2.3:a:google:chrome:-:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:internet_explorer:-:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:-:*:*:*:*:*:*:*

History

21 Nov 2024, 01:49

Type Values Removed Values Added
References () http://blogs.computerworld.com/malware-and-vulnerabilities/21693/yet-another-java-security-flaw-discovered-number-53 - () http://blogs.computerworld.com/malware-and-vulnerabilities/21693/yet-another-java-security-flaw-discovered-number-53 -
References () http://marc.info/?l=bugtraq&m=136439120408139&w=2 - () http://marc.info/?l=bugtraq&m=136439120408139&w=2 -
References () http://marc.info/?l=bugtraq&m=136733161405818&w=2 - () http://marc.info/?l=bugtraq&m=136733161405818&w=2 -
References () http://rhn.redhat.com/errata/RHSA-2013-0237.html - () http://rhn.redhat.com/errata/RHSA-2013-0237.html -
References () http://seclists.org/fulldisclosure/2013/Jan/241 - () http://seclists.org/fulldisclosure/2013/Jan/241 -
References () http://thenextweb.com/insider/2013/01/28/new-vulnerability-bypasses-oracles-attempt-to-stop-malware-drive-by-downloads-via-java-applets/ - () http://thenextweb.com/insider/2013/01/28/new-vulnerability-bypasses-oracles-attempt-to-stop-malware-drive-by-downloads-via-java-applets/ -
References () http://www.informationweek.com/security/application-security/java-security-work-remains-bug-hunter-sa/240147150 - () http://www.informationweek.com/security/application-security/java-security-work-remains-bug-hunter-sa/240147150 -
References () http://www.kb.cert.org/vuls/id/858729 - US Government Resource () http://www.kb.cert.org/vuls/id/858729 - US Government Resource
References () http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html - Vendor Advisory () http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html - Vendor Advisory
References () http://www.scmagazine.com.au/News/330453%2Cjava-still-unsafe-new-flaws-discovered.aspx - () http://www.scmagazine.com.au/News/330453%2Cjava-still-unsafe-new-flaws-discovered.aspx -
References () http://www.us-cert.gov/cas/techalerts/TA13-032A.html - US Government Resource () http://www.us-cert.gov/cas/techalerts/TA13-032A.html - US Government Resource
References () http://www.zdnet.com/java-update-doesnt-prevent-silent-exploits-at-all-7000010422/ - () http://www.zdnet.com/java-update-doesnt-prevent-silent-exploits-at-all-7000010422/ -
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A15906 - () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A15906 -
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19171 - () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19171 -

07 Nov 2023, 02:14

Type Values Removed Values Added
References
  • {'url': 'http://www.scmagazine.com.au/News/330453,java-still-unsafe-new-flaws-discovered.aspx', 'name': 'http://www.scmagazine.com.au/News/330453,java-still-unsafe-new-flaws-discovered.aspx', 'tags': [], 'refsource': 'MISC'}
  • () http://www.scmagazine.com.au/News/330453%2Cjava-still-unsafe-new-flaws-discovered.aspx -

Information

Published : 2013-01-31 14:55

Updated : 2024-11-21 01:49


NVD link : CVE-2013-1489

Mitre link : CVE-2013-1489

CVE.ORG link : CVE-2013-1489


JSON object : View

Products Affected

mozilla

  • firefox

oracle

  • jre
  • jdk

google

  • chrome

microsoft

  • internet_explorer

opera

  • opera_browser