← Back

CVE-2013-0434

nvd nist
Published: Feb 2, 2013Modified: Apr 29, 2026

JSON object

Loading...
5.0
Vector
AV:N/AC:L/Au:N/C:P/I:N/A:N
Exploitability: 10.0 / Impact: 2.9
Source: NVD

Description

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, 5.0 through Update 38, and 1.4.2_40 and earlier, and OpenJDK 6 and 7, allows remote attackers to affect confidentiality via vectors related to JAXP. NOTE: the previous information is from the February 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to the public declaration of the loadPropertyFile method in the JAXP FuncSystemProperty class, which allows remote attackers to obtain sensitive information.

Affected (241)

Products: Oracle: Jre, Jdk · Sun: Jre, Jdk
2 products
Jre
Jdk
2 products
Jre
Jdk
Configuration A
11 vulnerable
Vulnerable SoftwareAffected Versions
Oracle
Version 1.7.0
Version 1.7.0 update10
Version 1.7.0 update11
Version 1.7.0 update1
Version 1.7.0 update2
Version 1.7.0 update3
Version 1.7.0 update4
Version 1.7.0 update5
Version 1.7.0 update6
Version 1.7.0 update7
Version 1.7.0 update9
Configuration B
11 vulnerable
Vulnerable SoftwareAffected Versions
Oracle
Version 1.7.0
Version 1.7.0 update10
Version 1.7.0 update11
Version 1.7.0 update1
Version 1.7.0 update2
Version 1.7.0 update3
Version 1.7.0 update4
Version 1.7.0 update5
Version 1.7.0 update6
Version 1.7.0 update7
Version 1.7.0 update9
Configuration C
36 vulnerable
Vulnerable SoftwareAffected Versions
Oracle
Version 1.6.0 update22
Version 1.6.0 update23
Version 1.6.0 update24
Version 1.6.0 update25
Version 1.6.0 update26
Version 1.6.0 update27
Version 1.6.0 update29
Version 1.6.0 update30
Version 1.6.0 update31
Version 1.6.0 update32
Version 1.6.0 update33
Version 1.6.0 update34
Version 1.6.0 update35
Version 1.6.0 update37
Version 1.6.0 update38
Sun
Version 1.6.0
Version 1.6.0 update_10
Version 1.6.0 update_11
Version 1.6.0 update_12
Version 1.6.0 update_13
Version 1.6.0 update_14
Version 1.6.0 update_15
Version 1.6.0 update_16
Version 1.6.0 update_17
Version 1.6.0 update_18
Version 1.6.0 update_19
Version 1.6.0 update_1
Version 1.6.0 update_20
Version 1.6.0 update_21
Version 1.6.0 update_2
Version 1.6.0 update_3
Version 1.6.0 update_4
Version 1.6.0 update_5
Version 1.6.0 update_6
Version 1.6.0 update_7
Version 1.6.0 update_9
Configuration D
36 vulnerable
Vulnerable SoftwareAffected Versions
Oracle
Version 1.6.0 update22
Version 1.6.0 update23
Version 1.6.0 update24
Version 1.6.0 update25
Version 1.6.0 update26
Version 1.6.0 update27
Version 1.6.0 update29
Version 1.6.0 update30
Version 1.6.0 update31
Version 1.6.0 update32
Version 1.6.0 update33
Version 1.6.0 update34
Version 1.6.0 update35
Version 1.6.0 update37
Version 1.6.0 update38
Sun
Version 1.6.0
Version 1.6.0 update1
Version 1.6.0 update1_b06
Version 1.6.0 update2
Version 1.6.0 update_10
Version 1.6.0 update_11
Version 1.6.0 update_12
Version 1.6.0 update_13
Version 1.6.0 update_14
Version 1.6.0 update_15
Version 1.6.0 update_16
Version 1.6.0 update_17
Version 1.6.0 update_18
Version 1.6.0 update_19
Version 1.6.0 update_20
Version 1.6.0 update_21
Version 1.6.0 update_3
Version 1.6.0 update_4
Version 1.6.0 update_5
Version 1.6.0 update_6
Version 1.6.0 update_7
Configuration E
34 vulnerable
Vulnerable SoftwareAffected Versions
Oracle
Version 1.5.0 update36
Version 1.5.0 update38
Sun
Version 1.5.0
Version 1.5.0 update10
Version 1.5.0 update11
Version 1.5.0 update12
Version 1.5.0 update13
Version 1.5.0 update14
Version 1.5.0 update15
Version 1.5.0 update16
Version 1.5.0 update17
Version 1.5.0 update18
Version 1.5.0 update19
Version 1.5.0 update1
Version 1.5.0 update20
Version 1.5.0 update21
Version 1.5.0 update22
Version 1.5.0 update23
Version 1.5.0 update24
Version 1.5.0 update25
Version 1.5.0 update26
Version 1.5.0 update27
Version 1.5.0 update28
Version 1.5.0 update29
Version 1.5.0 update2
Version 1.5.0 update31
Version 1.5.0 update33
Version 1.5.0 update3
Version 1.5.0 update4
Version 1.5.0 update5
Version 1.5.0 update6
Version 1.5.0 update7
Version 1.5.0 update8
Version 1.5.0 update9
Configuration F
36 vulnerable
Vulnerable SoftwareAffected Versions
Oracle
Version 1.5.0 update36
Version 1.5.0 update38
Sun
Version 1.5.0
Version 1.5.0 update10
Version 1.5.0 update11
Version 1.5.0 update11_b03
Version 1.5.0 update12
Version 1.5.0 update13
Version 1.5.0 update14
Version 1.5.0 update15
Version 1.5.0 update16
Version 1.5.0 update17
Version 1.5.0 update18
Version 1.5.0 update19
Version 1.5.0 update1
Version 1.5.0 update20
Version 1.5.0 update21
Version 1.5.0 update22
Version 1.5.0 update23
Version 1.5.0 update24
Version 1.5.0 update25
Version 1.5.0 update26
Version 1.5.0 update27
Version 1.5.0 update28
Version 1.5.0 update29
Version 1.5.0 update2
Version 1.5.0 update31
Version 1.5.0 update33
Version 1.5.0 update3
Version 1.5.0 update4
Version 1.5.0 update5
Version 1.5.0 update6
Version 1.5.0 update7
Version 1.5.0 update7_b03
Version 1.5.0 update8
Version 1.5.0 update9
Configuration G
40 vulnerable
Vulnerable SoftwareAffected Versions
Oracle
Up to 1.4.2_40
Version 1.4.2_38
Sun
Version 1.4.2
Version 1.4.2_10
Version 1.4.2_11
Version 1.4.2_12
Version 1.4.2_13
Version 1.4.2_14
Version 1.4.2_15
Version 1.4.2_16
Version 1.4.2_17
Version 1.4.2_18
Version 1.4.2_19
Version 1.4.2_1
Version 1.4.2_20
Version 1.4.2_21
Version 1.4.2_22
Version 1.4.2_23
Version 1.4.2_24
Version 1.4.2_25
Version 1.4.2_26
Version 1.4.2_27
Version 1.4.2_28
Version 1.4.2_29
Version 1.4.2_2
Version 1.4.2_30
Version 1.4.2_31
Version 1.4.2_32
Version 1.4.2_33
Version 1.4.2_34
Version 1.4.2_35
Version 1.4.2_36
Version 1.4.2_37
Version 1.4.2_3
Version 1.4.2_4
Version 1.4.2_5
Version 1.4.2_6
Version 1.4.2_7
Version 1.4.2_8
Version 1.4.2_9
Configuration H
37 vulnerable
Vulnerable SoftwareAffected Versions
Oracle
Up to 1.4.2_40
Version 1.4.2_38
Sun
Version 1.4.2
Version 1.4.2_10
Version 1.4.2_11
Version 1.4.2_12
Version 1.4.2_13
Version 1.4.2_14
Version 1.4.2_15
Version 1.4.2_16
Version 1.4.2_17
Version 1.4.2_18
Version 1.4.2_19
Version 1.4.2_1
Version 1.4.2_22
Version 1.4.2_23
Version 1.4.2_25
Version 1.4.2_26
Version 1.4.2_27
Version 1.4.2_28
Version 1.4.2_29
Version 1.4.2_2
Version 1.4.2_30
Version 1.4.2_31
Version 1.4.2_32
Version 1.4.2_33
Version 1.4.2_34
Version 1.4.2_35
Version 1.4.2_36
Version 1.4.2_37
Version 1.4.2_3
Version 1.4.2_4
Version 1.4.2_5
Version 1.4.2_6
Version 1.4.2_7
Version 1.4.2_8
Version 1.4.2_9

References (54)

Source: secalert_us@oracle.com
US Government Resource
Source: secalert_us@oracle.com
Source: secalert_us@oracle.com
US Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
US Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
US Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.