peter bassill · operator
$ cve CVE-2013-1493 JSON

CVE-2013-1493 EXPLOIT

10.0
HIGH · CVSS 2.0 · EPSS 86.2% (pctl 100)

Patch early

A public exploit exists.

Description

The color management (CMM) functionality in the 2D component in Oracle Java SE 7 Update 15 and earlier, 6 Update 41 and earlier, and 5.0 Update 40 and earlier allows remote attackers to execute arbitrary code or cause a denial of service (crash) via an image with crafted raster parameters, which triggers (1) an out-of-bounds read or (2) memory corruption in the JVM, as exploited in the wild in February 2013.

Scoring

CVSS10.0 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
EPSS86.15% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-119
On CISA KEVno
Public exploityes
Published2013-03-05
Last modified2026-06-16

Affected (4)

VendorProduct
oraclejdk
oraclejre
sunjdk
sunjre

Public exploits

SourceTitleDate
exploit-dbJava CMM - Remote Code Execution (Metasploit)2013-03-29

References

→ the Explorer  ·  watch your stack  ·  NVD