VYPR
Unrated severityNVD Advisory· Published Jun 18, 2013· Updated Apr 29, 2026

CVE-2013-2407

CVE-2013-2407

Description

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier and 6 Update 45 and earlier, and OpenJDK 7, allows remote attackers to affect confidentiality and availability via unknown vectors related to Libraries. NOTE: the previous information is from the June 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to "XML security and the class loader."

Affected products

141
  • cpe:2.3:a:oracle:jdk:1.6.0:update22:*:*:*:*:*:*+ 33 more
    • cpe:2.3:a:oracle:jdk:1.6.0:update22:*:*:*:*:*:*
    • cpe:2.3:a:oracle:jdk:1.6.0:update23:*:*:*:*:*:*
    • cpe:2.3:a:oracle:jdk:1.6.0:update24:*:*:*:*:*:*
    • cpe:2.3:a:oracle:jdk:1.6.0:update25:*:*:*:*:*:*
    • cpe:2.3:a:oracle:jdk:1.6.0:update26:*:*:*:*:*:*
    • cpe:2.3:a:oracle:jdk:1.6.0:update27:*:*:*:*:*:*
    • cpe:2.3:a:oracle:jdk:1.6.0:update29:*:*:*:*:*:*
    • cpe:2.3:a:oracle:jdk:1.6.0:update30:*:*:*:*:*:*
    • cpe:2.3:a:oracle:jdk:1.6.0:update31:*:*:*:*:*:*
    • cpe:2.3:a:oracle:jdk:1.6.0:update32:*:*:*:*:*:*
    • cpe:2.3:a:oracle:jdk:1.6.0:update33:*:*:*:*:*:*
    • cpe:2.3:a:oracle:jdk:1.6.0:update34:*:*:*:*:*:*
    • cpe:2.3:a:oracle:jdk:1.6.0:update35:*:*:*:*:*:*
    • cpe:2.3:a:oracle:jdk:1.6.0:update37:*:*:*:*:*:*
    • cpe:2.3:a:oracle:jdk:1.6.0:update38:*:*:*:*:*:*
    • cpe:2.3:a:oracle:jdk:1.6.0:update39:*:*:*:*:*:*
    • cpe:2.3:a:oracle:jdk:1.6.0:update41:*:*:*:*:*:*
    • cpe:2.3:a:oracle:jdk:1.6.0:update43:*:*:*:*:*:*
    • cpe:2.3:a:oracle:jdk:1.7.0:*:*:*:*:*:*:*
    • cpe:2.3:a:oracle:jdk:1.7.0:update1:*:*:*:*:*:*
    • cpe:2.3:a:oracle:jdk:1.7.0:update10:*:*:*:*:*:*
    • cpe:2.3:a:oracle:jdk:1.7.0:update11:*:*:*:*:*:*
    • cpe:2.3:a:oracle:jdk:1.7.0:update13:*:*:*:*:*:*
    • cpe:2.3:a:oracle:jdk:1.7.0:update15:*:*:*:*:*:*
    • cpe:2.3:a:oracle:jdk:1.7.0:update17:*:*:*:*:*:*
    • cpe:2.3:a:oracle:jdk:1.7.0:update2:*:*:*:*:*:*
    • cpe:2.3:a:oracle:jdk:1.7.0:update3:*:*:*:*:*:*
    • cpe:2.3:a:oracle:jdk:1.7.0:update4:*:*:*:*:*:*
    • cpe:2.3:a:oracle:jdk:1.7.0:update5:*:*:*:*:*:*
    • cpe:2.3:a:oracle:jdk:1.7.0:update6:*:*:*:*:*:*
    • cpe:2.3:a:oracle:jdk:1.7.0:update7:*:*:*:*:*:*
    • cpe:2.3:a:oracle:jdk:1.7.0:update9:*:*:*:*:*:*
    • cpe:2.3:a:oracle:jdk:*:update21:*:*:*:*:*:*range: <=1.7.0
    • cpe:2.3:a:oracle:jdk:*:update45:*:*:*:*:*:*range: <=1.6.0
  • cpe:2.3:a:oracle:jre:1.6.0:update22:*:*:*:*:*:*+ 33 more
    • cpe:2.3:a:oracle:jre:1.6.0:update22:*:*:*:*:*:*
    • cpe:2.3:a:oracle:jre:1.6.0:update23:*:*:*:*:*:*
    • cpe:2.3:a:oracle:jre:1.6.0:update24:*:*:*:*:*:*
    • cpe:2.3:a:oracle:jre:1.6.0:update25:*:*:*:*:*:*
    • cpe:2.3:a:oracle:jre:1.6.0:update26:*:*:*:*:*:*
    • cpe:2.3:a:oracle:jre:1.6.0:update27:*:*:*:*:*:*
    • cpe:2.3:a:oracle:jre:1.6.0:update29:*:*:*:*:*:*
    • cpe:2.3:a:oracle:jre:1.6.0:update30:*:*:*:*:*:*
    • cpe:2.3:a:oracle:jre:1.6.0:update31:*:*:*:*:*:*
    • cpe:2.3:a:oracle:jre:1.6.0:update32:*:*:*:*:*:*
    • cpe:2.3:a:oracle:jre:1.6.0:update33:*:*:*:*:*:*
    • cpe:2.3:a:oracle:jre:1.6.0:update34:*:*:*:*:*:*
    • cpe:2.3:a:oracle:jre:1.6.0:update35:*:*:*:*:*:*
    • cpe:2.3:a:oracle:jre:1.6.0:update37:*:*:*:*:*:*
    • cpe:2.3:a:oracle:jre:1.6.0:update38:*:*:*:*:*:*
    • cpe:2.3:a:oracle:jre:1.6.0:update39:*:*:*:*:*:*
    • cpe:2.3:a:oracle:jre:1.6.0:update41:*:*:*:*:*:*
    • cpe:2.3:a:oracle:jre:1.6.0:update43:*:*:*:*:*:*
    • cpe:2.3:a:oracle:jre:1.7.0:*:*:*:*:*:*:*
    • cpe:2.3:a:oracle:jre:1.7.0:update1:*:*:*:*:*:*
    • cpe:2.3:a:oracle:jre:1.7.0:update10:*:*:*:*:*:*
    • cpe:2.3:a:oracle:jre:1.7.0:update11:*:*:*:*:*:*
    • cpe:2.3:a:oracle:jre:1.7.0:update13:*:*:*:*:*:*
    • cpe:2.3:a:oracle:jre:1.7.0:update15:*:*:*:*:*:*
    • cpe:2.3:a:oracle:jre:1.7.0:update17:*:*:*:*:*:*
    • cpe:2.3:a:oracle:jre:1.7.0:update2:*:*:*:*:*:*
    • cpe:2.3:a:oracle:jre:1.7.0:update3:*:*:*:*:*:*
    • cpe:2.3:a:oracle:jre:1.7.0:update4:*:*:*:*:*:*
    • cpe:2.3:a:oracle:jre:1.7.0:update5:*:*:*:*:*:*
    • cpe:2.3:a:oracle:jre:1.7.0:update6:*:*:*:*:*:*
    • cpe:2.3:a:oracle:jre:1.7.0:update7:*:*:*:*:*:*
    • cpe:2.3:a:oracle:jre:1.7.0:update9:*:*:*:*:*:*
    • cpe:2.3:a:oracle:jre:*:update21:*:*:*:*:*:*range: <=1.7.0
    • cpe:2.3:a:oracle:jre:*:update45:*:*:*:*:*:*range: <=1.6.0
  • Sun Corporation/Jdk21 versions
    cpe:2.3:a:sun:jdk:1.6.0:*:*:*:*:*:*:*+ 20 more
    • cpe:2.3:a:sun:jdk:1.6.0:*:*:*:*:*:*:*
    • cpe:2.3:a:sun:jdk:1.6.0:update1:*:*:*:*:*:*
    • cpe:2.3:a:sun:jdk:1.6.0:update_10:*:*:*:*:*:*
    • cpe:2.3:a:sun:jdk:1.6.0:update_11:*:*:*:*:*:*
    • cpe:2.3:a:sun:jdk:1.6.0:update_12:*:*:*:*:*:*
    • cpe:2.3:a:sun:jdk:1.6.0:update_13:*:*:*:*:*:*
    • cpe:2.3:a:sun:jdk:1.6.0:update_14:*:*:*:*:*:*
    • cpe:2.3:a:sun:jdk:1.6.0:update_15:*:*:*:*:*:*
    • cpe:2.3:a:sun:jdk:1.6.0:update_16:*:*:*:*:*:*
    • cpe:2.3:a:sun:jdk:1.6.0:update_17:*:*:*:*:*:*
    • cpe:2.3:a:sun:jdk:1.6.0:update_18:*:*:*:*:*:*
    • cpe:2.3:a:sun:jdk:1.6.0:update_19:*:*:*:*:*:*
    • cpe:2.3:a:sun:jdk:1.6.0:update1_b06:*:*:*:*:*:*
    • cpe:2.3:a:sun:jdk:1.6.0:update2:*:*:*:*:*:*
    • cpe:2.3:a:sun:jdk:1.6.0:update_20:*:*:*:*:*:*
    • cpe:2.3:a:sun:jdk:1.6.0:update_21:*:*:*:*:*:*
    • cpe:2.3:a:sun:jdk:1.6.0:update_3:*:*:*:*:*:*
    • cpe:2.3:a:sun:jdk:1.6.0:update_4:*:*:*:*:*:*
    • cpe:2.3:a:sun:jdk:1.6.0:update_5:*:*:*:*:*:*
    • cpe:2.3:a:sun:jdk:1.6.0:update_6:*:*:*:*:*:*
    • cpe:2.3:a:sun:jdk:1.6.0:update_7:*:*:*:*:*:*
  • Sun Corporation/Jre21 versions
    cpe:2.3:a:sun:jre:1.6.0:*:*:*:*:*:*:*+ 20 more
    • cpe:2.3:a:sun:jre:1.6.0:*:*:*:*:*:*:*
    • cpe:2.3:a:sun:jre:1.6.0:update_1:*:*:*:*:*:*
    • cpe:2.3:a:sun:jre:1.6.0:update_10:*:*:*:*:*:*
    • cpe:2.3:a:sun:jre:1.6.0:update_11:*:*:*:*:*:*
    • cpe:2.3:a:sun:jre:1.6.0:update_12:*:*:*:*:*:*
    • cpe:2.3:a:sun:jre:1.6.0:update_13:*:*:*:*:*:*
    • cpe:2.3:a:sun:jre:1.6.0:update_14:*:*:*:*:*:*
    • cpe:2.3:a:sun:jre:1.6.0:update_15:*:*:*:*:*:*
    • cpe:2.3:a:sun:jre:1.6.0:update_16:*:*:*:*:*:*
    • cpe:2.3:a:sun:jre:1.6.0:update_17:*:*:*:*:*:*
    • cpe:2.3:a:sun:jre:1.6.0:update_18:*:*:*:*:*:*
    • cpe:2.3:a:sun:jre:1.6.0:update_19:*:*:*:*:*:*
    • cpe:2.3:a:sun:jre:1.6.0:update_2:*:*:*:*:*:*
    • cpe:2.3:a:sun:jre:1.6.0:update_20:*:*:*:*:*:*
    • cpe:2.3:a:sun:jre:1.6.0:update_21:*:*:*:*:*:*
    • cpe:2.3:a:sun:jre:1.6.0:update_3:*:*:*:*:*:*
    • cpe:2.3:a:sun:jre:1.6.0:update_4:*:*:*:*:*:*
    • cpe:2.3:a:sun:jre:1.6.0:update_5:*:*:*:*:*:*
    • cpe:2.3:a:sun:jre:1.6.0:update_6:*:*:*:*:*:*
    • cpe:2.3:a:sun:jre:1.6.0:update_7:*:*:*:*:*:*
    • cpe:2.3:a:sun:jre:1.6.0:update_9:*:*:*:*:*:*
  • osv-coords31 versions
    < 0.53.0-r0+ 30 more
    • (no CPE)range: < 0.53.0-r0
    • (no CPE)range: < 0.53.0-r0
    • (no CPE)range: < 0.53.0-r0
    • (no CPE)range: < 0.53.0-r0
    • (no CPE)range: < 0.53.0-r0
    • (no CPE)range: < 0.53.0-r0
    • (no CPE)range: < 0.53.0-r0
    • (no CPE)range: < 0.53.0-r0
    • (no CPE)range: < 0.53.0-r0
    • (no CPE)range: < 0.53.0-r0
    • (no CPE)range: < 0.53.0-r0
    • (no CPE)range: < 0.53.0-r0
    • (no CPE)range: < 0.53.0-r0
    • (no CPE)range: < 0.53.0-r0
    • (no CPE)range: < 0.53.0-r0
    • (no CPE)range: < 0.53.0-r0
    • (no CPE)range: < 0.48.0-r2
    • (no CPE)range: < 0.48.0-r2
    • (no CPE)range: < 0.48.0-r2
    • (no CPE)range: < 0.48.0-r2
    • (no CPE)range: < 0.48.0-r2
    • (no CPE)range: < 0.48.0-r2
    • (no CPE)range: < 0.48.0-r2
    • (no CPE)range: < 0.48.0-r2
    • (no CPE)range: < 0.53.0-r1
    • (no CPE)range: < 0.53.0-r1
    • (no CPE)range: < 0.53.0-r1
    • (no CPE)range: < 0.53.0-r1
    • (no CPE)range: < 0.53.0-r1
    • (no CPE)range: < 0.53.0-r1
    • (no CPE)range: < 1.7.0.121-1.1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

26

News mentions

0

No linked articles in our index yet.