Executive Summary
Informations | |||
---|---|---|---|
Name | CVE-2013-1489 | First vendor Publication | 2013-01-31 |
Vendor | Cve | Last vendor Modification | 2024-11-21 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:L/Au:N/C:C/I:C/A:C) | |||
---|---|---|---|
Cvss Base Score | 10 | Attack Range | Network |
Cvss Impact Score | 10 | Attack Complexity | Low |
Cvss Expoit Score | 10 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 10 and Update 11, when running on Windows using Internet Explorer, Firefox, Opera, and Google Chrome, allows remote attackers to bypass the "Very High" security level of the Java Control Panel and execute unsigned Java code without prompting the user via unknown vectors, aka "Issue 53" and the "Java Security Slider" vulnerability. |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1489 |
OVAL Definitions
Definition Id: oval:org.mitre.oval:def:15906 | |||
Oval ID: | oval:org.mitre.oval:def:15906 | ||
Title: | Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE (subcomponent: Deployment) 7 Update 10 and Update 11, when running on Windows using Internet Explorer, Firefox, Opera, and Google Chrome, allows remote attackers to bypass the "Very High" security level of the Java Control Panel and execute unsigned Java code without prompting the user via unknown vectors, aka "Issue 53" and the "Java Security Slider" vulnerability. | ||
Description: | Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 10 and Update 11, when running on Windows using Internet Explorer, Firefox, Opera, and Google Chrome, allows remote attackers to bypass the "Very High" security level of the Java Control Panel and execute unsigned Java code without prompting the user via unknown vectors, aka "Issue 53" and the "Java Security Slider" vulnerability. | ||
Family: | windows | Class: | vulnerability |
Reference(s): | CVE-2013-1489 | Version: | 4 |
Platform(s): | Microsoft Windows 2000 Microsoft Windows XP Microsoft Windows Vista Microsoft Windows 7 Microsoft Windows 8 Microsoft Windows Server 2003 Microsoft Windows Server 2008 Microsoft Windows Server 2008 R2 Microsoft Windows Server 2012 | Product(s): | Java Runtime Environment |
Definition Synopsis: | |||
Definition Id: oval:org.mitre.oval:def:19171 | |||
Oval ID: | oval:org.mitre.oval:def:19171 | ||
Title: | HP-UX Running Java, Remote Unauthorized Access, Disclosure of Information, and Other Vulnerabilities | ||
Description: | Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 10 and Update 11, when running on Windows using Internet Explorer, Firefox, Opera, and Google Chrome, allows remote attackers to bypass the "Very High" security level of the Java Control Panel and execute unsigned Java code without prompting the user via unknown vectors, aka "Issue 53" and the "Java Security Slider" vulnerability. | ||
Family: | unix | Class: | vulnerability |
Reference(s): | CVE-2013-1489 | Version: | 11 |
Platform(s): | HP-UX 11 | Product(s): | |
Definition Synopsis: | |||
|
CPE : Common Platform Enumeration
Type | Description | Count |
---|---|---|
Application | 2 | |
Application | 2 |
Snort® IPS/IDS
Date | Description |
---|---|
2014-04-03 | Hello/LightsOut exploit kit - exploit targeting Java v1.6.32 and older RuleID : 30009 - Revision : 3 - Type : EXPLOIT-KIT |
2014-04-03 | Hello/LightsOut exploit kit - exploit targeting Microsoft Internet Explorer 8... RuleID : 30008 - Revision : 3 - Type : EXPLOIT-KIT |
2014-04-03 | Hello/LightsOut exploit kit - exploit targeting Microsoft Internet Explorer 7... RuleID : 30007 - Revision : 3 - Type : EXPLOIT-KIT |
2014-04-03 | Hello/LightsOut exploit kit - exploit targeting Microsoft Internet Explorer 6... RuleID : 30006 - Revision : 3 - Type : EXPLOIT-KIT |
2014-04-03 | Hello/LightsOut exploit kit - exploit targeting Google Chrome with Java befor... RuleID : 30005 - Revision : 3 - Type : EXPLOIT-KIT |
2014-04-03 | Hello/LightsOut exploit kit - exploit targeting Java before v1.7.17 RuleID : 30004 - Revision : 3 - Type : EXPLOIT-KIT |
2018-06-15 | Hello/LightsOut exploit kit payload download attempt RuleID : 30003-community - Revision : 6 - Type : EXPLOIT-KIT |
2014-04-03 | Hello/LightsOut exploit kit payload download attempt RuleID : 30003 - Revision : 6 - Type : EXPLOIT-KIT |
2014-04-03 | Hello/LightsOut exploit kit Java download attempt RuleID : 30002 - Revision : 3 - Type : EXPLOIT-KIT |
2014-04-03 | Hello/LightsOut exploit kit landing page detected RuleID : 30001 - Revision : 3 - Type : EXPLOIT-KIT |
2014-01-10 | Oracle Java Security Slider feature bypass attempt RuleID : 27766 - Revision : 2 - Type : BROWSER-PLUGINS |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2014-08-22 | Name : The remote host is affected by multiple vulnerabilities. File : juniper_nsm_jsa10642.nasl - Type : ACT_GATHER_INFO |
2014-01-08 | Name : The remote server is affected by multiple vulnerabilities. File : domino_9_0_1.nasl - Type : ACT_GATHER_INFO |
2014-01-08 | Name : The remote host has software installed that is affected by multiple vulnerabi... File : lotus_domino_9_0_1.nasl - Type : ACT_GATHER_INFO |
2013-11-04 | Name : The remote server is affected by multiple vulnerabilities. File : domino_8_5_3fp5.nasl - Type : ACT_GATHER_INFO |
2013-11-04 | Name : The remote host has software installed that is affected by multiple vulnerabi... File : lotus_domino_8_5_3_fp5.nasl - Type : ACT_GATHER_INFO |
2013-11-04 | Name : The remote host has software installed that is affected by multiple vulnerabi... File : lotus_notes_8_5_3_fp5.nasl - Type : ACT_GATHER_INFO |
2013-02-22 | Name : The remote Unix host contains a programming platform that is potentially affe... File : oracle_java_cpu_feb_2013_unix.nasl - Type : ACT_GATHER_INFO |
2013-02-05 | Name : The remote host has a version of Java that is affected by multiple vulnerabil... File : macosx_java_10_6_update12.nasl - Type : ACT_GATHER_INFO |
2013-02-05 | Name : The remote Red Hat host is missing one or more security updates. File : redhat-RHSA-2013-0237.nasl - Type : ACT_GATHER_INFO |
2013-02-04 | Name : The remote Windows host contains a programming platform that is potentially a... File : oracle_java_cpu_feb_2013.nasl - Type : ACT_GATHER_INFO |
Sources (Detail)
Alert History
Date | Informations |
---|---|
2024-11-28 12:34:00 |
|
2023-11-07 21:46:27 |
|
2020-05-23 00:36:30 |
|
2017-09-19 09:25:53 |
|
2016-06-28 19:22:12 |
|
2016-04-26 22:58:03 |
|
2014-04-03 21:21:29 |
|
2014-02-17 11:17:47 |
|
2014-01-19 21:29:15 |
|
2013-12-05 17:19:48 |
|
2013-11-04 21:26:15 |
|
2013-06-05 13:20:09 |
|
2013-05-10 22:29:40 |
|
2013-02-26 13:19:18 |
|
2013-02-07 13:24:47 |
|
2013-02-04 21:22:09 |
|
2013-02-02 13:24:19 |
|
2013-02-01 21:24:44 |
|
2013-01-31 17:19:21 |
|