CVE-2013-1488
HIGH 10.0EPSS 87.2%
The Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, and OpenJDK 6 and 7, allows remote attackers to execute arbitrary code via unspecified vectors involving reflection, Libraries, "improper toString calls," and the JDBC driver manager, as demonstrated by James Forshaw during a Pwn2Own competition at CanSecWest 2013.
- CVSS v2.0
- 10.0 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C - EPSS
- 87.23% chance of exploitation in the next 30 days, 100th percentile
- Published
- 2013-03-08
- Updated
- 2024-08-06
Proof-of-concept exploits (1)
- v-p-b/buherablog-cve-2013-14884★ · 2015-04-16