CVE-2013-1493
The color management (CMM) functionality in the 2D component in Oracle Java SE 7 Update 15 and earlier, 6 Update 41 and earlier, and 5.0 Update 40 and earlier allows remote attackers to execute arbitrary code or cause a denial of service (crash) via an image with crafted raster parameters, which triggers (1) an out-of-bounds read or (2) memory corruption in the JVM, as exploited in the wild in February 2013.
- Oracle Jre
- ≤ 1.7.0
- Fix
- Available
- CVSS 2.0
- 10.0 HIGH
- EPSS
- 86.2% (100th percentile)
- Weakness
- CWE-119
- NVD status
- Modified
- Published
- 2013-03-04
CVE-2013-1493 at NVD
10 known exploits for CVE-2013-1493
Proof-of-concept code and exploit modules indexed by Sploitus
Java CMM Remote Code Execution
HP Service Manager多个安全漏洞
Java Runtime Environment Color Management memory overwrite
Java Runtime Environment Color Management memory overwrite
Java Runtime Environment Color Management memory overwrite
Java Runtime Environment Color Management memory overwrite
Java CMM - Remote Code Execution (Metasploit)
Java CMM Remote Code Execution Vulnerability
Java CMM Remote Code Execution
Java CMM Remote Code Execution