Skip to main content

CVE detail

CVE-2013-2465

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier, and OpenJDK 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D. NOTE: the previous information is from the June 2013 CPU. Oracle has not commented on claims from another vendor that this issue allows remote attackers to bypass the Java sandbox via vectors related to "Incorrect image channel verification" in 2D.

CVSS 9.8 · CriticalBuzz score 64.3KEV listed

Buzz score

Why this CVE is surfacing

Buzz score total 64.3

This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.

Buzz score components · mention 28.3 · diversity 11.0 · KEV 25.0 · OTX 0.0 · PoC 0.0
Mention score
28.3
16 evidence mentions in the snapshot
Diversity score
11.0
5 sources across 1 categories
KEV score
25.0
Known exploited vulnerability present
OTX score
0.0
0 OTX pulses
PoC score
0.0
0 repos · best confidence N/A
Best PoC traction
0
Maximum stars on a matched PoC repo

Why it matters now

Mention timeline

Total mentions
0
within the 30d window
Peak daily
0
highest bucket

Evidence

Source links by recency

Newest mentions first
16 source links · newest first
  • It’s a new year and while some things change, some things stay the same (or similar). There’s lots of FUD about the sophisticated cyber attacks that are multi-threaded and obfuscated. Certainly there are attacks that fall into this category, but if you look at all of the cybercrime activity from the past year, it’s clear that the majority of threats do not have the level of sophistication that is often talked about.

    newswww.securityweek.comJan 20, 2017, 4:16 PM
  • New Terror Exploit Kit EmergesSecurityWeek

    After the fall of the Nuclear and Angler exploit kits (EKs), overall activity generated from exploit kits has dropped to only a fraction of what used to be.

    newswww.securityweek.comJan 10, 2017, 4:59 PM
  • cPanel is one of the most popular web hosting control panels out there. It allows administrators to manage their website(s) using a…

    newswww.malwarebytes.comFeb 25, 2015, 5:00 PM
  • Update (07/29/2014): Following our notification, the developers in charge of SocialBlade.com have investigated and identified the source of the compromise. The…

    newswww.malwarebytes.comJul 28, 2014, 5:00 PM
  • A cunning way to deliver malwareMalwarebytes Labs

    Potentially unwanted programs, also known as PUPs, continue to be a real nuisance. A recent blog post by Will Dormann on CERT.org…

    newswww.malwarebytes.comJul 10, 2014, 5:00 PM
  • The popular online magazine AskMen has been compromised and abused to distribute a piece of malware, Websense reported on Monday.

    newswww.securityweek.comJun 24, 2014, 5:17 PM
  • Askmen.com, one of the most popular websites on the Internet (Top 1000 Alexa), is compromised to sever the banking trojan Caphaw. Security experts at Websense have discovered that cyber criminals have compromised the popular website AskMen.com and they used it to serve malware. The attackers deployed several exploits to compromise the visitors, and if successful, the victim […]

    newssecurityaffairs.comJun 24, 2014, 5:52 AM
  • Last week Microsoft has announced that today’s Patch Tuesday will include a fix for the critical IE zero-day vulnerability that was found exploited in watering hole attacks earlier this year – and none too soon, as a number of bad actors have been using the same exploit code in other similar attack since then. Initially, the exploit was used to compromise the visitors of a fake French aerospace association GIFAS site and the legitimate but … More →

    newswww.helpnetsecurity.comMar 11, 2014, 9:15 AM
  • Here’s an overview of some of last week’s most interesting news, interviews, articles and reviews: Which e-commerce sites do more to protect your password? A Dashlane roundup assesses the password policies of the top 100 e-commerce sites in the US by examining 24 different password criteria that they have identified as important to online security, and awarding or docking points depending upon whether a site meets a criterion or not. Knox: Mac file encryption and … More →

    newswww.helpnetsecurity.comFeb 3, 2014, 12:03 AM
  • Researchers from Kaspersky Lab have uncovered a new malware that has the ability to infect systems running Windows, Mac OS X, and Linux, with the goal of launching DDoS attacks.

    newswww.securityweek.comJan 29, 2014, 6:36 PM
  • Java-based malware hits Windows, Mac and LinuxHelp Net Security

    Kaspersky Lab researchers have recently analysed a piece of malware that works well on all three of the most popular computer operating systems – the only thing that it needs to compromise targeted computers is for them to run a flawed version of Java. The Trojan is written wholly in Java, and exploits an unspecified vulnerability (CVE-2013-2465) in the JRE component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, … More →

    newswww.helpnetsecurity.comJan 29, 2014, 5:02 AM
  • An Advanced Persistent Threat (APT) called NetTraveler has been spotted making mischief again, but it appears to have learned a few new tricks since it was last spotted in June. The malware is now attacking a known Java vulnerability, CVE-2013-2465, and added water holing to its propagation strategy, according to new research from Kaspersky Lab. […]

    newswww.csoonline.comSep 4, 2013, 3:00 PM
  • Experts at Kaspersky firm provided evidences that the hackers behind cyber espionage campaign NetTraveler are still active and improved their attack methods. Last June Kaspersky firm uncovered a new global cyber espionage campaign dubbed NetTraveler. Kaspersky’s team discovered that NetTraveler targeted over 350 high profile victims from 40 countries. The name of the operation derives from […]

    newssecurityaffairs.comSep 4, 2013, 6:51 AM
  • Researchers at Kaspersky Lab revealed that they have discovered a new attack vector for NetTraveler – an attack campaign that has infected hundreds of victims across more than 40 countries.

    newswww.securityweek.comSep 3, 2013, 2:53 PM
  • The “Red Star” APT group employing the NetTraveler malware family is still active, but has changed its modus operandi. Its targets remain the same: government institutions, embassies, the oil and gas industry, research centers, military contractors and activists. But, while earlier this year they mostly relied on spear phishing emails to deliver a booby-trapped attachment, now they try to lead users to a booby-trapped site or they inject certain websites with malicious JavaScript that will … More →

    newswww.helpnetsecurity.comSep 3, 2013, 7:57 AM
  • Cybercriminals were quick to integrate a newly released exploit for a Java vulnerability patched in June into a tool used to launch mass attacks against users, an independent malware researcher warned. The exploit targets a critical vulnerability identified as CVE-2013-2465 that affects all Java versions older than Java 7 Update 25 and can enable remote […]

    newswww.csoonline.comAug 16, 2013, 3:00 PM

Exploit code

Public exploit repository references

Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.

0 repository references · best confidence N/A · max 0 stars
No public PoC repositories have been matched yet.

Related records

Similar CVEs

6 related CVEs with shared weakness or product evidence