Heap-based Buffer Overflow in Oracle Java SE and JavaFX
CVE-2013-0402
Currently unrated
Summary
A vulnerability in the Java Runtime Environment (JRE) and JavaFX allows remote attackers to execute arbitrary code on targeted systems. This heap-based buffer overflow can be exploited through vectors associated with JavaFX, as illustrated during the Pwn2Own competition held at CanSecWest 2013. The flaw affects Oracle Java SE 7 Update 17 and earlier and JavaFX 2.2.7 and earlier versions, highlighting the need for prompt updates to mitigate potential security breaches.
References
EPSS Score
7% chance of being exploited in the next 30 days.
Timeline
Vulnerability published
Vulnerability Reserved