Heap-based Buffer Overflow in Oracle Java SE and JavaFX
CVE-2013-0402

Currently unrated

Key Information:

Vendor
Oracle
Status
Vendor
CVE Published:
8 March 2013

Summary

A vulnerability in the Java Runtime Environment (JRE) and JavaFX allows remote attackers to execute arbitrary code on targeted systems. This heap-based buffer overflow can be exploited through vectors associated with JavaFX, as illustrated during the Pwn2Own competition held at CanSecWest 2013. The flaw affects Oracle Java SE 7 Update 17 and earlier and JavaFX 2.2.7 and earlier versions, highlighting the need for prompt updates to mitigate potential security breaches.

References

EPSS Score

7% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.