Skip to main content

CVE-2013-2423

3.7
LOWCVSS v3.1 Base Score
93.40%
HIGH RiskEPSS (100th percentile)
KEV
NVD-CWE-noinfo

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, and OpenJDK 7, allows remote attackers to affect integrity via unknown vectors related to HotSpot. NOTE: the previous information is from the April 2013 CPU. Oracle has not commented on claims from the original researcher that this vulnerability allows remote attackers to bypass permission checks by the MethodHandles method and modify arbitrary public final fields using reflection and type confusion, as demonstrated using integer and double fields to disable the security manager.

Published: 4/17/2013
Modified: 4/22/2026
Back to CVE Lookup

ACTIVELY EXPLOITED IN THE WILD

This vulnerability is listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.

Vulnerability Name:

Oracle JRE Unspecified Vulnerability

Vendor / Product:

Oracle Java Runtime Environment (JRE)

Required Action:

Apply updates per vendor instructions.

Due Date: 6/15/2022(OVERDUE)
Added to KEV:

5/25/2022

Notes:

https://nvd.nist.gov/vuln/detail/CVE-2013-2423

Vulnerability Summary

CVSS v3 Score

3.7LOW

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N

CVSS v2 Score

4.3

AV:N/AC:M/Au:N/C:N/I:P/A:N

EPSS Score (Exploitation Probability)

93.40%HIGH Exploitation Risk
100th percentile

This vulnerability has a 93.40% probability of being exploited in the next 30 days, ranking higher than 100% of all scored CVEs.

CWE Classification

NVD-CWE-noinfo

Related Vulnerabilities

Similar SeverityLOW

CVE-2026-8221LOW 2.4

A flaw has been found in Devs Palace ERP Online up to 4.0.0. This impacts an unknown function of the file /inventory/item-save. This manipulation causes cross site scripting. The attack is possible to be carried out remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

5/10/2026
CVE-2026-6216LOW 3.5

A security vulnerability has been detected in DbGate up to 7.1.4. This affects an unknown function of the file packages/web/src/icons/FontIcon.svelte of the component SVG Icon String Handler. Such manipulation of the argument applicationIcon leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed publicly and may be used. Upgrading to version 7.1.5 mitigates this issue. It is advisable to upgrade the affected component.

4/13/2026
CVE-2026-6192LOW 3.3

A vulnerability was identified in uclouvain openjpeg up to 2.5.4. This impacts the function opj_pi_initialise_encode in the library src/lib/openjp2/pi.c. The manipulation leads to integer overflow. The attack must be carried out locally. The exploit is publicly available and might be used. The identifier of the patch is 839936aa33eb8899bbbd80fda02796bb65068951. It is suggested to install a patch to address this issue.

4/13/2026
CVE-2026-36950LOW 2.7

Sourcecodester Online Thesis Archiving System v1.0 is vulnerable to SQL injection in /otas/projects_per_department.php.

4/13/2026
CVE-2026-24515LOW 2.9

In libexpat before 2.7.4, XML_ExternalEntityParserCreate does not copy unknown encoding handler user data.

1/23/2026