← Vulnerability feed

Vulnerability record · CVE-2013-1493 · published 5 March 2013

CVE-2013-1493: Oracle Java 2D CMM raster parameter flaw allows remote code execution

Oracle · Jre

The color management (CMM) functionality in the 2D component of Oracle Java SE 7 Update 15 and earlier, 6 Update 41 and earlier, and 5.0 Update 40 and earlier mishandles crafted raster parameters in an image, triggering an out-of-bounds read or memory corruption in the JVM. This is a remotely reachable memory-safety flaw that was exploited in the wild in February 2013, so unpatched Java runtimes remain a serious risk.

10.0 CVSS 2.0 High EPSS 86% · top 0.3% CWE-119 · Memory buffer overflow
10.0CVSS 2.0 base score
86%EPSS exploitation probability, 30 days
NoNot in CISA KEV
4Affected product versions listed by NVD
62References
16 Jun 2026Last modified by NVD

Description

The color management (CMM) functionality in the 2D component in Oracle Java SE 7 Update 15 and earlier, 6 Update 41 and earlier, and 5.0 Update 40 and earlier allows remote attackers to execute arbitrary code or cause a denial of service (crash) via an image with crafted raster parameters, which triggers (1) an out-of-bounds read or (2) memory corruption in the JVM, as exploited in the wild in February 2013.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

critical priorityRemote, unauthenticated code execution in Java with in-the-wild exploitation, a public exploit and a CVSS 2.0 score of 10 warrants critical priority despite the absence of a KEV listing.

What it is

The color management (CMM) functionality in the 2D component of Oracle Java SE 7 Update 15 and earlier, 6 Update 41 and earlier, and 5.0 Update 40 and earlier mishandles crafted raster parameters in an image, triggering an out-of-bounds read or memory corruption in the JVM. This is a remotely reachable memory-safety flaw that was exploited in the wild in February 2013, so unpatched Java runtimes remain a serious risk.

Impact

An attacker can execute arbitrary code in the context of the JVM process or crash it, giving full compromise of the host running the vulnerable Java version. The CVSS 2.0 vector AV:N/AC:L/Au:N/C:C/I:C/A:C reflects complete confidentiality, integrity and availability impact with no authentication.

Attack surface

Reachable over the network with no authentication and no user interaction beyond loading the crafted image content, per the AV:N/AC:L/Au:N vector. In practice this is delivered through Java applets or other image-processing paths in the JVM.

Exploitation

Exploited in the wild in February 2013 according to the description, and a public Exploit-DB entry (24904) exists; the record is not listed in CISA KEV, while EPSS is very high at 0.86151 (99.72nd percentile).

What to do

  • Patch Java to a version after 7 Update 15, 6 Update 41 or 5.0 Update 40, or apply the vendor advisories (Oracle alert, Red Hat RHSA, Ubuntu USN, openSUSE, Gentoo, Mandriva) for the affected distribution.
  • Remove or disable the Java browser plug-in and block applet execution where Java is not required.
  • Restrict outbound and inbound access to Java-dependent services and enforce least privilege on any host still running a vulnerable JRE/JDK.
  • Where legacy Java must remain, isolate it in a low-privilege sandbox or dedicated host and monitor for JVM crashes or unexpected child processes.

Detection

  • Hunt for JVM crash events or hs_err logs referencing the 2D/CMM code paths or out-of-bounds reads.
  • Monitor for Java processes spawning unexpected child processes such as cmd.exe, powershell.exe or /bin/sh.
  • Inspect proxy and email logs for image files delivered to Java applet or image-processing endpoints, and alert on applet loads from untrusted origins.
  • Track hosts still reporting Java 7 Update 15, 6 Update 41, 5.0 Update 40 or earlier via software inventory.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://blog.fireeye.com/research/2013/02/yaj0-yet-another-java-zero-day-2.html
http://h20565.www2.hp.com/hpsc/doc/public/display?docId=emr_na-c04117626-1
http://lists.opensuse.org/opensuse-security-announce/2013-03/msg00009.html
http://lists.opensuse.org/opensuse-security-announce/2013-03/msg00011.html
http://lists.opensuse.org/opensuse-security-announce/2013-03/msg00012.html
http://lists.opensuse.org/opensuse-security-announce/2013-04/msg00020.html
http://mail.openjdk.java.net/pipermail/distro-pkg-dev/2013-March/022145.html
http://marc.info/?l=bugtraq&m=136439120408139&w=2
http://marc.info/?l=bugtraq&m=136570436423916&w=2
http://rhn.redhat.com/errata/RHSA-2013-0601.html
http://rhn.redhat.com/errata/RHSA-2013-0603.html
http://rhn.redhat.com/errata/RHSA-2013-0604.html
http://rhn.redhat.com/errata/RHSA-2013-1455.html
http://rhn.redhat.com/errata/RHSA-2013-1456.html
http://security.gentoo.org/glsa/glsa-201406-32.xml
http://www.exploit-db.com/exploits/24904
http://www.kb.cert.org/vuls/id/688246 US Government Resource
http://www.mandriva.com/security/advisories?name=MDVSA-2013:095
http://www.oracle.com/ocom/groups/public/%40otn/documents/webcontent/1915099.xml
http://www.oracle.com/technetwork/topics/security/alert-cve-2013-1493-1915081.html
http://www.securityfocus.com/bid/58238
http://www.securitytracker.com/id/1029803
http://www.symantec.com/connect/blogs/latest-java-zero-day-shares-connections-bit9-security-incident
http://www.ubuntu.com/usn/USN-1755-2
http://www.us-cert.gov/ncas/alerts/TA13-064A US Government Resource
https://bugzilla.redhat.com/show_bug.cgi?id=917553
https://krebsonsecurity.com/2013/03/new-java-0-day-attack-echoes-bit9-breach/
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19246
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19477
https://twitter.com/jduck1337/status/307629902574800897
https://wiki.mageia.org/en/Support/Advisories/MGASA-2013-0088
http://blog.fireeye.com/research/2013/02/yaj0-yet-another-java-zero-day-2.html
http://h20565.www2.hp.com/hpsc/doc/public/display?docId=emr_na-c04117626-1
http://lists.opensuse.org/opensuse-security-announce/2013-03/msg00009.html
http://lists.opensuse.org/opensuse-security-announce/2013-03/msg00011.html
http://lists.opensuse.org/opensuse-security-announce/2013-03/msg00012.html
http://lists.opensuse.org/opensuse-security-announce/2013-04/msg00020.html
http://mail.openjdk.java.net/pipermail/distro-pkg-dev/2013-March/022145.html
http://marc.info/?l=bugtraq&m=136439120408139&w=2
http://marc.info/?l=bugtraq&m=136570436423916&w=2

Track CVE-2013-1493 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2016-3427Oracle Java SE JMX Improper Access Control VulnerabilityCVE-2016-3427 is an unspecified vulnerability in Oracle Java SE 6u113, 7u99, 8u77, Java SE Embedded 8u77, and JRockit R28.3.9, reached through vector…KEVEPSS 92%analysed9.8CVE-2015-2590Oracle Java SE Libraries flaw allows remote code executionCVE-2015-2590 is an unspecified vulnerability in the Libraries component of Oracle Java SE 6u95, 7u80, 8u45 and Java SE Embedded 7u75, 8u33. The reco…KEVEPSS 25%analysed9.8CVE-2013-2465Oracle Java SE JRE 2D sandbox bypass and code executionCVE-2013-2465 is an unspecified vulnerability in the 2D component of Oracle Java SE JRE (7 Update 21 and earlier, 6 Update 45 and earlier, 5.0 Update…KEVEPSS 99%analysed9.8CVE-2013-0422Oracle Java 7 JMX/MBean and Reflection API sandbox bypass RCEOracle Java 7 before Update 11 contains two flaws: the public getMBeanInstantiator method in JmxMBeanServer exposes a private MBeanInstantiator that …KEVEPSS 97%analysed9.8CVE-2012-5076Oracle Java SE JRE JAX-WS sandbox bypassCVE-2012-5076 is an unspecified vulnerability in the Java Runtime Environment (JRE) component of Oracle Java SE 7 Update 7 and earlier, related to JA…KEVEPSS 91%analysed9.8CVE-2012-4681Oracle Java SE 7 JRE SecurityManager bypass allows remote code executionThe Java Runtime Environment in Oracle Java SE 7 Update 6 and earlier fails to properly enforce SecurityManager restrictions. A crafted applet can us…KEVEPSS 99%analysed9.8CVE-2012-1723Oracle Java SE Hotspot Improper Access Control Enables Remote Code ExecutionCVE-2012-1723 is an unspecified vulnerability in the Hotspot component of Oracle Java SE (JRE) affecting Java SE 7 update 4 and earlier, 6 update 32 …KEVEPSS 94%analysed9.8CVE-2012-0507Oracle Java SE JRE AtomicReferenceArray type confusion sandbox bypassCVE-2012-0507 is an unspecified vulnerability in the Java Runtime Environment (JRE) Concurrency component affecting Java SE 7 Update 2 and earlier, 6…KEVEPSS 98%analysed

Source: NIST National Vulnerability Database (record CVE-2013-1493), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.