← Vulnerability feed

Vulnerability record · CVE-2013-2465 · published 18 June 2013

CVE-2013-2465: Oracle Java SE JRE 2D sandbox bypass and code execution

Oracle · Jre

CVE-2013-2465 is an unspecified vulnerability in the 2D component of Oracle Java SE JRE (7 Update 21 and earlier, 6 Update 45 and earlier, 5.0 Update 45 and earlier, and OpenJDK 7). Oracle's advisory gives no technical detail, but a third-party vendor claims it allows remote attackers to bypass the Java sandbox via incorrect image channel verification in 2D. Because it is remotely reachable without authentication and can affect confidentiality, integrity and availability, it is a serious client-side risk.

9.8 CVSS 3.1 Critical CISA KEV since 28 Mar 2022 Known ransomware use EPSS 99% · top 0.1% CWE-693 · CWE-693
9.8CVSS 3.1 base score, v2 10.0
99%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
6Affected product versions listed by NVD
65References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier, and OpenJDK 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D. NOTE: the previous information is from the June 2013 CPU. Oracle has not commented on claims from another vendor that this issue allows remote attackers to bypass the Java sandbox via vectors related to "Incorrect image channel verification" in 2D.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: medium.

critical priorityCVSS 9.8, CISA KEV listing with known ransomware use, and a 0.987 EPSS probability make this an actively exploited remote code execution flaw.

What it is

CVE-2013-2465 is an unspecified vulnerability in the 2D component of Oracle Java SE JRE (7 Update 21 and earlier, 6 Update 45 and earlier, 5.0 Update 45 and earlier, and OpenJDK 7). Oracle's advisory gives no technical detail, but a third-party vendor claims it allows remote attackers to bypass the Java sandbox via incorrect image channel verification in 2D. Because it is remotely reachable without authentication and can affect confidentiality, integrity and availability, it is a serious client-side risk.

Impact

An attacker can escape the Java sandbox and run code with the privileges of the JVM process, gaining full control of confidentiality, integrity and availability on the host. In practice this means arbitrary code execution on any machine that loads the malicious Java content.

Attack surface

Reached over the network (AV:N) with no privileges and no user interaction required per the CVSS vector, typically by delivering malicious Java content to a JRE. The description does not specify the exact delivery path, so the vector is inferred from the CVSS metrics rather than stated in the record.

Exploitation

CVE-2013-2465 is listed in CISA KEV (added 2022-03-28, due 2022-04-18) with known ransomware campaign use, and EPSS gives a 30-day probability of 0.987 (99.9th percentile). The record contains no exploit code or public PoC reference, but KEV and EPSS indicate active exploitation.

What to do

  • Apply the vendor updates referenced in the Oracle June 2013 CPU advisory and the OpenJDK patch; this is the only complete fix.
  • Upgrade to a supported Java release; Java 7 Update 21, 6 Update 45 and 5.0 Update 45 and earlier are affected.
  • If legacy Java cannot be removed, disable the Java browser plug-in and block execution of untrusted JAR/applet content.
  • Apply the Linux distribution errata (Red Hat, SUSE, Gentoo, Mandriva) for hosts running the bundled JRE.
  • Restrict outbound and inbound paths that deliver Java content to reduce exposure until patching completes.

Detection

  • Hunt for JRE versions at or below 7u21, 6u45 and 5.0u45 on endpoints and servers, including bundled JREs in third-party software.
  • Monitor for unexpected child processes spawned by java/javaw, especially browsers or office applications launching Java.
  • Alert on Java processes making outbound network connections or writing executables to user-writable directories.
  • Review proxy and IDS logs for delivery of JAR or applet content from untrusted or newly seen hosts.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2013-2465 to the Known Exploited Vulnerabilities catalog on 28 March 2022 as "Oracle Java SE Unspecified Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 18 April 2022.

Affected products

6 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://advisories.mageia.org/MGASA-2013-0185.html Broken Link
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c03898880 Broken Link
http://hg.openjdk.java.net/jdk7u/jdk7u-dev/jdk/rev/2a9c79db0040 Patch
http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00026.html Mailing ListThird Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00027.html Mailing ListThird Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00028.html Mailing ListThird Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00029.html Mailing ListThird Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00031.html Mailing ListThird Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2013-08/msg00000.html Mailing ListThird Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2013-08/msg00003.html Mailing ListThird Party Advisory
http://marc.info/?l=bugtraq&m=137545505800971&w=2 Mailing ListThird Party Advisory
http://marc.info/?l=bugtraq&m=137545592101387&w=2 Mailing ListThird Party Advisory
http://rhn.redhat.com/errata/RHSA-2013-0963.html Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2013-1059.html Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2013-1060.html Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2013-1081.html Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2013-1455.html Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2013-1456.html Third Party Advisory
http://secunia.com/advisories/54154 Not Applicable
http://security.gentoo.org/glsa/glsa-201406-32.xml Third Party Advisory
http://www-01.ibm.com/support/docview.wss?uid=swg21642336 Third Party Advisory
http://www.mandriva.com/security/advisories?name=MDVSA-2013:183 Not Applicable
http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html Vendor Advisory
http://www.securityfocus.com/bid/60657 Broken LinkThird Party AdvisoryVDB Entry
http://www.us-cert.gov/ncas/alerts/TA13-169A Third Party AdvisoryUS Government Resource
https://access.redhat.com/errata/RHSA-2014:0414 Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=975118 Issue Tracking
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A17106 Broken Link
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19074 Broken Link
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19455 Broken Link
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19703 Broken Link
http://advisories.mageia.org/MGASA-2013-0185.html Broken Link
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c03898880 Broken Link
http://hg.openjdk.java.net/jdk7u/jdk7u-dev/jdk/rev/2a9c79db0040 Patch
http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00026.html Mailing ListThird Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00027.html Mailing ListThird Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00028.html Mailing ListThird Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00029.html Mailing ListThird Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00031.html Mailing ListThird Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2013-08/msg00000.html Mailing ListThird Party Advisory

Track CVE-2013-2465 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2016-4171Adobe Flash Player unspecified remote code execution flawCVE-2016-4171 is an unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier that allows remote attackers to execute arbitrary code thr…KEVEPSS 20%analysed9.8CVE-2016-4117Adobe Flash Player unspecified vectors allow arbitrary code executionAdobe Flash Player 21.0.0.226 and earlier contains a critical flaw that lets remote attackers execute arbitrary code through unspecified vectors. Ado…KEVEPSS 94%analysed9.8CVE-2016-3427Oracle Java SE JMX Improper Access Control VulnerabilityCVE-2016-3427 is an unspecified vulnerability in Oracle Java SE 6u113, 7u99, 8u77, Java SE Embedded 8u77, and JRockit R28.3.9, reached through vector…KEVEPSS 92%analysed9.8CVE-2015-2590Oracle Java SE Libraries flaw allows remote code executionCVE-2015-2590 is an unspecified vulnerability in the Libraries component of Oracle Java SE 6u95, 7u80, 8u45 and Java SE Embedded 7u75, 8u33. The reco…KEVEPSS 25%analysed9.8CVE-2015-5123Adobe Flash Player ActionScript 3 BitmapData use-after-freeAdobe Flash Player contains a use-after-free in the ActionScript 3 BitmapData class, triggered by crafted Flash content that overrides a valueOf func…KEVEPSS 19%analysed9.8CVE-2015-5122Adobe Flash Player ActionScript 3 Use-After-Free in DisplayObjectA use-after-free flaw in the DisplayObject class of Adobe Flash Player's ActionScript 3 implementation is triggered by crafted Flash content that mis…KEVEPSS 94%analysed9.8CVE-2015-5119Adobe Flash Player ActionScript 3 ByteArray use-after-freeA use-after-free flaw exists in the ByteArray class of the ActionScript 3 implementation in Adobe Flash Player. Crafted Flash content that overrides …KEVEPSS 99%analysed9.8CVE-2015-3113Adobe Flash Player heap buffer overflow allows remote code executionAdobe Flash Player contains a heap-based buffer overflow (CWE-122/CWE-787) reachable through unspecified vectors. It affects Flash Player before 13.0…KEVEPSS 100%analysed

Source: NIST National Vulnerability Database (record CVE-2013-2465), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.