Vulnerability Details CVE-2013-4578
jarsigner in OpenJDK and Oracle Java SE before 7u51 allows remote attackers to bypass a code-signing protection mechanism and inject unsigned bytecode into a signed JAR file by leveraging improper file validation.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.009
EPSS Ranking 74.9%
CVSS Severity
CVSS v3 Score 5.3
CVSS v2 Score 5.0
Products affected by CVE-2013-4578
-
cpe:2.3:a:oracle:jdk:1.4.2_37
-
cpe:2.3:a:oracle:jdk:1.4.2_38
-
cpe:2.3:a:oracle:jdk:1.4.2_40
-
cpe:2.3:a:oracle:jdk:1.5.0
-
-
cpe:2.3:a:oracle:jdk:1.6.0
-
-
cpe:2.3:a:oracle:jdk:1.7.0
-
-
cpe:2.3:a:oracle:jre:1.1.6_009
-
cpe:2.3:a:oracle:jre:1.1.7b_007
-
cpe:2.3:a:oracle:jre:1.1.8_005
-
cpe:2.3:a:oracle:jre:1.1.8_006
-
cpe:2.3:a:oracle:jre:1.1.8_007
-
cpe:2.3:a:oracle:jre:1.1.8_008
-
cpe:2.3:a:oracle:jre:1.1.8_009
-
cpe:2.3:a:oracle:jre:1.1.8_010
-
cpe:2.3:a:oracle:jre:1.1.8_015
-
cpe:2.3:a:oracle:jre:1.1.8_16
-
cpe:2.3:a:oracle:jre:1.4.0
-
cpe:2.3:a:oracle:jre:1.4.0_01
-
cpe:2.3:a:oracle:jre:1.4.0_02
-
cpe:2.3:a:oracle:jre:1.4.0_03
-
cpe:2.3:a:oracle:jre:1.4.0_04
-
cpe:2.3:a:oracle:jre:1.4.1
-
cpe:2.3:a:oracle:jre:1.4.1_02
-
cpe:2.3:a:oracle:jre:1.4.1_03
-
cpe:2.3:a:oracle:jre:1.4.1_04
-
cpe:2.3:a:oracle:jre:1.4.1_05
-
cpe:2.3:a:oracle:jre:1.4.1_06
-
cpe:2.3:a:oracle:jre:1.4.1_07
-
cpe:2.3:a:oracle:jre:1.4.2
-
cpe:2.3:a:oracle:jre:1.4.2_01
-
cpe:2.3:a:oracle:jre:1.4.2_02
-
cpe:2.3:a:oracle:jre:1.4.2_03
-
cpe:2.3:a:oracle:jre:1.4.2_04
-
cpe:2.3:a:oracle:jre:1.4.2_05
-
cpe:2.3:a:oracle:jre:1.4.2_06
-
cpe:2.3:a:oracle:jre:1.4.2_07
-
cpe:2.3:a:oracle:jre:1.4.2_08
-
cpe:2.3:a:oracle:jre:1.4.2_09
-
cpe:2.3:a:oracle:jre:1.4.2_10
-
cpe:2.3:a:oracle:jre:1.4.2_11
-
cpe:2.3:a:oracle:jre:1.4.2_12
-
cpe:2.3:a:oracle:jre:1.4.2_13
-
cpe:2.3:a:oracle:jre:1.4.2_14
-
cpe:2.3:a:oracle:jre:1.4.2_15
-
cpe:2.3:a:oracle:jre:1.4.2_16
-
cpe:2.3:a:oracle:jre:1.4.2_17
-
cpe:2.3:a:oracle:jre:1.4.2_18
-
cpe:2.3:a:oracle:jre:1.4.2_19
-
cpe:2.3:a:oracle:jre:1.4.2_25
-
cpe:2.3:a:oracle:jre:1.4.2_37
-
cpe:2.3:a:oracle:jre:1.4.2_38
-
cpe:2.3:a:oracle:jre:1.4.2_40
-
cpe:2.3:a:oracle:jre:1.5.0
-
-
cpe:2.3:a:oracle:jre:1.6.0
-
-
cpe:2.3:a:oracle:jre:1.7.0