VRT 391,192 CVEs tracked · 15,442 in RASP scope · data as of 16 hours ago
Reset
More filters (2)
Columns
Has a public PoCAdvisory: Java SE CPU Feb 2013
Overview 2 matches, all public PoC · 1 in RASP scope · 0 protected · 1 KEV · 1 CISA SSVC · 1 EPSS ≥ 0.5 · 0 disputed
2matches, all public PoC 1in RASP scope50.0% 0protected0.0% 1KEV50.0% 1CISA SSVC50.0% 1EPSS ≥ 0.550.0% 0disputed0.0%
Critical 0 0.0% High 0 0.0% Medium 1 50.0% Low 1 50.0% None 0 0.0% Unknown 0 0.0%
Protected by RASP 0 0.0% Rule in development 0 0.0% Mitigation candidate 1 50.0% No exploit published 0 0.0% No fix identified 0 0.0% Mitigated by environment configuration 0 0.0% Queued for review 0 0.0% Not applicable 0 0.0% Out of RASP scope 1 50.0% Rejected 0 0.0%
blocked by ARMR today 0 0.0% not blocked 2 100.0% not established 0 0.0% unrecorded 0 0.0%
Exploited in the wild 1 50.0% Working exploit published 0 0.0% Proof of concept only 0 0.0% Forecast only 0 0.0% No public exploit 1 50.0%
split by peak 1 / month
Unknown: 0None: 0Low: 1Medium: 1High: 0Critical: 0 Rejected: 0Out of RASP scope: 1Not applicable: 0Queued for review: 0Mitigated by environment configuration: 0No fix identified: 0No exploit published: 0Mitigation candidate: 1Rule in development: 0Protected by RASP: 0 unrecorded: 0not established: 0not blocked: 2blocked by ARMR today: 0 No public exploit: 1Forecast only: 0Proof of concept only: 0Working exploit published: 0Exploited in the wild: 1 January 2013: 1 CVE February 2013: 1 CVE
Jan 13Feb 13
2 matches CSV JSON
CVE Severity Published Status Exploitation Description
CVE-2013-0169 Low 2013-02-08 Out of RASP scope No public exploit The TLS protocol 1.1 and 1.2 and the DTLS protocol 1.0 and 1.2, as used in OpenSSL, OpenJDK, PolarSSL, and other products, do not properly consider timing side-channel attacks on a MAC check requirement during the processing of malformed CBC padding, which allows remote attackers to conduct distinguishing attacks and plaintext-recovery attacks via statistical analysis of timing data for crafted packets, aka the "Lucky Thirteen" issue.
CVE-2013-0431 Medium 2013-01-31 Mitigation candidate Exploited in the wild Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, and OpenJDK 7, allows user-assisted remote attackers to bypass the Java security sandbox via unspecified vectors related to JMX, aka "Issue 52," a different vulnerability than CVE-2013-1490.