CISA KEV · catalog date Mar 28, 2022 · first observed Jul 19, 2026
Evidence dossier
CVE-2013-2465
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier, and…
Exploited in the wild (CISA KEV since Mar 28, 2022). NVD reports CVSS 2.0 10.0. EPSS estimates 98.7% exploit likelihood as of Jul 26, 2026.
As of Aug 27, 2026
Normalized restatement
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier, and OpenJDK 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D. NOTE: the previous information is from the June 2013 CPU. Oracle has not commented on claims from another vendor that this issue allows remote attackers to bypass the Java sandbox via vectors related to "Incorrect image channel verification" in 2D.
- State
- PUBLISHED
- Published
- Jun 18, 2013
- Updated
- Oct 22, 2025
- Evidence coverage
- 99%
Evidence chronology
What was known when
- Source dateSource date omittedFirst observed by CASCACISA-ADPOriginal evidence ↗
Record text: CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
- Source dateSource date omittedFirst observed by CASCACVE ProgramOriginal evidence ↗
Record text: CVE Program Container
Inspect raw assertion
- Field
container- Value
- CVE Program Container
- Source dateSource date omittedFirst observed by CASCAoracleOriginal evidence ↗
Record text: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier, and OpenJDK 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D. NOTE: the previous information is from the June 2013 CPU. Oracle has not commented on claims from another vendor that this issue allows remote attackers to bypass the Java sandbox via vectors related to "Incorrect image channel verification" in 2D.
Inspect raw assertion
- Field
container- Value
- Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier, and OpenJDK 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D. NOTE: the previous information is from the June 2013 CPU. Oracle has not commented on claims from another vendor that this issue allows remote attackers to bypass the Java sandbox via vectors related to "Incorrect image channel verification" in 2D.
- Source dateFirst observed by CASCACISA KEVOriginal evidence ↗
Exploitation cataloged: Oracle Java SE Unspecified Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- Oracle Java SE Unspecified Vulnerability
- Source dateFirst observed by CASCAFIRST EPSSOriginal evidence ↗
EPSS score: 98.7% probability · 99.92th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.987040000000; percentile 0.999210000000
FIRST EPSS · score date Jul 26, 2026 · 99.9th percentile · first observed Jul 27, 2026
NVD · CVSS 2.0 · first observed Jul 19, 2026 · same-version scores align in this snapshot
Evidence detail
Source limits and decisions
Why each evidence state has this value
Outside this view’s verified evidenceReason detail begins outside this selected snapshot; the state remains source-bound.
Source comparison
Who said what
CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
CVE Program Container
Inspect raw assertion
- Field
container- Value
- CVE Program Container
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier, and OpenJDK 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D. NOTE: the previous information is from the June 2013 CPU. Oracle has not commented on claims from another vendor that this issue allows remote attackers to bypass the Java sandbox via vectors related to "Incorrect image channel verification" in 2D.
Inspect raw assertion
- Field
container- Value
- Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier, and OpenJDK 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D. NOTE: the previous information is from the June 2013 CPU. Oracle has not commented on claims from another vendor that this issue allows remote attackers to bypass the Java sandbox via vectors related to "Incorrect image channel verification" in 2D.
Oracle Java SE Unspecified Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- Oracle Java SE Unspecified Vulnerability
98.7% probability · 99.92th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.987040000000; percentile 0.999210000000
Applicability
Cited product scope
Grouped from 4 configuration nodes in this exact snapshot. Visual grouping is navigational; asset exposure and root cause require cited evidence.
Identity source boundaries
- Cpe dictionary1,775,266 records · observed through 2026-07-21T06:45:29.809Z
27d65b0f-b718-4b4f-bb79-c47c68d09dfa - Cpe match643,502 records · observed through 2026-07-21T08:13:17.697Z
955dae73-7302-438b-aee1-058d7cc5d48e
7 scope groups
Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "n/a"}]product-70c0761d49c3bbe44615490ef7b613557bcd3ccdfa71d09d74202c114d277fb7Linked exactInspect raw assertions
cpe:2.3:a:oracle:jre:1.7.0:update9:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 14
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
4ffc7f0d-1f32-4235-8359-277ce41382df
cpe:2.3:a:oracle:jre:1.6.0:update31:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 9
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
23cda4f0-c32b-4b08-a377-7d4426c2f569
cpe:2.3:a:oracle:jre:1.7.0:update13:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 4
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
f3c3c9c7-73ae-4b1d-aa85-c7f5330a4de6
cpe:2.3:a:oracle:jre:1.5.0:update38:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 2
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
b4a2d725-a7dc-4802-a377-5c3963ad9941
cpe:2.3:a:oracle:jre:1.7.0:update2:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 7
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
cb106fa9-26ce-48c5-aea5-fd1a5454aee2
cpe:2.3:a:oracle:jre:1.6.0:update22:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 1
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
ef13b96d-1f80-4672-8da3-f86f6d3bf070
cpe:2.3:a:oracle:jre:1.5.0:update40:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 4
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
a3c6e1d8-b96e-40fb-9e66-9b3a5325e78b
cpe:2.3:a:oracle:jre:1.6.0:update35:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 13
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
ff56e0d9-612d-4215-9c76-560ae0661a05
cpe:2.3:a:oracle:jre:1.7.0:update3:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 9
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
5831d70b-3854-4cb8-b88d-40f1743daee0
cpe:2.3:a:oracle:jre:1.6.0:update27:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 6
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
f0b82fb1-0f0e-44f9-87ae-628517279e4d
cpe:2.3:a:oracle:jre:1.6.0:update32:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 10
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
8e76476e-4120-46a9-90a8-a95fe89636cd
cpe:2.3:a:oracle:jre:1.6.0:-:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
eb864346-1429-46b5-a91e-a1126c486421
cpe:2.3:a:oracle:jre:1.5.0:update45:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 6
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
a13547ea-ef77-493a-a863-f09e2aee8bd4
cpe:2.3:a:oracle:jre:1.7.0:update17:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 6
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
37b5b98b-0e41-4397-8ab0-c18c6f10aed1
cpe:2.3:a:oracle:jre:1.7.0:update15:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 5
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
1d8bb8d7-d5ec-42d6-beaa-cb03d1d6513e
cpe:2.3:a:oracle:jre:1.5.0:update39:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 3
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
a47e0a76-d6a3-445e-84c8-038497655bbc
cpe:2.3:a:oracle:jre:1.6.0:update43:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 18
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
8b276b96-66be-4c09-be9f-11fa7461cbdf
cpe:2.3:a:oracle:jre:1.6.0:update37:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 14
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
ba717604-4bb0-4968-b258-7c9f884016ff
cpe:2.3:a:oracle:jre:1.6.0:update29:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 7
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
a0a67640-2f4a-488a-9d8f-3fe1f4da8def
cpe:2.3:a:oracle:jre:1.6.0:update23:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 2
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
d1a2d440-d966-41a6-955d-38b28dde0fdb
cpe:2.3:a:oracle:jre:1.7.0:update4:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 10
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
eeb101c9-ca38-4421-bc0c-c1ad47aa2cc9
cpe:2.3:a:oracle:jre:1.5.0:-:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
d8730889-a618-4cf9-888c-bf95802dd00f
cpe:2.3:a:oracle:jre:1.6.0:update41:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 17
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
5c91517e-4c81-4d09-9fcb-b7ac769c7107
cpe:2.3:a:oracle:jre:1.6.0:update38:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 15
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
aa71fcf4-580f-432d-aadc-65a2a92cebc8
cpe:2.3:a:oracle:jre:1.6.0:update26:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 5
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
daf7d86b-1b4d-4e1f-9ef0-da7e419d7e99
cpe:2.3:a:oracle:jre:1.6.0:update45:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 19
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
626e11ca-20ee-4ab0-84d7-8dae7a9d8960
cpe:2.3:a:oracle:jre:1.6.0:update30:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 8
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
0d60d98d-4363-44a0-aab4-b61ba623ee21
cpe:2.3:a:oracle:jre:1.5.0:update36:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 1
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
cc062ae6-515b-4d40-9b86-46f7a1d7ff1c
cpe:2.3:a:oracle:jre:1.7.0:update6:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 12
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
f9a8ebcb-5e6a-42f0-8d07-f3a3d1c850f0
cpe:2.3:a:oracle:jre:1.7.0:update11:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 3
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
b2b20041-eb5d-4fa4-ac7d-c35e7878bcfd
cpe:2.3:a:oracle:jre:1.5.0:update41:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 5
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
f08a5aad-84ca-491f-83d3-ceffd16212e0
cpe:2.3:a:oracle:jre:1.7.0:update1:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 1
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
f4b153fd-e20b-4909-8b10-884e48f5b590
cpe:2.3:a:oracle:jre:1.7.0:update5:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 11
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
ba302df3-abbb-4262-b206-4c0f7b5b1e91
cpe:2.3:a:oracle:jre:1.6.0:update34:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 12
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
738ec3e5-a4eb-47fe-9c9a-7c8e8c669765
cpe:2.3:a:oracle:jre:1.7.0:update21:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 8
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
4ff6c211-ad55-40fe-9130-77164e586f62
cpe:2.3:a:oracle:jre:1.7.0:update7:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 13
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
0cd8a54e-185b-4d34-82ef-c0c05739ec12
cpe:2.3:a:oracle:jre:1.7.0:update10:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 2
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
f21933fb-a27c-4af3-9811-2de28484a5a6
cpe:2.3:a:oracle:jre:1.7.0:-:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
dfaa351a-93cd-46a8-a480-ce2783ccd620
cpe:2.3:a:oracle:jre:1.6.0:update25:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 4
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
cd7c4194-d34a-418f-9b00-5c6012844aae
cpe:2.3:a:oracle:jre:1.6.0:update24:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 3
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
b1c57774-ad93-4162-8e45-92b09139c808
cpe:2.3:a:oracle:jre:1.6.0:update39:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 16
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
f1e1a8f3-5a63-401e-9bda-acca30ff6ac8
cpe:2.3:a:oracle:jre:1.6.0:update33:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 11
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
97a84689-0ced-404f-8dc3-708beb37d2ce
product-e24bd6c1d86d6df9c425d9bad331eddd1e2be5933a99d4054300f066e687940cLinked exactInspect raw assertions
cpe:2.3:a:sun:jre:1.6.0:update_7:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 37
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
272a5c44-18ec-41a9-8233-e9d4d0734ea6
cpe:2.3:a:sun:jre:1.5.0:update18:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 16
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
b83b2ce1-45d7-47ad-bc0a-6ec74d5f8f5a
cpe:2.3:a:sun:jre:1.6.0:update_1:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 20
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
09027c19-d442-446f-b7a8-21db6787cf43
cpe:2.3:a:sun:jre:1.5.0:update12:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 10
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
02565d6f-4cb2-4671-a4ef-3169bcfa6154
cpe:2.3:a:sun:jre:1.5.0:update21:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 20
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
b0e0373b-201d-408f-9234-a7efe8b4970d
cpe:2.3:a:sun:jre:1.5.0:update24:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 23
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
7e0a0a2d-62b9-4a00-84ef-90c15e47a632
cpe:2.3:a:sun:jre:1.5.0:update6:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 34
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
724c972f-74fe-4044-bbc4-7e0e61fc9002
cpe:2.3:a:sun:jre:1.6.0:update_14:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 25
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
12a3b254-8580-45db-bde4-5b5a29cbffb3
cpe:2.3:a:sun:jre:1.6.0:update_19:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 30
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
be409d5c-8f9f-4de9-acb7-0e0b813f6399
cpe:2.3:a:sun:jre:1.6.0:update_18:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 29
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
c4fde9eb-08fe-436e-a265-30e83b15db23
cpe:2.3:a:sun:jre:1.6.0:update_16:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 27
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
aadbb4f9-e43e-428b-9979-f47a15696c85
cpe:2.3:a:sun:jre:1.5.0:update15:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 13
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
55231b6b-9298-4363-9b5a-14c2da7b1f50
cpe:2.3:a:sun:jre:1.6.0:update_6:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 36
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
30dfc10a-a4d9-4f89-b17c-ab9260087d29
cpe:2.3:a:sun:jre:1.5.0:update28:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 27
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
b7fc11be-8cf7-4d45-bb4a-3efa1ddbb10d
cpe:2.3:a:sun:jre:1.5.0:update13:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 11
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
452a3e51-9eac-451d-ba04-a1e7b7d917eb
cpe:2.3:a:sun:jre:1.6.0:update_9:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 38
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
81c2c04d-d4ba-4c87-9609-c53aa63bff19
cpe:2.3:a:sun:jre:1.6.0:update_13:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 24
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
2dbb6b73-8d6b-41ff-bee0-e0c7f5f1eb41
cpe:2.3:a:sun:jre:1.5.0:update17:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 15
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
a5467e9d-07d8-4beb-84d5-a3136c133519
cpe:2.3:a:sun:jre:1.6.0:update_15:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 26
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
1db1de6a-66ae-499b-ad92-9e6ace474c6d
cpe:2.3:a:sun:jre:1.6.0:update_4:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 34
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
2528152c-e20a-4d97-931c-a5ec3ceaa06d
cpe:2.3:a:sun:jre:1.5.0:update8:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 36
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
ebe909de-e55a-4bd3-a5bf-ade407432193
cpe:2.3:a:sun:jre:1.5.0:update29:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 28
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
1d75c40d-62ae-47f2-a6e0-53f3495260bd
cpe:2.3:a:sun:jre:1.5.0:update11:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 9
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
9919d091-73d7-465a-80ff-f37d6caf9f46
cpe:2.3:a:sun:jre:1.5.0:update20:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 19
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
04344167-530e-4a4d-90ef-74c684943df1
cpe:2.3:a:sun:jre:1.5.0:update1:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 7
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
a7fc09e8-7f30-4fe4-912e-588aa250e2a3
cpe:2.3:a:sun:jre:1.5.0:update5:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 33
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
b863420b-de16-416a-9640-1a1340a9b855
cpe:2.3:a:sun:jre:1.5.0:update3:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 29
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
44051cfe-d15d-4416-a123-f3e49c67a9e7
cpe:2.3:a:sun:jre:1.5.0:update27:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 26
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
044baddd-a80b-4ae2-8595-5f8186314550
cpe:2.3:a:sun:jre:1.6.0:update_20:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 31
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
b08c075b-9fc0-4381-a9e4-fff0362bd308
cpe:2.3:a:sun:jre:1.6.0:update_17:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 28
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
49260b94-05de-4b78-9068-6f5f6bfdd19e
cpe:2.3:a:sun:jre:1.5.0:update10:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 8
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
a586de4e-8a46-41de-9fdb-5fdb81dcc87b
cpe:2.3:a:sun:jre:1.5.0:update33:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 31
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
0e8009bc-f5a8-4d00-9f5f-8635475c6065
cpe:2.3:a:sun:jre:1.5.0:update22:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 21
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
15ead76d-d5d0-4984-9d07-c1451d791083
cpe:2.3:a:sun:jre:1.5.0:update26:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 25
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
3ecae71b-c549-4efb-a509-bfd599f5917a
cpe:2.3:a:sun:jre:1.5.0:update31:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 30
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
4c061911-fb19-45eb-8e88-7450224f4023
cpe:2.3:a:sun:jre:1.5.0:update16:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 14
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
e42cf0f7-418c-4bb6-9b73-fa3b9171d092
cpe:2.3:a:sun:jre:1.5.0:update23:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 22
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
de949ebf-2bc0-4355-8b28-b494023d45fe
cpe:2.3:a:sun:jre:1.6.0:update_5:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 35
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
a99dab4c-272b-4c91-bc70-7729e1152590
cpe:2.3:a:sun:jre:1.6.0:update_12:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 23
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
0c71089a-bdde-41fc-9df9-9aef4c2374df
cpe:2.3:a:sun:jre:1.6.0:update_10:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 21
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
0a0fec28-0707-4f42-9740-78f3d2d551ee
cpe:2.3:a:sun:jre:1.5.0:update14:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 12
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
3e8c6aac-c90b-4220-a69b-2a886a35cf5d
cpe:2.3:a:sun:jre:1.5.0:update9:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 37
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
5dac04d2-68fd-4793-a8e7-4690a543d7d4
cpe:2.3:a:sun:jre:1.5.0:update2:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 18
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
7ea5b9e9-654d-44f7-ae98-3d8b382804ac
cpe:2.3:a:sun:jre:1.6.0:update_3:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 33
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
90ec6c13-4b37-48e5-8199-a702a944d5a6
cpe:2.3:a:sun:jre:1.6.0:update_21:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 32
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
f587e635-3a15-4186-b6a1-f99be0a56820
cpe:2.3:a:sun:jre:1.5.0:update25:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 24
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
a070a282-cbd6-4041-b149-5e310bd12e7b
cpe:2.3:a:sun:jre:1.5.0:update7:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 35
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
46f41c15-0ef4-4115-bfaa-eead56faeedb
cpe:2.3:a:sun:jre:1.5.0:update19:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 17
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
8a32f326-ea92-43cd-930e-e527b60cdd3b
cpe:2.3:a:sun:jre:1.6.0:update_11:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 22
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
c3c5879a-a608-4230-9dc1-c27f0f48a13b
cpe:2.3:a:sun:jre:1.5.0:update4:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 32
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
f296acf3-1373-429d-b991-8b5ba704a7ef
product-908c58b965f5cdd7f6621821fd6c68d62c5a5ce89de01a9e91af7286e0b17d41Linked exactInspect raw assertion
cpe:2.3:o:suse:linux_enterprise_desktop:10:sp4:*:*:-:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 3 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
4339de06-19fb-4b8e-b6ae-3495f605ad05
product-4bed2322ee2f3c6046cc5e2544c025ebca9d0b203d3e86bbe13a28ee7ba092f8Linked exactInspect raw assertions
cpe:2.3:o:suse:linux_enterprise_java:10:sp4:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 3 · node/0 · match 1
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
3cf5c5b9-2cb9-4cd8-b94f-a674ed909cc3
cpe:2.3:o:suse:linux_enterprise_java:11:sp2:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 3 · node/0 · match 2
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
252cf7a7-3feb-4503-aee8-b67139c5b0d5
cpe:2.3:o:suse:linux_enterprise_java:11:sp3:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 3 · node/0 · match 3
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
79d7dbba-6849-45f7-afef-c765569c481a
product-4f2240e45c4385f8980643ce838561b90551012dc317022ee66a7d71a9db8e28Linked exactInspect raw assertions
cpe:2.3:o:suse:linux_enterprise_server:10:sp3:*:*:ltss:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 3 · node/0 · match 4
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
ced02712-1031-4206-ac4d-e68710f46ec9
cpe:2.3:o:suse:linux_enterprise_server:11:sp3:*:*:*:-:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 3 · node/0 · match 8
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
e534c201-bcc5-473c-aaa7-aab97ceb5437
cpe:2.3:o:suse:linux_enterprise_server:11:sp3:*:*:*:vmware:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 3 · node/0 · match 9
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
2470c6e8-2024-4cf5-9982-cff50e88eae9
cpe:2.3:o:suse:linux_enterprise_server:10:sp4:*:*:-:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 3 · node/0 · match 5
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
d1d7b467-58dd-45f1-9f1f-632620df072a
cpe:2.3:o:suse:linux_enterprise_server:11:sp2:*:*:*:vmware:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 3 · node/0 · match 7
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
db4d6749-81a1-41d7-bf4f-1c45a7f49a22
cpe:2.3:o:suse:linux_enterprise_server:11:sp2:*:*:*:-:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 3 · node/0 · match 6
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
88d6e858-fd8f-4c55-b7d5-ceeda2bba898
product-bd4950335ff1f3f03b9dd6fa5c596f7c67c9ea6d150272de074ec3767af3532aLinked exactInspect raw assertions
cpe:2.3:o:suse:linux_enterprise_software_development_kit:11:sp3:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 3 · node/0 · match 11
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
2f7f8866-dead-44d1-ab10-21ee611aa026
cpe:2.3:o:suse:linux_enterprise_software_development_kit:11:sp2:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 3 · node/0 · match 10
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
5aa37837-3083-4dc7-94f4-54fd5d7cb53c
Affected-product evidence
Accepted scope and product mapping
0 canonical links · 0 source-reported links
Applicability remains source-scoped; safety and exposure remain unassessed.
Assessments
CVSS by origin
AV:N/AC:L/Au:N/C:C/I:C/A:CCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HEvidence boundaries
- KEV membership is authoritative for the catalog, not proof of exposure in any environment.
- EPSS is a dated model probability and not an individual-environment prediction.
- Affected or fixed status applies only to the exact cited product and version scope; remaining scope stays source-scoped.
- NVD-carried upstream facts remain derivative; independent corroboration requires a separately authored source.
- Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
- NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
- Affected-product evidence remains source-scoped; canonical linkage is required before applicability scoring.
- Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.
- OSV aggregation and OSV-converted NVD material are not independent corroboration.
- Red Hat facts are vendor assertions for the exact supplied products.
- Nonmembership and not-yet-observed states are not proof of safety.