CVE-2013-5824

Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, and Java SE Embedded 7u40 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment, a different vulnerability than CVE-2013-5787, CVE-2013-5789, CVE-2013-5832, and CVE-2013-5852.

Published: 2013-10-16 Last update: 2026-04-29 Assigner: [email protected] Source: [email protected]

Conclusion & alert: CVE-2013-5824 is rated High Risk (70.6/100): CVSS Critical severity, with medium exploitation likelihood (EPSS 4.84%). Mandatory action: High exploitation likelihood—assess exposure and prioritize remediation.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

Exploit prediction scoring system (EPSS) score for CVE-2013-5824

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2025-07-01 5.42% 4.84% -0.58%
2 2025-03-30 8.42% 5.42% -3.00%
3 2025-03-29 8.42%

Full EPSS history (7 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2013-5824

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
10.0 2.0 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C Click to expand
Access vector (AV:N)
Can be exploited remotely over network reachability.
Access complexity (AC:L)
Exploitation conditions are straightforward and predictable.
Authentication (AU:N)
No authentication is required.
Confidentiality impact (C:C)
Complete confidentiality impact.
Integrity impact (I:C)
Complete integrity impact.
Availability impact (A:C)
Complete availability impact.
10.0 10.0 [email protected]

Weakness enumeration for CVE-2013-5824

OS Trackers for CVE-2013-5824

vendor priority summary link
gentoo high CVE-2013-5824: 1 GLSA(s) (201401-30), 5 atom(s) (app-emulation/emul-linux-x86-java, dev-java/oracle-jdk-bin, dev-java/oracle-jre-bin, dev-java/sun-jdk, dev-java/sun-jre-bin); latest impact high. https://bugs.gentoo.org/buglist.cgi?quicksearch=CVE-2013-5824
redhat critical https://access.redhat.com/security/cve/CVE-2013-5824
suse medium CVE-2013-5824 severity moderate: SUSE including 25 source package names (java-1_6_0-ibm-1.6.0_sr15.0-0.5.1, java-1_6_0-ibm-1.6.0_sr16.1-5.9, …), 70 product×package rows across 10 product lines (SUSE Linux Enterprise Module for Legacy 12, SUSE Linux Enterprise Server 11 SP1-LTSS, … (10 product lines)): Fixed 70. https://www.suse.com/security/cve/CVE-2013-5824/
ubuntu medium CVE-2013-5824 medium priority: Ubuntu including 2 source packages (openjdk-6, openjdk-7), 10 status rows across 5 suites (lucid, precise, quantal, raring, upstream): not-affected 9, DNE 1. https://ubuntu.com/security/CVE-2013-5824

NVD evaluator notes for CVE-2013-5824

Comment: Per http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html 'Applies to client deployment of Java only. This vulnerability can be exploited only through sandboxed Java Web Start applications and sandboxed Java applets.'

Affected software / configurations for CVE-2013-5824

Vendor Product Version Raw CPE
oracle jdk <= 1.7.0 cpe:2.3:a:oracle:jdk:*:update40:*:*:*:*:*:*
oracle jdk 1.7.0 cpe:2.3:a:oracle:jdk:1.7.0:*:*:*:*:*:*:*
oracle jdk 1.7.0 cpe:2.3:a:oracle:jdk:1.7.0:update1:*:*:*:*:*:*
oracle jdk 1.7.0 cpe:2.3:a:oracle:jdk:1.7.0:update10:*:*:*:*:*:*
oracle jdk 1.7.0 cpe:2.3:a:oracle:jdk:1.7.0:update11:*:*:*:*:*:*
oracle jdk 1.7.0 cpe:2.3:a:oracle:jdk:1.7.0:update13:*:*:*:*:*:*
oracle jdk 1.7.0 cpe:2.3:a:oracle:jdk:1.7.0:update15:*:*:*:*:*:*
oracle jdk 1.7.0 cpe:2.3:a:oracle:jdk:1.7.0:update17:*:*:*:*:*:*
oracle jdk 1.7.0 cpe:2.3:a:oracle:jdk:1.7.0:update2:*:*:*:*:*:*
oracle jdk 1.7.0 cpe:2.3:a:oracle:jdk:1.7.0:update21:*:*:*:*:*:*
oracle jdk 1.7.0 cpe:2.3:a:oracle:jdk:1.7.0:update25:*:*:*:*:*:*
oracle jdk 1.7.0 cpe:2.3:a:oracle:jdk:1.7.0:update3:*:*:*:*:*:*
oracle jdk 1.7.0 cpe:2.3:a:oracle:jdk:1.7.0:update4:*:*:*:*:*:*
oracle jdk 1.7.0 cpe:2.3:a:oracle:jdk:1.7.0:update5:*:*:*:*:*:*
oracle jdk 1.7.0 cpe:2.3:a:oracle:jdk:1.7.0:update6:*:*:*:*:*:*
oracle jdk 1.7.0 cpe:2.3:a:oracle:jdk:1.7.0:update7:*:*:*:*:*:*
oracle jdk 1.7.0 cpe:2.3:a:oracle:jdk:1.7.0:update9:*:*:*:*:*:*
oracle jre <= 1.7.0 cpe:2.3:a:oracle:jre:*:update40:*:*:*:*:*:*
oracle jre 1.7.0 cpe:2.3:a:oracle:jre:1.7.0:*:*:*:*:*:*:*
oracle jre 1.7.0 cpe:2.3:a:oracle:jre:1.7.0:update1:*:*:*:*:*:*
oracle jre 1.7.0 cpe:2.3:a:oracle:jre:1.7.0:update10:*:*:*:*:*:*
oracle jre 1.7.0 cpe:2.3:a:oracle:jre:1.7.0:update11:*:*:*:*:*:*
oracle jre 1.7.0 cpe:2.3:a:oracle:jre:1.7.0:update13:*:*:*:*:*:*
oracle jre 1.7.0 cpe:2.3:a:oracle:jre:1.7.0:update15:*:*:*:*:*:*
oracle jre 1.7.0 cpe:2.3:a:oracle:jre:1.7.0:update17:*:*:*:*:*:*
oracle jre 1.7.0 cpe:2.3:a:oracle:jre:1.7.0:update2:*:*:*:*:*:*
oracle jre 1.7.0 cpe:2.3:a:oracle:jre:1.7.0:update21:*:*:*:*:*:*
oracle jre 1.7.0 cpe:2.3:a:oracle:jre:1.7.0:update25:*:*:*:*:*:*
oracle jre 1.7.0 cpe:2.3:a:oracle:jre:1.7.0:update3:*:*:*:*:*:*
oracle jre 1.7.0 cpe:2.3:a:oracle:jre:1.7.0:update4:*:*:*:*:*:*
oracle jre 1.7.0 cpe:2.3:a:oracle:jre:1.7.0:update5:*:*:*:*:*:*
oracle jre 1.7.0 cpe:2.3:a:oracle:jre:1.7.0:update6:*:*:*:*:*:*
oracle jre 1.7.0 cpe:2.3:a:oracle:jre:1.7.0:update7:*:*:*:*:*:*
oracle jre 1.7.0 cpe:2.3:a:oracle:jre:1.7.0:update9:*:*:*:*:*:*
oracle jre <= 1.6.0 cpe:2.3:a:oracle:jre:*:update60:*:*:*:*:*:*
oracle jre 1.6.0 cpe:2.3:a:oracle:jre:1.6.0:update22:*:*:*:*:*:*
oracle jre 1.6.0 cpe:2.3:a:oracle:jre:1.6.0:update23:*:*:*:*:*:*
oracle jre 1.6.0 cpe:2.3:a:oracle:jre:1.6.0:update24:*:*:*:*:*:*
oracle jre 1.6.0 cpe:2.3:a:oracle:jre:1.6.0:update25:*:*:*:*:*:*
oracle jre 1.6.0 cpe:2.3:a:oracle:jre:1.6.0:update26:*:*:*:*:*:*
oracle jre 1.6.0 cpe:2.3:a:oracle:jre:1.6.0:update27:*:*:*:*:*:*
oracle jre 1.6.0 cpe:2.3:a:oracle:jre:1.6.0:update29:*:*:*:*:*:*
oracle jre 1.6.0 cpe:2.3:a:oracle:jre:1.6.0:update30:*:*:*:*:*:*
oracle jre 1.6.0 cpe:2.3:a:oracle:jre:1.6.0:update31:*:*:*:*:*:*
oracle jre 1.6.0 cpe:2.3:a:oracle:jre:1.6.0:update32:*:*:*:*:*:*
oracle jre 1.6.0 cpe:2.3:a:oracle:jre:1.6.0:update33:*:*:*:*:*:*
oracle jre 1.6.0 cpe:2.3:a:oracle:jre:1.6.0:update34:*:*:*:*:*:*
oracle jre 1.6.0 cpe:2.3:a:oracle:jre:1.6.0:update35:*:*:*:*:*:*
oracle jre 1.6.0 cpe:2.3:a:oracle:jre:1.6.0:update37:*:*:*:*:*:*
oracle jre 1.6.0 cpe:2.3:a:oracle:jre:1.6.0:update38:*:*:*:*:*:*
oracle jre 1.6.0 cpe:2.3:a:oracle:jre:1.6.0:update39:*:*:*:*:*:*
oracle jre 1.6.0 cpe:2.3:a:oracle:jre:1.6.0:update41:*:*:*:*:*:*
oracle jre 1.6.0 cpe:2.3:a:oracle:jre:1.6.0:update43:*:*:*:*:*:*
oracle jre 1.6.0 cpe:2.3:a:oracle:jre:1.6.0:update45:*:*:*:*:*:*
oracle jre 1.6.0 cpe:2.3:a:oracle:jre:1.6.0:update51:*:*:*:*:*:*
sun jre 1.6.0 cpe:2.3:a:sun:jre:1.6.0:*:*:*:*:*:*:*
sun jre 1.6.0 cpe:2.3:a:sun:jre:1.6.0:update_1:*:*:*:*:*:*
sun jre 1.6.0 cpe:2.3:a:sun:jre:1.6.0:update_10:*:*:*:*:*:*
sun jre 1.6.0 cpe:2.3:a:sun:jre:1.6.0:update_11:*:*:*:*:*:*
sun jre 1.6.0 cpe:2.3:a:sun:jre:1.6.0:update_12:*:*:*:*:*:*
sun jre 1.6.0 cpe:2.3:a:sun:jre:1.6.0:update_13:*:*:*:*:*:*
sun jre 1.6.0 cpe:2.3:a:sun:jre:1.6.0:update_14:*:*:*:*:*:*
sun jre 1.6.0 cpe:2.3:a:sun:jre:1.6.0:update_15:*:*:*:*:*:*
sun jre 1.6.0 cpe:2.3:a:sun:jre:1.6.0:update_16:*:*:*:*:*:*
sun jre 1.6.0 cpe:2.3:a:sun:jre:1.6.0:update_17:*:*:*:*:*:*
sun jre 1.6.0 cpe:2.3:a:sun:jre:1.6.0:update_18:*:*:*:*:*:*
sun jre 1.6.0 cpe:2.3:a:sun:jre:1.6.0:update_19:*:*:*:*:*:*
sun jre 1.6.0 cpe:2.3:a:sun:jre:1.6.0:update_2:*:*:*:*:*:*
sun jre 1.6.0 cpe:2.3:a:sun:jre:1.6.0:update_20:*:*:*:*:*:*
sun jre 1.6.0 cpe:2.3:a:sun:jre:1.6.0:update_21:*:*:*:*:*:*
sun jre 1.6.0 cpe:2.3:a:sun:jre:1.6.0:update_3:*:*:*:*:*:*
sun jre 1.6.0 cpe:2.3:a:sun:jre:1.6.0:update_4:*:*:*:*:*:*
sun jre 1.6.0 cpe:2.3:a:sun:jre:1.6.0:update_5:*:*:*:*:*:*
sun jre 1.6.0 cpe:2.3:a:sun:jre:1.6.0:update_6:*:*:*:*:*:*
sun jre 1.6.0 cpe:2.3:a:sun:jre:1.6.0:update_7:*:*:*:*:*:*
sun jre 1.6.0 cpe:2.3:a:sun:jre:1.6.0:update_9:*:*:*:*:*:*
oracle jdk <= 1.6.0 cpe:2.3:a:oracle:jdk:*:update60:*:*:*:*:*:*
oracle jdk 1.6.0 cpe:2.3:a:oracle:jdk:1.6.0:update22:*:*:*:*:*:*
oracle jdk 1.6.0 cpe:2.3:a:oracle:jdk:1.6.0:update23:*:*:*:*:*:*
oracle jdk 1.6.0 cpe:2.3:a:oracle:jdk:1.6.0:update24:*:*:*:*:*:*

References for CVE-2013-5824

URL Tags
http://lists.apple.com/archives/security-announce/2013/Oct/msg00001.html
http://lists.opensuse.org/opensuse-security-announce/2013-11/msg00013.html
http://marc.info/?l=bugtraq&m=138674031212883&w=2
http://marc.info/?l=bugtraq&m=138674073720143&w=2
http://rhn.redhat.com/errata/RHSA-2013-1440.html
http://rhn.redhat.com/errata/RHSA-2013-1507.html
http://rhn.redhat.com/errata/RHSA-2013-1508.html
http://rhn.redhat.com/errata/RHSA-2013-1793.html
http://secunia.com/advisories/56338
http://support.apple.com/kb/HT5982
http://www-01.ibm.com/support/docview.wss?uid=swg21655201
http://www.hitachi.co.jp/Prod/comp/soft1/global/security/info/vuls/HS13-025/index.html
http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html Vendor Advisory
http://www.securityfocus.com/bid/63139
https://access.redhat.com/errata/RHSA-2014:0414
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19212
cvelogic Threat Intelligence