Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 10 and Update 11, when running on Windows using Internet Explorer, Firefox, Opera, and Google Chrome, allows remote attackers to bypass the "Very High" security level of the Java Control Panel and execute unsigned Java code without prompting the user via unknown vectors, aka "Issue 53" and the "Java Security Slider" vulnerability.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Hpux | — | Update Jre70.JRE70-IPF64-HS to the latest versionUpdate Jdk70.JDK70-COM to the latest versionUpdate Jre70.JRE70-COM to the latest versionUpdate Jre70.JRE70-IPF64 to the latest versionUpdate Jre70.JRE70-IPF32 to the latest versionUpdate Jdk70.JDK70-DEMO to the latest versionUpdate Jdk70.JDK70-IPF64 to the latest versionUpdate Jre70.JRE70-IPF32-HS to the latest versionUpdate Jdk70.JDK70-IPF32 to the latest version | Aug 11, 2017 | Jan 31, 2013 |
| Jre Vuln | — | Upgrade to the latest version of Oracle Java | Feb 3, 2013 | Jan 31, 2013 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jan 27, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub