Unspecified vulnerability in the JavaFX component in Oracle Java SE JavaFX 2.2.4 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors, a different vulnerability than other CVEs listed in the February 2013 CPU. NOTE: the previous information is from the February 2013 CPU. Oracle has not commented on claims from a third party that the issue is due to an invalid type cast in the JSObject class.
2013-02-02T00:55:01.130
2025-04-11T00:51:21.963
Deferred
CVSSv2: 7.6 (HIGH)
AV:N/AC:H/Au:N/C:C/I:C/A:C
4.9
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | oracle | javafx | ≤ 2.2.4 | Yes |
Application | oracle | javafx | 2.0 | Yes |
Application | oracle | javafx | 2.0.2 | Yes |
Application | oracle | javafx | 2.0.3 | Yes |
Application | oracle | javafx | 2.1 | Yes |
Application | oracle | javafx | 2.2 | Yes |
Application | oracle | javafx | 2.2.3 | Yes |