CVE-2013-0434: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 throu
infovulnerability
security
Summary
A security flaw was found in Oracle Java SE versions 7 (up to Update 11), 6 (up to Update 38), and older versions, as well as OpenJDK, that could let remote attackers (people attacking from outside your system) access sensitive information through JAXP (Java API for XML Processing, a tool for handling XML files). The exact nature of the vulnerability was not publicly detailed by Oracle, though another vendor suggested it involved a publicly accessible method in JAXP that could expose private data.
Vulnerability Details
CVSS Score
5
EPSS (30-day exploit probability)
EPSS: 0.3%
Classification
Attack SophisticationModerate
Original source: https://nvd.nist.gov/vuln/detail/CVE-2013-0434
First tracked: February 15, 2026 at 08:43 PM
Classified by LLM (prompt v3) · confidence: 95%