Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2016-0603

Опубликовано: 08 фев. 2016
Источник: nvd
CVSS2: 7.6
EPSS Низкий

Описание

Unspecified vulnerability in the Java SE component in Oracle Java SE 6u111, 7u95, 8u71, and 8u72, when running on Windows, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Install. NOTE: the previous information is from Oracle's Security Alert for CVE-2016-0603. Oracle has not commented on third-party claims that this is an untrusted search path issue that allows local users to gain privileges via a Trojan horse dll in the "application directory."

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:o:microsoft:windows:*:*:*:*:*:*:*:*

Одно из

cpe:2.3:a:oracle:jre:1.6.0:update111:*:*:*:*:*:*
cpe:2.3:a:oracle:jre:1.7.0:update95:*:*:*:*:*:*
cpe:2.3:a:oracle:jre:1.8.0:update71:*:*:*:*:*:*
cpe:2.3:a:oracle:jre:1.8.0:update72:*:*:*:*:*:*
Конфигурация 2

Одновременно

cpe:2.3:o:microsoft:windows:*:*:*:*:*:*:*:*

Одно из

cpe:2.3:a:oracle:jdk:1.6.0:update111:*:*:*:*:*:*
cpe:2.3:a:oracle:jdk:1.7.0:update95:*:*:*:*:*:*
cpe:2.3:a:oracle:jdk:1.8.0:update72:*:*:*:*:*:*

EPSS

Процентиль: 86%
0.03
Низкий

7.6 High

CVSS2

Дефекты

NVD-CWE-noinfo

Связанные уязвимости

ubuntu
почти 10 лет назад

Unspecified vulnerability in the Java SE component in Oracle Java SE 6u111, 7u95, 8u71, and 8u72, when running on Windows, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Install. NOTE: the previous information is from Oracle's Security Alert for CVE-2016-0603. Oracle has not commented on third-party claims that this is an untrusted search path issue that allows local users to gain privileges via a Trojan horse dll in the "application directory."

debian
почти 10 лет назад

Unspecified vulnerability in the Java SE component in Oracle Java SE 6 ...

github
больше 3 лет назад

Unspecified vulnerability in the Java SE component in Oracle Java SE 6u111, 7u95, 8u71, and 8u72, when running on Windows, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Install. NOTE: the previous information is from Oracle's Security Alert for CVE-2016-0603. Oracle has not commented on third-party claims that this is an untrusted search path issue that allows local users to gain privileges via a Trojan horse dll in the "application directory."

fstec
почти 10 лет назад

Уязвимость программной платформы Java Platform, позволяющая нарушителю загрузить на компьютер произвольные файлы

EPSS

Процентиль: 86%
0.03
Низкий

7.6 High

CVSS2

Дефекты

NVD-CWE-noinfo