Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2012-1541

Опубликовано: 01 фев. 2013
Источник: redhat
CVSS2: 6.8
EPSS Низкий

Описание

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11 and 6 through Update 38 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment, a different vulnerability than other CVEs listed in the February 2013 CPU. NOTE: the previous information is from the February 2013 CPU. Oracle has not commented on claims from a third party that the issue is due to an interaction error in between the JRE plug-in for WebKit-based browsers and the Javascript engine, which allows remote attackers to execute arbitrary code by modifying DOM nodes that contain applet elements in a way that triggers an incorrect reference count and a use after free.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5java-1.4.2-ibmWill not fix
Red Hat Enterprise Linux 5java-1.5.0-ibmNot affected
Red Hat Enterprise Linux 6java-1.5.0-ibmNot affected
Red Hat Network Satellite Server v 5.4java-1.6.0-ibmFixedRHSA-2013:145523.10.2013
Red Hat Network Satellite Server v 5.5java-1.6.0-ibmFixedRHSA-2013:145623.10.2013
Supplementary for Red Hat Enterprise Linux 5java-1.6.0-sunFixedRHSA-2013:023604.02.2013
Supplementary for Red Hat Enterprise Linux 5java-1.7.0-oracleFixedRHSA-2013:023704.02.2013
Supplementary for Red Hat Enterprise Linux 5java-1.6.0-ibmFixedRHSA-2013:062511.03.2013
Supplementary for Red Hat Enterprise Linux 5java-1.7.0-ibmFixedRHSA-2013:062611.03.2013
Supplementary for Red Hat Enterprise Linux 6java-1.6.0-sunFixedRHSA-2013:023604.02.2013

Показывать по

Дополнительная информация

Статус:

Critical
https://bugzilla.redhat.com/show_bug.cgi?id=906914JDK: unspecified vulnerability fixed in 6u39 and 7u13 (Deployment)

EPSS

Процентиль: 93%
0.09545
Низкий

6.8 Medium

CVSS2

Связанные уязвимости

ubuntu
около 13 лет назад

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11 and 6 through Update 38 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment, a different vulnerability than other CVEs listed in the February 2013 CPU. NOTE: the previous information is from the February 2013 CPU. Oracle has not commented on claims from a third party that the issue is due to an interaction error in between the JRE plug-in for WebKit-based browsers and the Javascript engine, which allows remote attackers to execute arbitrary code by modifying DOM nodes that contain applet elements in a way that triggers an incorrect reference count and a use after free.

nvd
около 13 лет назад

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11 and 6 through Update 38 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment, a different vulnerability than other CVEs listed in the February 2013 CPU. NOTE: the previous information is from the February 2013 CPU. Oracle has not commented on claims from a third party that the issue is due to an interaction error in between the JRE plug-in for WebKit-based browsers and the Javascript engine, which allows remote attackers to execute arbitrary code by modifying DOM nodes that contain applet elements in a way that triggers an incorrect reference count and a use after free.

debian
около 13 лет назад

Unspecified vulnerability in the Java Runtime Environment (JRE) compon ...

github
больше 3 лет назад

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11 and 6 through Update 38 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment, a different vulnerability than other CVEs listed in the February 2013 CPU. NOTE: the previous information is from the February 2013 CPU. Oracle has not commented on claims from a third party that the issue is due to an interaction error in between the JRE plug-in for WebKit-based browsers and the Javascript engine, which allows remote attackers to execute arbitrary code by modifying DOM nodes that contain applet elements in a way that triggers an incorrect reference count and a use after free.

suse-cvrf
около 12 лет назад

Security update for IBM Java 6

EPSS

Процентиль: 93%
0.09545
Низкий

6.8 Medium

CVSS2