Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-3425

Опубликовано: 19 апр. 2016
Источник: redhat
CVSS2: 4.3
EPSS Низкий

Описание

Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to affect availability via vectors related to JAXP.

It was discovered that the JAXP component in OpenJDK failed to properly handle Unicode surrogate pairs used as part of the XML attribute values. Specially crafted XML input could cause a Java application to use an excessive amount of memory when parsed.

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=1328040OpenJDK: incorrect handling of surrogate pairs in XML attribute values (JAXP, 8143167)

EPSS

Процентиль: 91%
0.06497
Низкий

4.3 Medium

CVSS2

Связанные уязвимости

CVSS3: 4.3
ubuntu
больше 9 лет назад

Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to affect availability via vectors related to JAXP.

CVSS3: 4.3
nvd
больше 9 лет назад

Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to affect availability via vectors related to JAXP.

CVSS3: 4.3
debian
больше 9 лет назад

Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Jav ...

CVSS3: 4.3
github
больше 3 лет назад

Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to affect availability via vectors related to JAXP.

suse-cvrf
больше 9 лет назад

Security update for java-1_7_0-openjdk

EPSS

Процентиль: 91%
0.06497
Низкий

4.3 Medium

CVSS2