Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2012-1541

Опубликовано: 02 фев. 2013
Источник: ubuntu
Приоритет: medium
CVSS2: 10

Описание

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11 and 6 through Update 38 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment, a different vulnerability than other CVEs listed in the February 2013 CPU. NOTE: the previous information is from the February 2013 CPU. Oracle has not commented on claims from a third party that the issue is due to an interaction error in between the JRE plug-in for WebKit-based browsers and the Javascript engine, which allows remote attackers to execute arbitrary code by modifying DOM nodes that contain applet elements in a way that triggers an incorrect reference count and a use after free.

РелизСтатусПримечание
devel

released

6b27-1.12.1-2ubuntu2
hardy

released

6b27-1.12.3-0ubuntu1~08.04.1
lucid

released

6b27-1.12.1-2ubuntu0.10.04.2
oneiric

released

6b27-1.12.1-2ubuntu0.11.10.2
precise

released

6b27-1.12.1-2ubuntu0.12.04.2
quantal

released

6b27-1.12.1-2ubuntu0.12.10.2
upstream

pending

6b24-1.11.6, 6b27-1.12.1

Показывать по

РелизСтатусПримечание
devel

DNE

hardy

DNE

lucid

ignored

end of life
oneiric

ignored

end of life
precise

DNE

quantal

DNE

upstream

needs-triage

Показывать по

РелизСтатусПримечание
devel

released

7u13-2.3.6-1ubuntu1
hardy

DNE

lucid

DNE

oneiric

released

7u13-2.3.6-0ubuntu0.11.10.2
precise

released

7u13-2.3.6-0ubuntu0.12.04.1
quantal

released

7u13-2.3.6-0ubuntu0.12.10.1
upstream

pending

7u9-2.3.5

Показывать по

РелизСтатусПримечание
devel

DNE

hardy

ignored

end of life
lucid

DNE

oneiric

DNE

precise

DNE

quantal

DNE

upstream

ignored

end of life

Показывать по

РелизСтатусПримечание
devel

DNE

hardy

ignored

end of life
lucid

DNE

removed from archive
oneiric

DNE

precise

DNE

quantal

DNE

upstream

needs-triage

Показывать по

10 Critical

CVSS2

Связанные уязвимости

redhat
около 13 лет назад

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11 and 6 through Update 38 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment, a different vulnerability than other CVEs listed in the February 2013 CPU. NOTE: the previous information is from the February 2013 CPU. Oracle has not commented on claims from a third party that the issue is due to an interaction error in between the JRE plug-in for WebKit-based browsers and the Javascript engine, which allows remote attackers to execute arbitrary code by modifying DOM nodes that contain applet elements in a way that triggers an incorrect reference count and a use after free.

nvd
около 13 лет назад

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11 and 6 through Update 38 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment, a different vulnerability than other CVEs listed in the February 2013 CPU. NOTE: the previous information is from the February 2013 CPU. Oracle has not commented on claims from a third party that the issue is due to an interaction error in between the JRE plug-in for WebKit-based browsers and the Javascript engine, which allows remote attackers to execute arbitrary code by modifying DOM nodes that contain applet elements in a way that triggers an incorrect reference count and a use after free.

debian
около 13 лет назад

Unspecified vulnerability in the Java Runtime Environment (JRE) compon ...

github
больше 3 лет назад

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11 and 6 through Update 38 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment, a different vulnerability than other CVEs listed in the February 2013 CPU. NOTE: the previous information is from the February 2013 CPU. Oracle has not commented on claims from a third party that the issue is due to an interaction error in between the JRE plug-in for WebKit-based browsers and the Javascript engine, which allows remote attackers to execute arbitrary code by modifying DOM nodes that contain applet elements in a way that triggers an incorrect reference count and a use after free.

suse-cvrf
около 12 лет назад

Security update for IBM Java 6

10 Critical

CVSS2