Логотип exploitDog
bind:"BDU:2021-04417" OR bind:"CVE-2012-4681"
Консоль
Логотип exploitDog

exploitDog

bind:"BDU:2021-04417" OR bind:"CVE-2012-4681"

Количество 9

Количество 9

fstec логотип

BDU:2021-04417

почти 13 лет назад

Уязвимость компонента Java Runtime Environment (JRE) программных платформ Java SE, позволяющая нарушителю выполнить произвольный код

CVSS2: 10
EPSS: Критический
ubuntu логотип

CVE-2012-4681

почти 13 лет назад

Multiple vulnerabilities in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier allow remote attackers to execute arbitrary code via a crafted applet that bypasses SecurityManager restrictions by (1) using com.sun.beans.finder.ClassFinder.findClass and leveraging an exception with the forName method to access restricted classes from arbitrary packages such as sun.awt.SunToolkit, then (2) using "reflection with a trusted immediate caller" to leverage the getField method to access and modify private fields, as exploited in the wild in August 2012 using Gondzz.class and Gondvv.class.

CVSS3: 9.8
EPSS: Критический
redhat логотип

CVE-2012-4681

почти 13 лет назад

Multiple vulnerabilities in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier allow remote attackers to execute arbitrary code via a crafted applet that bypasses SecurityManager restrictions by (1) using com.sun.beans.finder.ClassFinder.findClass and leveraging an exception with the forName method to access restricted classes from arbitrary packages such as sun.awt.SunToolkit, then (2) using "reflection with a trusted immediate caller" to leverage the getField method to access and modify private fields, as exploited in the wild in August 2012 using Gondzz.class and Gondvv.class.

CVSS2: 6.8
EPSS: Критический
nvd логотип

CVE-2012-4681

почти 13 лет назад

Multiple vulnerabilities in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier allow remote attackers to execute arbitrary code via a crafted applet that bypasses SecurityManager restrictions by (1) using com.sun.beans.finder.ClassFinder.findClass and leveraging an exception with the forName method to access restricted classes from arbitrary packages such as sun.awt.SunToolkit, then (2) using "reflection with a trusted immediate caller" to leverage the getField method to access and modify private fields, as exploited in the wild in August 2012 using Gondzz.class and Gondvv.class.

CVSS3: 9.8
EPSS: Критический
debian логотип

CVE-2012-4681

почти 13 лет назад

Multiple vulnerabilities in the Java Runtime Environment (JRE) compone ...

CVSS3: 9.8
EPSS: Критический
github логотип

GHSA-fw99-8m5g-58p8

больше 3 лет назад

Multiple vulnerabilities in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier allow remote attackers to execute arbitrary code via a crafted applet that bypasses SecurityManager restrictions by (1) using com.sun.beans.finder.ClassFinder.findClass and leveraging an exception with the forName method to access restricted classes from arbitrary packages such as sun.awt.SunToolkit, then (2) using "reflection with a trusted immediate caller" to leverage the getField method to access and modify private fields, as exploited in the wild in August 2012 using Gondzz.class and Gondvv.class.

CVSS3: 9.8
EPSS: Критический
oracle-oval логотип

ELSA-2012-1223

почти 13 лет назад

ELSA-2012-1223: java-1.7.0-openjdk security update (IMPORTANT)

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2015:1086-3

почти 12 лет назад

Security update for IBM Java 7

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2015:0344-1

почти 12 лет назад

Security update for IBM Java 7

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
fstec логотип
BDU:2021-04417

Уязвимость компонента Java Runtime Environment (JRE) программных платформ Java SE, позволяющая нарушителю выполнить произвольный код

CVSS2: 10
94%
Критический
почти 13 лет назад
ubuntu логотип
CVE-2012-4681

Multiple vulnerabilities in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier allow remote attackers to execute arbitrary code via a crafted applet that bypasses SecurityManager restrictions by (1) using com.sun.beans.finder.ClassFinder.findClass and leveraging an exception with the forName method to access restricted classes from arbitrary packages such as sun.awt.SunToolkit, then (2) using "reflection with a trusted immediate caller" to leverage the getField method to access and modify private fields, as exploited in the wild in August 2012 using Gondzz.class and Gondvv.class.

CVSS3: 9.8
94%
Критический
почти 13 лет назад
redhat логотип
CVE-2012-4681

Multiple vulnerabilities in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier allow remote attackers to execute arbitrary code via a crafted applet that bypasses SecurityManager restrictions by (1) using com.sun.beans.finder.ClassFinder.findClass and leveraging an exception with the forName method to access restricted classes from arbitrary packages such as sun.awt.SunToolkit, then (2) using "reflection with a trusted immediate caller" to leverage the getField method to access and modify private fields, as exploited in the wild in August 2012 using Gondzz.class and Gondvv.class.

CVSS2: 6.8
94%
Критический
почти 13 лет назад
nvd логотип
CVE-2012-4681

Multiple vulnerabilities in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier allow remote attackers to execute arbitrary code via a crafted applet that bypasses SecurityManager restrictions by (1) using com.sun.beans.finder.ClassFinder.findClass and leveraging an exception with the forName method to access restricted classes from arbitrary packages such as sun.awt.SunToolkit, then (2) using "reflection with a trusted immediate caller" to leverage the getField method to access and modify private fields, as exploited in the wild in August 2012 using Gondzz.class and Gondvv.class.

CVSS3: 9.8
94%
Критический
почти 13 лет назад
debian логотип
CVE-2012-4681

Multiple vulnerabilities in the Java Runtime Environment (JRE) compone ...

CVSS3: 9.8
94%
Критический
почти 13 лет назад
github логотип
GHSA-fw99-8m5g-58p8

Multiple vulnerabilities in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier allow remote attackers to execute arbitrary code via a crafted applet that bypasses SecurityManager restrictions by (1) using com.sun.beans.finder.ClassFinder.findClass and leveraging an exception with the forName method to access restricted classes from arbitrary packages such as sun.awt.SunToolkit, then (2) using "reflection with a trusted immediate caller" to leverage the getField method to access and modify private fields, as exploited in the wild in August 2012 using Gondzz.class and Gondvv.class.

CVSS3: 9.8
94%
Критический
больше 3 лет назад
oracle-oval логотип
ELSA-2012-1223

ELSA-2012-1223: java-1.7.0-openjdk security update (IMPORTANT)

почти 13 лет назад
suse-cvrf логотип
SUSE-SU-2015:1086-3

Security update for IBM Java 7

почти 12 лет назад
suse-cvrf логотип
SUSE-SU-2015:0344-1

Security update for IBM Java 7

почти 12 лет назад

Уязвимостей на страницу