Логотип exploitDog
bind:"CVE-2012-0547" OR bind:"CVE-2012-3136" OR bind:"CVE-2012-1682" OR bind:"CVE-2012-4681"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2012-0547" OR bind:"CVE-2012-3136" OR bind:"CVE-2012-1682" OR bind:"CVE-2012-4681"

Количество 26

Количество 26

oracle-oval логотип

ELSA-2012-1223

почти 13 лет назад

ELSA-2012-1223: java-1.7.0-openjdk security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2012-1222

почти 13 лет назад

ELSA-2012-1222: java-1.6.0-openjdk security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2012-1221

почти 13 лет назад

ELSA-2012-1221: java-1.6.0-openjdk security update (CRITICAL)

EPSS: Низкий
ubuntu логотип

CVE-2012-0547

почти 13 лет назад

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier, and 6 Update 34 and earlier, has no impact and remote attack vectors involving AWT and "a security-in-depth issue that is not directly exploitable but which can be used to aggravate security vulnerabilities that can be directly exploited." NOTE: this identifier was assigned by the Oracle CNA, but CVE is not intended to cover defense-in-depth issues that are only exposed by the presence of other vulnerabilities. NOTE: Oracle has not commented on claims from a downstream vendor that this issue is related to "toolkit internals references."

EPSS: Средний
redhat логотип

CVE-2012-0547

почти 13 лет назад

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier, and 6 Update 34 and earlier, has no impact and remote attack vectors involving AWT and "a security-in-depth issue that is not directly exploitable but which can be used to aggravate security vulnerabilities that can be directly exploited." NOTE: this identifier was assigned by the Oracle CNA, but CVE is not intended to cover defense-in-depth issues that are only exposed by the presence of other vulnerabilities. NOTE: Oracle has not commented on claims from a downstream vendor that this issue is related to "toolkit internals references."

EPSS: Средний
nvd логотип

CVE-2012-0547

почти 13 лет назад

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier, and 6 Update 34 and earlier, has no impact and remote attack vectors involving AWT and "a security-in-depth issue that is not directly exploitable but which can be used to aggravate security vulnerabilities that can be directly exploited." NOTE: this identifier was assigned by the Oracle CNA, but CVE is not intended to cover defense-in-depth issues that are only exposed by the presence of other vulnerabilities. NOTE: Oracle has not commented on claims from a downstream vendor that this issue is related to "toolkit internals references."

EPSS: Средний
debian логотип

CVE-2012-0547

почти 13 лет назад

Unspecified vulnerability in the Java Runtime Environment (JRE) compon ...

EPSS: Средний
github логотип

GHSA-mpj2-6qj6-74jr

больше 3 лет назад

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier, and 6 Update 34 and earlier, has no impact and remote attack vectors involving AWT and "a security-in-depth issue that is not directly exploitable but which can be used to aggravate security vulnerabilities that can be directly exploited." NOTE: this identifier was assigned by the Oracle CNA, but CVE is not intended to cover defense-in-depth issues that are only exposed by the presence of other vulnerabilities. NOTE: Oracle has not commented on claims from a downstream vendor that this issue is related to "toolkit internals references."

EPSS: Средний
ubuntu логотип

CVE-2012-3136

почти 13 лет назад

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Beans, a different vulnerability than CVE-2012-1682.

CVSS2: 10
EPSS: Низкий
redhat логотип

CVE-2012-3136

почти 13 лет назад

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Beans, a different vulnerability than CVE-2012-1682.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2012-3136

почти 13 лет назад

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Beans, a different vulnerability than CVE-2012-1682.

CVSS2: 10
EPSS: Низкий
debian логотип

CVE-2012-3136

почти 13 лет назад

Unspecified vulnerability in the Java Runtime Environment (JRE) compon ...

CVSS2: 10
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2015:1086-3

почти 12 лет назад

Security update for IBM Java 7

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2015:0344-1

почти 12 лет назад

Security update for IBM Java 7

EPSS: Низкий
github логотип

GHSA-5jvp-8v86-8h9w

больше 3 лет назад

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Beans, a different vulnerability than CVE-2012-1682.

EPSS: Низкий
ubuntu логотип

CVE-2012-4681

почти 13 лет назад

Multiple vulnerabilities in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier allow remote attackers to execute arbitrary code via a crafted applet that bypasses SecurityManager restrictions by (1) using com.sun.beans.finder.ClassFinder.findClass and leveraging an exception with the forName method to access restricted classes from arbitrary packages such as sun.awt.SunToolkit, then (2) using "reflection with a trusted immediate caller" to leverage the getField method to access and modify private fields, as exploited in the wild in August 2012 using Gondzz.class and Gondvv.class.

CVSS3: 9.8
EPSS: Критический
redhat логотип

CVE-2012-4681

почти 13 лет назад

Multiple vulnerabilities in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier allow remote attackers to execute arbitrary code via a crafted applet that bypasses SecurityManager restrictions by (1) using com.sun.beans.finder.ClassFinder.findClass and leveraging an exception with the forName method to access restricted classes from arbitrary packages such as sun.awt.SunToolkit, then (2) using "reflection with a trusted immediate caller" to leverage the getField method to access and modify private fields, as exploited in the wild in August 2012 using Gondzz.class and Gondvv.class.

CVSS2: 6.8
EPSS: Критический
nvd логотип

CVE-2012-4681

почти 13 лет назад

Multiple vulnerabilities in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier allow remote attackers to execute arbitrary code via a crafted applet that bypasses SecurityManager restrictions by (1) using com.sun.beans.finder.ClassFinder.findClass and leveraging an exception with the forName method to access restricted classes from arbitrary packages such as sun.awt.SunToolkit, then (2) using "reflection with a trusted immediate caller" to leverage the getField method to access and modify private fields, as exploited in the wild in August 2012 using Gondzz.class and Gondvv.class.

CVSS3: 9.8
EPSS: Критический
debian логотип

CVE-2012-4681

почти 13 лет назад

Multiple vulnerabilities in the Java Runtime Environment (JRE) compone ...

CVSS3: 9.8
EPSS: Критический
ubuntu логотип

CVE-2012-1682

почти 13 лет назад

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Beans, a different vulnerability than CVE-2012-3136. NOTE: Oracle has not commented on claims from a downstream vendor that this issue is related to "XMLDecoder security issue via ClassFinder."

CVSS2: 10
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
oracle-oval логотип
ELSA-2012-1223

ELSA-2012-1223: java-1.7.0-openjdk security update (IMPORTANT)

почти 13 лет назад
oracle-oval логотип
ELSA-2012-1222

ELSA-2012-1222: java-1.6.0-openjdk security update (IMPORTANT)

почти 13 лет назад
oracle-oval логотип
ELSA-2012-1221

ELSA-2012-1221: java-1.6.0-openjdk security update (CRITICAL)

почти 13 лет назад
ubuntu логотип
CVE-2012-0547

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier, and 6 Update 34 and earlier, has no impact and remote attack vectors involving AWT and "a security-in-depth issue that is not directly exploitable but which can be used to aggravate security vulnerabilities that can be directly exploited." NOTE: this identifier was assigned by the Oracle CNA, but CVE is not intended to cover defense-in-depth issues that are only exposed by the presence of other vulnerabilities. NOTE: Oracle has not commented on claims from a downstream vendor that this issue is related to "toolkit internals references."

11%
Средний
почти 13 лет назад
redhat логотип
CVE-2012-0547

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier, and 6 Update 34 and earlier, has no impact and remote attack vectors involving AWT and "a security-in-depth issue that is not directly exploitable but which can be used to aggravate security vulnerabilities that can be directly exploited." NOTE: this identifier was assigned by the Oracle CNA, but CVE is not intended to cover defense-in-depth issues that are only exposed by the presence of other vulnerabilities. NOTE: Oracle has not commented on claims from a downstream vendor that this issue is related to "toolkit internals references."

11%
Средний
почти 13 лет назад
nvd логотип
CVE-2012-0547

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier, and 6 Update 34 and earlier, has no impact and remote attack vectors involving AWT and "a security-in-depth issue that is not directly exploitable but which can be used to aggravate security vulnerabilities that can be directly exploited." NOTE: this identifier was assigned by the Oracle CNA, but CVE is not intended to cover defense-in-depth issues that are only exposed by the presence of other vulnerabilities. NOTE: Oracle has not commented on claims from a downstream vendor that this issue is related to "toolkit internals references."

11%
Средний
почти 13 лет назад
debian логотип
CVE-2012-0547

Unspecified vulnerability in the Java Runtime Environment (JRE) compon ...

11%
Средний
почти 13 лет назад
github логотип
GHSA-mpj2-6qj6-74jr

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier, and 6 Update 34 and earlier, has no impact and remote attack vectors involving AWT and "a security-in-depth issue that is not directly exploitable but which can be used to aggravate security vulnerabilities that can be directly exploited." NOTE: this identifier was assigned by the Oracle CNA, but CVE is not intended to cover defense-in-depth issues that are only exposed by the presence of other vulnerabilities. NOTE: Oracle has not commented on claims from a downstream vendor that this issue is related to "toolkit internals references."

11%
Средний
больше 3 лет назад
ubuntu логотип
CVE-2012-3136

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Beans, a different vulnerability than CVE-2012-1682.

CVSS2: 10
1%
Низкий
почти 13 лет назад
redhat логотип
CVE-2012-3136

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Beans, a different vulnerability than CVE-2012-1682.

CVSS2: 6.8
1%
Низкий
почти 13 лет назад
nvd логотип
CVE-2012-3136

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Beans, a different vulnerability than CVE-2012-1682.

CVSS2: 10
1%
Низкий
почти 13 лет назад
debian логотип
CVE-2012-3136

Unspecified vulnerability in the Java Runtime Environment (JRE) compon ...

CVSS2: 10
1%
Низкий
почти 13 лет назад
suse-cvrf логотип
SUSE-SU-2015:1086-3

Security update for IBM Java 7

почти 12 лет назад
suse-cvrf логотип
SUSE-SU-2015:0344-1

Security update for IBM Java 7

почти 12 лет назад
github логотип
GHSA-5jvp-8v86-8h9w

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Beans, a different vulnerability than CVE-2012-1682.

1%
Низкий
больше 3 лет назад
ubuntu логотип
CVE-2012-4681

Multiple vulnerabilities in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier allow remote attackers to execute arbitrary code via a crafted applet that bypasses SecurityManager restrictions by (1) using com.sun.beans.finder.ClassFinder.findClass and leveraging an exception with the forName method to access restricted classes from arbitrary packages such as sun.awt.SunToolkit, then (2) using "reflection with a trusted immediate caller" to leverage the getField method to access and modify private fields, as exploited in the wild in August 2012 using Gondzz.class and Gondvv.class.

CVSS3: 9.8
94%
Критический
почти 13 лет назад
redhat логотип
CVE-2012-4681

Multiple vulnerabilities in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier allow remote attackers to execute arbitrary code via a crafted applet that bypasses SecurityManager restrictions by (1) using com.sun.beans.finder.ClassFinder.findClass and leveraging an exception with the forName method to access restricted classes from arbitrary packages such as sun.awt.SunToolkit, then (2) using "reflection with a trusted immediate caller" to leverage the getField method to access and modify private fields, as exploited in the wild in August 2012 using Gondzz.class and Gondvv.class.

CVSS2: 6.8
94%
Критический
почти 13 лет назад
nvd логотип
CVE-2012-4681

Multiple vulnerabilities in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier allow remote attackers to execute arbitrary code via a crafted applet that bypasses SecurityManager restrictions by (1) using com.sun.beans.finder.ClassFinder.findClass and leveraging an exception with the forName method to access restricted classes from arbitrary packages such as sun.awt.SunToolkit, then (2) using "reflection with a trusted immediate caller" to leverage the getField method to access and modify private fields, as exploited in the wild in August 2012 using Gondzz.class and Gondvv.class.

CVSS3: 9.8
94%
Критический
почти 13 лет назад
debian логотип
CVE-2012-4681

Multiple vulnerabilities in the Java Runtime Environment (JRE) compone ...

CVSS3: 9.8
94%
Критический
почти 13 лет назад
ubuntu логотип
CVE-2012-1682

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Beans, a different vulnerability than CVE-2012-3136. NOTE: Oracle has not commented on claims from a downstream vendor that this issue is related to "XMLDecoder security issue via ClassFinder."

CVSS2: 10
3%
Низкий
почти 13 лет назад

Уязвимостей на страницу