VRT 391,192 CVEs tracked · 15,442 in RASP scope · data as of 16 hours ago
Reset
More filters (1)
Columns
Advisory: Java SE CPU Feb 2012
Overview 14 matches · 10 in RASP scope · 4 protected · 1 KEV · 3 public PoC · 1 CISA SSVC · 3 EPSS ≥ 0.5 · 0 disputed
14matches 10in RASP scope71.4% 4protected28.6% 1KEV7.1% 3public PoC21.4% 1CISA SSVC7.1% 3EPSS ≥ 0.521.4% 0disputed0.0%
Critical 1 7.1% High 8 57.1% Medium 5 35.7% Low 0 0.0% None 0 0.0% Unknown 0 0.0%
Protected by RASP 0 0.0% Rule in development 0 0.0% Mitigation candidate 1 7.1% No exploit published 0 0.0% No fix identified 5 35.7% Mitigated by environment configuration 4 28.6% Queued for review 0 0.0% Not applicable 1 7.1% Out of RASP scope 3 21.4% Rejected 0 0.0%
blocked by ARMR today 4 28.6% not blocked 10 71.4% not established 0 0.0% unrecorded 0 0.0%
split by peak 12 / month
Unknown: 0None: 0Low: 0Medium: 5High: 8Critical: 1 Rejected: 0Out of RASP scope: 3Not applicable: 1Queued for review: 0Mitigated by environment configuration: 4No fix identified: 5No exploit published: 0Mitigation candidate: 1Rule in development: 0Protected by RASP: 0 unrecorded: 0not established: 0not blocked: 10blocked by ARMR today: 4 No public exploit: 11Forecast only: 0Proof of concept only: 0Working exploit published: 2Exploited in the wild: 1 December 2011: 1 CVE January 2012: 0 CVEs February 2012: 12 CVEs March 2012: 0 CVEs April 2012: 0 CVEs May 2012: 0 CVEs June 2012: 1 CVE
Dec 11Jan 12Feb 12Mar 12Apr 12May 12Jun 12
14 matches CSV JSON
CVE Severity Published Status Exploitation Description
CVE-2012-0507 Critical 2012-06-07 Mitigation candidate Exploited in the wild Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, and 5.0 Update 33 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Concurrency. NOTE: the previous information was obtained from the February 2012 Oracle CPU. Oracle has not commented on claims from a downstream vendor and third party researchers that this issue occurs because the AtomicReferenceArray class implementation does not ensure that the array is of the Object[] type, which allows attackers to cause a denial of service (JVM crash) or bypass Java sandbox restrictions. NOTE: this issue was originally mapped to CVE-2011-3571, but that identifier was already assigned to a different issue.
CVE-2012-0508 High 2012-02-15 Out of RASP scope No public exploit Unspecified vulnerability in the JavaFX component in Oracle Java SE JavaFX, 1.3.0 and earlier, and 1.2.2 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.
CVE-2012-0506 Medium 2012-02-15 Mitigated by environment configuration No public exploit Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, 5.0 Update 33 and earlier, and 1.4.2_35 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect integrity via unknown vectors related to CORBA.
CVE-2012-0505 High 2012-02-15 Mitigated by environment configuration No public exploit Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, 5 Update 33 and earlier, and 1.4.2_35 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality, integrity, and availability via unknown vectors related to Serialization.
CVE-2012-0504 High 2012-02-15 Out of RASP scope No public exploit Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, and 6 Update 30 and earlier, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Install and the Java Update mechanism.
CVE-2012-0503 High 2012-02-15 Mitigated by environment configuration No public exploit Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, 5.0 Update 33 and earlier, and 1.4.2_35 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality, integrity, and availability, related to I18n.
CVE-2012-0502 Medium 2012-02-15 Mitigated by environment configuration No public exploit Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, 5.0 Update 33 and earlier, and 1.4.2_35 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality and availability, related to AWT.
CVE-2012-0501 Medium 2012-02-15 No fix identified No public exploit Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, and 5.0 Update 33 and earlier allows remote attackers to affect availability via unknown vectors.
CVE-2012-0500 High 2012-02-15 Out of RASP scope Working exploit published Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, and JavaFX 2.0.2 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality, integrity, and availability via unknown vectors related to Deployment.
CVE-2012-0499 High 2012-02-15 No fix identified No public exploit Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, 5.0 Update 33 and earlier, and 1.4.2_35 and earlier; and JavaFX 2.0.2 and earlier; allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D.
CVE-2012-0498 High 2012-02-15 No fix identified No public exploit Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, and 5.0 Update 33 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D.
CVE-2012-0497 High 2012-02-15 No fix identified No public exploit Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, and 6 Update 30 and earlier, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D.
CVE-2011-3563 Medium 2012-02-15 No fix identified No public exploit Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, 5.0 Update 33 and earlier, and 1.4.2_35 and earlier allows remote attackers to affect confidentiality and availability via unknown vectors related to Sound.
CVE-2011-5035 Medium 2011-12-30 Not applicable Working exploit published Oracle Glassfish 2.1.1, 3.0.1, and 3.1.1, as used in Communications Server 2.0, Sun Java System Application Server 8.1 and 8.2, and possibly other products, computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters, aka Oracle security ticket S0104869.