VRT 391,192 CVEs tracked · 15,442 in RASP scope · data as of 18 hours ago
Reset
More filters (1)
Columns
Advisory: Java SE CPU Feb 2012
Overview 5 matches · 4 in RASP scope · 2 protected · 0 KEV · 1 public PoC · 0 CISA SSVC · 1 EPSS ≥ 0.5 · 0 disputed
5matches 4in RASP scope80.0% 2protected40.0% 0KEV0.0% 1public PoC20.0% 0CISA SSVC0.0% 1EPSS ≥ 0.520.0% 0disputed0.0%
Critical 0 0.0% High 0 0.0% Medium 5 100.0% Low 0 0.0% None 0 0.0% Unknown 0 0.0%
Protected by RASP 0 0.0% Rule in development 0 0.0% Mitigation candidate 0 0.0% No exploit published 0 0.0% No fix identified 2 40.0% Mitigated by environment configuration 2 40.0% Queued for review 0 0.0% Not applicable 1 20.0% Out of RASP scope 0 0.0% Rejected 0 0.0%
blocked by ARMR today 2 40.0% not blocked 3 60.0% not established 0 0.0% unrecorded 0 0.0%
Exploited in the wild 0 0.0% Working exploit published 1 20.0% Proof of concept only 0 0.0% Forecast only 0 0.0% No public exploit 4 80.0%
split by peak 4 / month
Unknown: 0None: 0Low: 0Medium: 5High: 0Critical: 0 Rejected: 0Out of RASP scope: 0Not applicable: 1Queued for review: 0Mitigated by environment configuration: 2No fix identified: 2No exploit published: 0Mitigation candidate: 0Rule in development: 0Protected by RASP: 0 unrecorded: 0not established: 0not blocked: 3blocked by ARMR today: 2 No public exploit: 4Forecast only: 0Proof of concept only: 0Working exploit published: 1Exploited in the wild: 0 December 2011: 1 CVE January 2012: 0 CVEs February 2012: 4 CVEs
Dec 11Jan 12Feb 12
5 matches CSV JSON
CVE Severity Published Status Exploitation Description
CVE-2012-0506 Medium 2012-02-15 Mitigated by environment configuration No public exploit Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, 5.0 Update 33 and earlier, and 1.4.2_35 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect integrity via unknown vectors related to CORBA.
CVE-2012-0502 Medium 2012-02-15 Mitigated by environment configuration No public exploit Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, 5.0 Update 33 and earlier, and 1.4.2_35 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality and availability, related to AWT.
CVE-2012-0501 Medium 2012-02-15 No fix identified No public exploit Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, and 5.0 Update 33 and earlier allows remote attackers to affect availability via unknown vectors.
CVE-2011-3563 Medium 2012-02-15 No fix identified No public exploit Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, 5.0 Update 33 and earlier, and 1.4.2_35 and earlier allows remote attackers to affect confidentiality and availability via unknown vectors related to Sound.
CVE-2011-5035 Medium 2011-12-30 Not applicable Working exploit published Oracle Glassfish 2.1.1, 3.0.1, and 3.1.1, as used in Communications Server 2.0, Sun Java System Application Server 8.1 and 8.2, and possibly other products, computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters, aka Oracle security ticket S0104869.