VRT 391,192 CVEs tracked · 15,442 in RASP scope · data as of 20 hours ago
Reset
More filters (1)
Columns
Oracle product: Oracle Java SE / Java Runtime Environment
Overview 7 matches, all in RASP scope · 4 protected · 1 KEV · 1 public PoC · 1 CISA SSVC · 1 EPSS ≥ 0.5 · 0 disputed
7matches, all in RASP scope 4protected57.1% 1KEV14.3% 1public PoC14.3% 1CISA SSVC14.3% 1EPSS ≥ 0.514.3% 0disputed0.0%
Critical 0 0.0% High 0 0.0% Medium 0 0.0% Low 7 100.0% None 0 0.0% Unknown 0 0.0%
Protected by RASP 1 14.3% Rule in development 0 0.0% Mitigation candidate 2 28.6% No exploit published 0 0.0% No fix identified 1 14.3% Mitigated by environment configuration 3 42.9% Queued for review 0 0.0% Not applicable 0 0.0% Out of RASP scope 0 0.0% Rejected 0 0.0%
blocked by ARMR today 4 57.1% not blocked 3 42.9% not established 0 0.0% unrecorded 0 0.0%
Exploited in the wild 1 14.3% Working exploit published 0 0.0% Proof of concept only 0 0.0% Forecast only 0 0.0% No public exploit 6 85.7%
split by peak 3 / quarter
Unknown: 0None: 0Low: 7Medium: 0High: 0Critical: 0 Rejected: 0Out of RASP scope: 0Not applicable: 0Queued for review: 0Mitigated by environment configuration: 3No fix identified: 1No exploit published: 0Mitigation candidate: 2Rule in development: 0Protected by RASP: 1 unrecorded: 0not established: 0not blocked: 3blocked by ARMR today: 4 No public exploit: 6Forecast only: 0Proof of concept only: 0Working exploit published: 0Exploited in the wild: 1 Q2 2011: 1 CVE Q3 2011: 0 CVEs Q4 2011: 0 CVEs Q1 2012: 0 CVEs Q2 2012: 1 CVE Q3 2012: 0 CVEs Q4 2012: 3 CVEs Q1 2013: 0 CVEs Q2 2013: 2 CVEs
Q2 11Q3 11Q4 11Q1 12Q2 12Q3 12Q4 12Q1 13Q2 13
7 matches CSV JSON
CVE Severity Published Status Exploitation Description
CVE-2013-2423 Low 2013-04-17 Mitigation candidate Exploited in the wild Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, and OpenJDK 7, allows remote attackers to affect integrity via unknown vectors related to HotSpot. NOTE: the previous information is from the April 2013 CPU. Oracle has not commented on claims from the original researcher that this vulnerability allows remote attackers to bypass permission checks by the MethodHandles method and modify arbitrary public final fields using reflection and type confusion, as demonstrated using integer and double fields to disable the security manager.
CVE-2013-2415 Low 2013-04-17 Mitigation candidate No public exploit Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, and OpenJDK 6 and 7, allows local users to affect confidentiality via vectors related to JAX-WS. NOTE: the previous information is from the April 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to "processing of MTOM attachments" and the creation of temporary files with weak permissions.
CVE-2012-5085 Low 2012-10-16 No fix identified No public exploit Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier, 6 Update 35 and earlier, 5.0 Update 36 and earlier, and 1.4.2_38 and earlier allows remote authenticated users to have an unspecified impact via unknown vectors related to Networking. NOTE: the Oracle CPU states that this issue has a 0.0 CVSS score. If so, then this is not a vulnerability and this issue should not be included in CVE.
CVE-2012-5077 Low 2012-10-16 Mitigated by environment configuration No public exploit Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier, 6 Update 35 and earlier, 5.0 Update 36 and earlier, and 1.4.2_38 and earlier allows remote attackers to affect confidentiality via unknown vectors related to Security.
CVE-2012-3216 Low 2012-10-16 Mitigated by environment configuration No public exploit Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier, 6 Update 35 and earlier, 5.0 Update 36 and earlier, and 1.4.2_38 and earlier allows remote attackers to affect confidentiality via unknown vectors related to Libraries.
CVE-2012-1717 Low 2012-06-16 Mitigated by environment configuration No public exploit Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update 4 and earlier, 6 update 32 and earlier, 5 update 35 and earlier, and 1.4.2_37 and earlier allows local users to affect confidentiality via unknown vectors related to printing on Solaris or Linux.
CVE-2011-0865 Low 2011-06-14 Protected by RASP No public exploit Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 6 Update 25 and earlier, 5.0 Update 29 and earlier, and 1.4.2_31 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect integrity via unknown vectors related to Deserialization.