VRT 391,810 CVEs tracked · 15,472 in RASP scope · data as of 38 minutes ago
Reset
More filters (2)
Columns
Published from 2012-01-01Published to 2012-12-31
Overview 7 matches, all in RASP scope, all KEV, all CISA SSVC · 1 protected · 6 public PoC · 6 EPSS ≥ 0.5 · 0 disputed
7matches, all in RASP scope, all KEV, all CISA SSVC 1protected14.3% 6public PoC85.7% 6EPSS ≥ 0.585.7% 0disputed0.0%
Critical 7 100.0% High 0 0.0% Medium 0 0.0% Low 0 0.0% None 0 0.0% Unknown 0 0.0%
Protected by RASP 1 14.3% Rule in development 0 0.0% Mitigation candidate 5 71.4% No exploit published 0 0.0% No fix identified 1 14.3% Mitigated by environment configuration 0 0.0% Queued for review 0 0.0% Not applicable 0 0.0% Out of RASP scope 0 0.0% Rejected 0 0.0%
blocked by ARMR today 1 14.3% not blocked 6 85.7% not established 0 0.0% unrecorded 0 0.0%
Exploited in the wild 7 100.0% Working exploit published 0 0.0% Proof of concept only 0 0.0% Forecast only 0 0.0% No public exploit 0 0.0%
split by peak 2 / month
Unknown: 0None: 0Low: 0Medium: 0High: 0Critical: 7 Rejected: 0Out of RASP scope: 0Not applicable: 0Queued for review: 0Mitigated by environment configuration: 0No fix identified: 1No exploit published: 0Mitigation candidate: 5Rule in development: 0Protected by RASP: 1 unrecorded: 0not established: 0not blocked: 6blocked by ARMR today: 1 No public exploit: 0Forecast only: 0Proof of concept only: 0Working exploit published: 0Exploited in the wild: 7 January 2012: 1 CVE February 2012: 0 CVEs March 2012: 0 CVEs April 2012: 0 CVEs May 2012: 1 CVE June 2012: 2 CVEs July 2012: 0 CVEs August 2012: 1 CVE September 2012: 0 CVEs October 2012: 2 CVEs
Jan 12Feb 12Mar 12Apr 12May 12Jun 12Jul 12Aug 12Sep 12Oct 12
7 matches CSV JSON
CVE Severity Published Status Exploitation Description
CVE-2012-5076 Critical 2012-10-16 Mitigation candidate Exploited in the wild Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier allows remote attackers to affect confidentiality, integrity, and availability, related to JAX-WS.
CVE-2012-3152 Critical 2012-10-16 Protected by RASP Exploited in the wild Unspecified vulnerability in the Oracle Reports Developer component in Oracle Fusion Middleware 11.1.1.4, 11.1.1.6, and 11.1.2.0 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Report Server Component. NOTE: the previous information is from the October 2012 CPU. Oracle has not commented on claims from the original researcher that the URLPARAMETER functionality allows remote attackers to read and upload arbitrary files to reports/rwservlet, and that this issue occurs in earlier versions. NOTE: this can be leveraged with CVE-2012-3153 to execute arbitrary code by uploading a .jsp file.
CVE-2012-4681 Critical 2012-08-28 Mitigation candidate Exploited in the wild Multiple vulnerabilities in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier allow remote attackers to execute arbitrary code via a crafted applet that bypasses SecurityManager restrictions by (1) using com.sun.beans.finder.ClassFinder.findClass and leveraging an exception with the forName method to access restricted classes from arbitrary packages such as sun.awt.SunToolkit, then (2) using "reflection with a trusted immediate caller" to leverage the getField method to access and modify private fields, as exploited in the wild in August 2012 using Gondzz.class and Gondvv.class.
CVE-2012-1723 Critical 2012-06-16 Mitigation candidate Exploited in the wild Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update 4 and earlier, 6 update 32 and earlier, 5 update 35 and earlier, and 1.4.2_37 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Hotspot.
CVE-2012-0507 Critical 2012-06-07 Mitigation candidate Exploited in the wild Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, and 5.0 Update 33 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Concurrency. NOTE: the previous information was obtained from the February 2012 Oracle CPU. Oracle has not commented on claims from a downstream vendor and third party researchers that this issue occurs because the AtomicReferenceArray class implementation does not ensure that the array is of the Object[] type, which allows attackers to cause a denial of service (JVM crash) or bypass Java sandbox restrictions. NOTE: this issue was originally mapped to CVE-2011-3571, but that identifier was already assigned to a different issue.
CVE-2012-1710 Critical 2012-05-03 No fix identified Exploited in the wild Unspecified vulnerability in the Oracle WebCenter Forms Recognition component in Oracle Fusion Middleware 10.1.3.5 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Designer, a different vulnerability than CVE-2012-1709.
CVE-2012-0391 Critical 2012-01-08 Mitigation candidate Exploited in the wild The ExceptionDelegator component in Apache Struts before 2.2.3.1 interprets parameter values as OGNL expressions during certain exception handling for mismatched data types of properties, which allows remote attackers to execute arbitrary Java code via a crafted parameter.