CVE-2012-0497
published 2012-02-15CVE-2012-0497: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, and 6 Update 30 and earlier, allows remote…
PriorityP355critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
5.92%
92.4th percentile
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, and 6 Update 30 and earlier, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | jre | <= 1.6.0 | — |
| oracle | jre | <= 1.7.0 | — |
| oracle | jre | — | — |
| oracle | jre | — | — |
| sun | jre | — | — |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vendor_redhat10.0CRITICAL
vendor_ubuntu6.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
OpenJDK 6 (ARM) vulnerabilities
vendor_ubuntu·2012-03-01·CVSS 6.4
CVE-2012-0501 [MEDIUM] OpenJDK 6 (ARM) vulnerabilities
Title: OpenJDK 6 (ARM) vulnerabilities
Summary: Multiple vulnerabilities in OpenJDK 6 for the ARM architecture have
been fixed.
USN 1373-1 fixed vulnerabilities in OpenJDK 6 in Ubuntu 10.04 LTS,
Ubuntu 10.10 and Ubuntu 11.04 for all architectures except for ARM
(armel). This provides the corresponding OpenJDK 6 update for use
with the ARM (armel) architecture in Ubuntu 10.04 LTS, Ubuntu 10.10
and Ubuntu 11.04.
Original advisory details:
It was discovered that the Java HttpServer class did not limit the
number of headers read from a HTTP request. A remote attacker could
cause a denial of service by sending special requests that trigger
hash collisions predictably. (CVE-2011-5035)
ATTENTION: this update changes previous Java HttpServer class behavior
by limiting the number of request he
Ubuntu
OpenJDK 6 vulnerabilities
vendor_ubuntu·2012-02-24·CVSS 6.4
CVE-2011-3563 [MEDIUM] OpenJDK 6 vulnerabilities
Title: OpenJDK 6 vulnerabilities
Summary: Multiple OpenJDK 6 vulnerabilities have been fixed.
It was discovered that the Java HttpServer class did not limit the
number of headers read from a HTTP request. A remote attacker could
cause a denial of service by sending special requests that trigger
hash collisions predictably. (CVE-2011-5035)
ATTENTION: this update changes previous Java HttpServer class behavior
by limiting the number of request headers to 200. This may be increased
by adjusting the sun.net.httpserver.maxReqHeaders property.
It was discovered that the Java Sound component did not properly
check buffer boundaries. A remote attacker could use this to cause
a denial of service or view confidential data. (CVE-2011-3563)
It was discovered that the Java2D implementation does no
Red Hat
OpenJDK: insufficient checking of the graphics rendering object (2D, 7112642)
vendor_redhat·2012-02-14·CVSS 10.0
CVE-2012-0497 [CRITICAL] OpenJDK: insufficient checking of the graphics rendering object (2D, 7112642)
OpenJDK: insufficient checking of the graphics rendering object (2D, 7112642)
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, and 6 Update 30 and earlier, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D.
Package: java-1.6.0-sun (Red Hat Enterprise Linux 4) - Not affected
Package: java-1.6.0-sun (Red Hat Enterprise Linux 5) - Not affected
Package: java-1.6.0-sun (Red Hat Enterprise Linux 6) - Not affected
GHSA
GHSA-x8rc-48fv-g2g8: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, and 6 Update 30 and earlier, allow
ghsa_unreviewed·2022-05-04
CVE-2012-0497 [HIGH] GHSA-x8rc-48fv-g2g8: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, and 6 Update 30 and earlier, allow
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, and 6 Update 30 and earlier, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D.
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-security-announce/2012-05/msg00010.htmlhttp://marc.info/?l=bugtraq&m=133364885411663&w=2http://marc.info/?l=bugtraq&m=133847939902305&w=2http://marc.info/?l=bugtraq&m=134254866602253&w=2http://marc.info/?l=bugtraq&m=134254957702612&w=2http://rhn.redhat.com/errata/RHSA-2012-0514.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1455.htmlhttp://secunia.com/advisories/48074http://secunia.com/advisories/48589http://secunia.com/advisories/48950http://security.gentoo.org/glsa/glsa-201406-32.xmlhttp://www.debian.org/security/2012/dsa-2420http://www.mandriva.com/security/advisories?name=MDVSA-2013:150http://www.oracle.com/technetwork/topics/security/cpuapr2012-366314.htmlhttp://www.oracle.com/technetwork/topics/security/javacpufeb2012-366318.htmlhttp://www.securityfocus.com/bid/52009https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14772http://lists.opensuse.org/opensuse-security-announce/2012-05/msg00010.htmlhttp://marc.info/?l=bugtraq&m=133364885411663&w=2http://marc.info/?l=bugtraq&m=133847939902305&w=2http://marc.info/?l=bugtraq&m=134254866602253&w=2http://marc.info/?l=bugtraq&m=134254957702612&w=2http://rhn.redhat.com/errata/RHSA-2012-0514.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1455.htmlhttp://secunia.com/advisories/48074http://secunia.com/advisories/48589http://secunia.com/advisories/48950http://security.gentoo.org/glsa/glsa-201406-32.xmlhttp://www.debian.org/security/2012/dsa-2420http://www.mandriva.com/security/advisories?name=MDVSA-2013:150http://www.oracle.com/technetwork/topics/security/cpuapr2012-366314.htmlhttp://www.oracle.com/technetwork/topics/security/javacpufeb2012-366318.htmlhttp://www.securityfocus.com/bid/52009https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14772
2012-02-15
Published