CVE-2012-0499
published 2012-02-15CVE-2012-0499: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, 5.0 Update 33 and…
PriorityP354critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
6.34%
92.8th percentile
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, 5.0 Update 33 and earlier, and 1.4.2_35 and earlier; and JavaFX 2.0.2 and earlier; allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D.
Affected
50 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | javafx | <= 2.0.2 | — |
| oracle | javafx | — | — |
| oracle | javafx | — | — |
| oracle | javafx | — | — |
| oracle | javafx | — | — |
| oracle | javafx | — | — |
| oracle | javafx | — | — |
| oracle | jre | <= 1.6.0 | — |
| oracle | jre | <= 1.7.0 | — |
| oracle | jre | — | — |
| oracle | jre | — | — |
| sun | jre | <= 1.4.2_35 | — |
| sun | jre | <= 1.5.0 | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vendor_redhat10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-w5h4-pg4w-wqvr: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, 5
ghsa_unreviewed·2022-05-04
CVE-2012-0499 [HIGH] GHSA-w5h4-pg4w-wqvr: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, 5
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, 5.0 Update 33 and earlier, and 1.4.2_35 and earlier; and JavaFX 2.0.2 and earlier; allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D.
Red Hat
JDK: unspecified vulnerability fixed in 6u31 and 7u3 (2D)
vendor_redhat·2012-02-14·CVSS 10.0
CVE-2012-0499 [CRITICAL] JDK: unspecified vulnerability fixed in 6u31 and 7u3 (2D)
JDK: unspecified vulnerability fixed in 6u31 and 7u3 (2D)
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, 5.0 Update 33 and earlier, and 1.4.2_35 and earlier; and JavaFX 2.0.2 and earlier; allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D.
Package: java-1.6.0-sun (Red Hat Enterprise Linux 4) - Affected
Package: java-1.6.0-openjdk (Red Hat Enterprise Linux 5) - Not affected
Package: java-1.6.0-openjdk (Red Hat Enterprise Linux 6) - Not affected
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-0504 Oracle JDK: unspecified vulnerability fixed in 6u31 and 7u3 (Install)
bugzilla·2012-02-15·CVSS 10.0
CVE-2012-0504 [CRITICAL] CVE-2012-0504 Oracle JDK: unspecified vulnerability fixed in 6u31 and 7u3 (Install)
CVE-2012-0504 Oracle JDK: unspecified vulnerability fixed in 6u31 and 7u3 (Install)
Java SE 6 Update 31 and Java SE 7 Update 3 of Oracle/Sun Java fixes an unspecified vulnerability in the Install component (CVE-2012-0499). Upstream has CVSSv2 scored this issue as: 10/AV:N/AC:L/Au:N/C:C/I:C/A:C
http://www.oracle.com/technetwork/topics/security/javacpufeb2012-366318.html
Discussion:
This issue affects Java Update mechanism (see Note 4 on the Oracle CPU Patch Advisory page), which is only available on Microsoft Windows platform:
http://www.java.com/en/download/help/java_update.xml
---
Statement:
Not vulnerable. This issue affects the Java Update mechanism which is only available on the Microsoft Windows platform.
Bugzilla
CVE-2012-0499 Oracle JDK: unspecified vulnerability fixed in 6u31 and 7u3 (2D)
bugzilla·2012-02-15·CVSS 10.0
CVE-2012-0499 [CRITICAL] CVE-2012-0499 Oracle JDK: unspecified vulnerability fixed in 6u31 and 7u3 (2D)
CVE-2012-0499 Oracle JDK: unspecified vulnerability fixed in 6u31 and 7u3 (2D)
Java SE 6 Update 31 and Java SE 7 Update 3 of Oracle/Sun Java fixes an unspecified vulnerability in the Java2D component (CVE-2012-0499). Upstream has CVSSv2 scored this issue as: 10/AV:N/AC:L/Au:N/C:C/I:C/A:C
http://www.oracle.com/technetwork/topics/security/javacpufeb2012-366318.html
Discussion:
This issue has been addressed in following products:
Extras for RHEL 4
Supplementary for Red Hat Enterprise Linux 5
Supplementary for Red Hat Enterprise Linux 6
Via RHSA-2012:0139 https://rhn.redhat.com/errata/RHSA-2012-0139.html
---
This issue has been addressed in following products:
Supplementary for Red Hat Enterprise Linux 5
Supplementary for Red Hat Enterprise Linux 6
Via RHSA-2012:0508 https://rhn.redh
Bugzilla
CVE-2012-0500 Oracle JDK: unspecified vulnerability fixed in 6u31 and 7u3 (Deployment)
bugzilla·2012-02-15·CVSS 10.0
CVE-2012-0500 [CRITICAL] CVE-2012-0500 Oracle JDK: unspecified vulnerability fixed in 6u31 and 7u3 (Deployment)
CVE-2012-0500 Oracle JDK: unspecified vulnerability fixed in 6u31 and 7u3 (Deployment)
Java SE 6 Update 31 and Java SE 7 Update 3 of Oracle/Sun Java fixes an unspecified vulnerability in the Deployment component (CVE-2012-0499). Upstream has CVSSv2 scored this issue as: 10/AV:N/AC:L/Au:N/C:C/I:C/A:C
http://www.oracle.com/technetwork/topics/security/javacpufeb2012-366318.html
Discussion:
TELUS Security Labs VR advisory for this issue:
http://seclists.org/fulldisclosure/2012/Feb/251
http://telussecuritylabs.com/threats/show/TSL20120214-01
---
This issue has been addressed in following products:
Extras for RHEL 4
Supplementary for Red Hat Enterprise Linux 5
Supplementary for Red Hat Enterprise Linux 6
Via RHSA-2012:0139 https://rhn.redhat.com/errata/RHSA-2012-0139.html
---
(In repl
http://lists.opensuse.org/opensuse-security-announce/2012-05/msg00009.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-05/msg00010.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-06/msg00009.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-07/msg00007.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-08/msg00015.htmlhttp://marc.info/?l=bugtraq&m=133364885411663&w=2http://marc.info/?l=bugtraq&m=133365109612558&w=2http://marc.info/?l=bugtraq&m=133728004526190&w=2http://marc.info/?l=bugtraq&m=133847939902305&w=2http://marc.info/?l=bugtraq&m=134254866602253&w=2http://marc.info/?l=bugtraq&m=134254957702612&w=2http://rhn.redhat.com/errata/RHSA-2012-0508.htmlhttp://rhn.redhat.com/errata/RHSA-2012-0514.htmlhttp://rhn.redhat.com/errata/RHSA-2012-0702.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1080.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1455.htmlhttp://secunia.com/advisories/48073http://secunia.com/advisories/48074http://secunia.com/advisories/48589http://secunia.com/advisories/48692http://secunia.com/advisories/48915http://secunia.com/advisories/48948http://secunia.com/advisories/48950http://secunia.com/advisories/49198http://www.mandriva.com/security/advisories?name=MDVSA-2013:150http://www.oracle.com/technetwork/topics/security/cpuapr2012-366314.htmlhttp://www.oracle.com/technetwork/topics/security/javacpufeb2012-366318.htmlhttp://www.securityfocus.com/bid/52016https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14878http://lists.opensuse.org/opensuse-security-announce/2012-05/msg00009.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-05/msg00010.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-06/msg00009.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-07/msg00007.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-08/msg00015.htmlhttp://marc.info/?l=bugtraq&m=133364885411663&w=2http://marc.info/?l=bugtraq&m=133365109612558&w=2http://marc.info/?l=bugtraq&m=133728004526190&w=2http://marc.info/?l=bugtraq&m=133847939902305&w=2http://marc.info/?l=bugtraq&m=134254866602253&w=2http://marc.info/?l=bugtraq&m=134254957702612&w=2http://rhn.redhat.com/errata/RHSA-2012-0508.htmlhttp://rhn.redhat.com/errata/RHSA-2012-0514.htmlhttp://rhn.redhat.com/errata/RHSA-2012-0702.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1080.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1455.htmlhttp://secunia.com/advisories/48073http://secunia.com/advisories/48074http://secunia.com/advisories/48589http://secunia.com/advisories/48692http://secunia.com/advisories/48915http://secunia.com/advisories/48948http://secunia.com/advisories/48950http://secunia.com/advisories/49198http://www.mandriva.com/security/advisories?name=MDVSA-2013:150http://www.oracle.com/technetwork/topics/security/cpuapr2012-366314.htmlhttp://www.oracle.com/technetwork/topics/security/javacpufeb2012-366318.htmlhttp://www.securityfocus.com/bid/52016https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14878
2012-02-15
Published