CVE-2012-0501Off-by-one Error in Oracle JRE

CWE-193Off-by-one Error8 documents7 sources
Severity
5.0MEDIUMNVD
EPSS
5.1%
top 10.11%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 15
Latest updateMay 4

Description

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, and 5.0 Update 33 and earlier allows remote attackers to affect availability via unknown vectors.

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9

Affected Packages2 packages

NVDoracle/jre1.6.0+3
NVDsun/jre1.5.0+2

🔴Vulnerability Details

2
GHSA
GHSA-8366-7q28-v2hw: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, and 52022-05-04
CVEList
CVE-2012-0501: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, and 52012-02-15

💥Exploits & PoCs

1
Exploit-DB
Advantech Studio 7.0 - SCADA/HMI Directory Traversal2012-12-04

📋Vendor Advisories

3
Ubuntu
OpenJDK 6 (ARM) vulnerabilities2012-03-01
Ubuntu
OpenJDK 6 vulnerabilities2012-02-24
Red Hat
OpenJDK: off-by-one bug in ZIP reading code (JRE, 7118283)2012-02-14

💬Community

1
Bugzilla
CVE-2012-0501 OpenJDK: off-by-one bug in ZIP reading code (JRE, 7118283)2012-02-08
CVE-2012-0501 — Off-by-one Error in Oracle JRE | cvebase