CVE-2012-0502Oracle JRE vulnerability

7 documents6 sources
Severity
6.4MEDIUMNVD
EPSS
1.9%
top 16.85%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 15
Latest updateMay 4

Description

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, 5.0 Update 33 and earlier, and 1.4.2_35 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality and availability, related to AWT.

CVSS vector

AV:N/AC:L/C:P/I:N/A:PExploitability: 10.0 | Impact: 4.9

Affected Packages2 packages

NVDoracle/jre1.6.0+3
NVDsun/jre1.4.2_35+38

🔴Vulnerability Details

2
GHSA
GHSA-m25x-m489-rqr9: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, 52022-05-04
CVEList
CVE-2012-0502: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, 52012-02-15

📋Vendor Advisories

3
Ubuntu
OpenJDK 6 (ARM) vulnerabilities2012-03-01
Ubuntu
OpenJDK 6 vulnerabilities2012-02-24
Red Hat
OpenJDK: KeyboardFocusManager focus stealing (AWT, 7110683)2012-02-14

💬Community

1
Bugzilla
CVE-2012-0502 OpenJDK: KeyboardFocusManager focus stealing (AWT, 7110683)2012-02-10
CVE-2012-0502 — Oracle JRE vulnerability | cvebase