CVE-2012-0505Oracle JRE vulnerability

7 documents6 sources
Severity
7.5HIGHNVD
EPSS
2.0%
top 16.38%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 15
Latest updateMay 4

Description

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, 5 Update 33 and earlier, and 1.4.2_35 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality, integrity, and availability via unknown vectors related to Serialization.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4

Affected Packages2 packages

NVDoracle/jre1.6.0+3
NVDsun/jre1.4.2_35+38

🔴Vulnerability Details

2
GHSA
GHSA-265h-j3mg-7rf9: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, 5 Update2022-05-04
CVEList
CVE-2012-0505: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, 5 Update2012-02-15

📋Vendor Advisories

3
Ubuntu
OpenJDK 6 (ARM) vulnerabilities2012-03-01
Ubuntu
OpenJDK 6 vulnerabilities2012-02-24
Red Hat
OpenJDK: incomplete info in the deserialization exception (Serialization, 7110700)2012-02-14

💬Community

1
Bugzilla
CVE-2012-0505 OpenJDK: incomplete info in the deserialization exception (Serialization, 7110700)2012-02-10
CVE-2012-0505 — Oracle JRE vulnerability | cvebase