CVE-2012-1711
published 2012-06-16CVE-2012-1711: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update 4 and earlier, 6 update 32 and earlier, 5 update 35 and…
PriorityP346high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
2.89%
85.5th percentile
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update 4 and earlier, 6 update 32 and earlier, 5 update 35 and earlier, and 1.4.2_37 and earlier allows remote attackers to affect confidentiality, integrity, and availability, related to CORBA.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | jdk | <= 1.7.0 | — |
| oracle | jdk | <= 1.6.0 | — |
| oracle | jre | <= 1.7.0 | — |
| oracle | jre | <= 1.6.0 | — |
| sun | jdk | <= 1.5.0 | — |
| sun | jdk | <= 1.4.2_37 | — |
| sun | jre | <= 1.5.0 | — |
| sun | jre | <= 1.4.2_37 | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
IcedTea-Web regression
vendor_ubuntu·2012-08-30·CVSS 7.5
[HIGH] IcedTea-Web regression
Title: IcedTea-Web regression
Summary: USN 1505-1 introduced a regression in the IcedTea-Web Java web browser
plugin that prevented it from working with the Chromium web browser.
USN-1505-1 fixed vulnerabilities in OpenJDK 6. As part of the update,
IcedTea-Web packages were upgraded to a new version. That upgrade
introduced a regression which prevented the IcedTea-Web plugin from
working with the Chromium web browser in Ubuntu 11.04 and Ubuntu 11.10.
This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
It was discovered that multiple flaws existed in the CORBA (Common
Object Request Broker Architecture) implementation in OpenJDK. An
attacker could create a Java application or applet that used these
flaws to bypass Java sandbox restrictions or m
Ubuntu
OpenJDK 6 vulnerabilities
vendor_ubuntu·2012-07-13·CVSS 7.5
CVE-2012-1711 [HIGH] OpenJDK 6 vulnerabilities
Title: OpenJDK 6 vulnerabilities
Summary: Several security issues were fixed in OpenJDK 6.
It was discovered that multiple flaws existed in the CORBA (Common
Object Request Broker Architecture) implementation in OpenJDK. An
attacker could create a Java application or applet that used these
flaws to bypass Java sandbox restrictions or modify immutable object
data. (CVE-2012-1711, CVE-2012-1719)
It was discovered that multiple flaws existed in the OpenJDK font
manager's layout lookup implementation. A attacker could specially
craft a font file that could cause a denial of service through
crashing the JVM (Java Virtual Machine) or possibly execute arbitrary
code. (CVE-2012-1713)
It was discovered that the SynthLookAndFeel class from Swing in
OpenJDK did not properly prevent access to cert
Red Hat
OpenJDK: improper protection of CORBA data models (CORBA, 7079902)
vendor_redhat·2012-06-12·CVSS 7.5
CVE-2012-1711 [HIGH] OpenJDK: improper protection of CORBA data models (CORBA, 7079902)
OpenJDK: improper protection of CORBA data models (CORBA, 7079902)
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update 4 and earlier, 6 update 32 and earlier, 5 update 35 and earlier, and 1.4.2_37 and earlier allows remote attackers to affect confidentiality, integrity, and availability, related to CORBA.
GHSA
GHSA-hjww-xjq7-7798: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update 4 and earlier, 6 update 32 and earlier, 5 update
ghsa_unreviewed·2022-05-14
CVE-2012-1711 [HIGH] GHSA-hjww-xjq7-7798: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update 4 and earlier, 6 update 32 and earlier, 5 update
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update 4 and earlier, 6 update 32 and earlier, 5 update 35 and earlier, and 1.4.2_37 and earlier allows remote attackers to affect confidentiality, integrity, and availability, related to CORBA.
No detection rules found.
No public exploits indexed.
http://mail.openjdk.java.net/pipermail/distro-pkg-dev/2012-June/019076.htmlhttp://marc.info/?l=bugtraq&m=134496371727681&w=2http://rhn.redhat.com/errata/RHSA-2012-0734.htmlhttp://security.gentoo.org/glsa/glsa-201406-32.xmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2012:095http://www.oracle.com/technetwork/topics/security/javacpujun2012-1515912.htmlhttp://www.securityfocus.com/bid/53949https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A15996http://mail.openjdk.java.net/pipermail/distro-pkg-dev/2012-June/019076.htmlhttp://marc.info/?l=bugtraq&m=134496371727681&w=2http://rhn.redhat.com/errata/RHSA-2012-0734.htmlhttp://security.gentoo.org/glsa/glsa-201406-32.xmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2012:095http://www.oracle.com/technetwork/topics/security/javacpujun2012-1515912.htmlhttp://www.securityfocus.com/bid/53949https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A15996
2012-06-16
Published