CVE-2012-1724Infinite Loop in Oracle JDK

CWE-835Infinite Loop6 documents6 sources
Severity
5.0MEDIUMNVD
EPSS
2.5%
top 14.67%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 16
Latest updateMay 14

Description

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update 4 and earlier, and 6 update 32 and earlier, allows remote attackers to affect availability, related to JAXP.

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9

Affected Packages4 packages

NVDoracle/jdk1.7.0+3
NVDoracle/jre1.7.0+3
NVDsun/jdk1.6.0
NVDsun/jre1.6.0

🔴Vulnerability Details

2
GHSA
GHSA-j436-w8m4-m9w5: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update 4 and earlier, and 6 update 32 and earlier, allow2022-05-14
CVEList
CVE-2012-1724: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update 4 and earlier, and 6 update 32 and earlier, allow2012-06-16

📋Vendor Advisories

2
Ubuntu
OpenJDK 6 vulnerabilities2012-07-13
Red Hat
OpenJDK: XML parsing infinite loop (JAXP, 7157609)2012-06-12

💬Community

1
Bugzilla
CVE-2012-1724 OpenJDK: XML parsing infinite loop (JAXP, 7157609)2012-06-06
CVE-2012-1724 — Infinite Loop in Oracle JDK | cvebase