CVE-2015-0410Infinite Loop in Oracle JDK

CWE-835Infinite Loop11 documents9 sources
Severity
5.0MEDIUMNVD
EPSS
5.5%
top 9.80%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 21
Latest updateMay 13

Description

Unspecified vulnerability in the Java SE, Java SE Embedded, JRockit component in Oracle Java SE 5.0u75, 6u85, 7u72, and 8u25; Java SE Embedded 7u71 and 8u6; and JRockit R27.8.4 and R28.3.4 allows remote attackers to affect availability via unknown vectors related to Security.

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9

Affected Packages6 packages

NVDoracle/jrockitr27.8.4, r28.3.4+1
NVDoracle/jdk4 versions+3
NVDoracle/jre4 versions+3

Also affects: Debian Linux 7.0, 8.0, Ubuntu Linux 10.04, 12.04, 14.04, 14.10, Enterprise Linux 5.0, 6.0, 7.0

Patches

🔴Vulnerability Details

3
GHSA
GHSA-52j6-f8wf-g688: Unspecified vulnerability in the Java SE, Java SE Embedded, JRockit component in Oracle Java SE 52022-05-13
OSV
CVE-2015-0410: Unspecified vulnerability in the Java SE, Java SE Embedded, JRockit component in Oracle Java SE 52015-01-21
CVEList
CVE-2015-0410: Unspecified vulnerability in the Java SE, Java SE Embedded, JRockit component in Oracle Java SE 52015-01-21

📋Vendor Advisories

5
Android
CVE-2015-0410: Android Security Bulletin 2016-11-01 CVE: CVE-2015-0410 Severity: HIGH Affected AOSP versions: 72016-11-01
Ubuntu
OpenJDK 7 vulnerabilities2015-01-28
Ubuntu
OpenJDK 6 vulnerabilities2015-01-27
Red Hat
OpenJDK: DER decoder infinite loop (Security, 8059485)2015-01-20
Debian
CVE-2015-0410: openjdk-8 - Unspecified vulnerability in the Java SE, Java SE Embedded, JRockit component in...2015

💬Community

2
Bugzilla
pcre: Buffer overflow caused by certain patterns with an unmatched closing parenthesis (8.38/18)2015-12-02
Bugzilla
CVE-2015-0410 OpenJDK: DER decoder infinite loop (Security, 8059485)2015-01-16
CVE-2015-0410 — Infinite Loop in Oracle JDK | cvebase