CVE-2015-0410
published 2015-01-21CVE-2015-0410: Unspecified vulnerability in the Java SE, Java SE Embedded, JRockit component in Oracle Java SE 5.0u75, 6u85, 7u72, and 8u25; Java SE Embedded 7u71 and 8u6…
PriorityP429medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
5.03%
91.3th percentile
Unspecified vulnerability in the Java SE, Java SE Embedded, JRockit component in Oracle Java SE 5.0u75, 6u85, 7u72, and 8u25; Java SE Embedded 7u71 and 8u6; and JRockit R27.8.4 and R28.3.4 allows remote attackers to affect availability via unknown vectors related to Security.
Affected
24 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | openjdk-8 | < openjdk-8 8u40~b22-1 (sid) | openjdk-8 8u40~b22-1 (sid) |
| android | — | — | |
| novell | suse_linux_enterprise_desktop | — | — |
| novell | suse_linux_enterprise_server | — | — |
| opensuse | opensuse | — | — |
| oracle | jdk | — | — |
| oracle | jdk | — | — |
| oracle | jdk | — | — |
| oracle | jdk | — | — |
| oracle | jre | — | — |
| oracle | jre | — | — |
| oracle | jre | — | — |
| oracle | jre | — | — |
| oracle | jrockit | — | — |
| oracle | jrockit | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
vendor_ubuntu3.4LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-52j6-f8wf-g688: Unspecified vulnerability in the Java SE, Java SE Embedded, JRockit component in Oracle Java SE 5
ghsa_unreviewed·2022-05-13
CVE-2015-0410 [MEDIUM] GHSA-52j6-f8wf-g688: Unspecified vulnerability in the Java SE, Java SE Embedded, JRockit component in Oracle Java SE 5
Unspecified vulnerability in the Java SE, Java SE Embedded, JRockit component in Oracle Java SE 5.0u75, 6u85, 7u72, and 8u25; Java SE Embedded 7u71 and 8u6; and JRockit R27.8.4 and R28.3.4 allows remote attackers to affect availability via unknown vectors related to Security.
OSV
openjdk-7 vulnerabilities
osv·2015-01-28·CVSS 3.4
CVE-2014-3566 [LOW] openjdk-7 vulnerabilities
openjdk-7 vulnerabilities
Several vulnerabilities were discovered in the OpenJDK JRE related to
information disclosure, data integrity and availability. An attacker could
exploit these to cause a denial of service or expose sensitive data over
the network. (CVE-2014-3566, CVE-2014-6587, CVE-2014-6601, CVE-2015-0395,
CVE-2015-0408, CVE-2015-0412)
Several vulnerabilities were discovered in the OpenJDK JRE related to
information disclosure. An attacker could exploit these to expose sensitive
data over the network. (CVE-2014-6585, CVE-2014-6591, CVE-2015-0400,
CVE-2015-0407)
A vulnerability was discovered in the OpenJDK JRE related to
information disclosure and integrity. An attacker could exploit this to
expose sensitive data over the network. (CVE-2014-6593)
A vulnerability was discovere
OSV
CVE-2015-0410: Unspecified vulnerability in the Java SE, Java SE Embedded, JRockit component in Oracle Java SE 5
osv·2015-01-21·CVSS 5.0
CVE-2015-0410 [MEDIUM] CVE-2015-0410: Unspecified vulnerability in the Java SE, Java SE Embedded, JRockit component in Oracle Java SE 5
Unspecified vulnerability in the Java SE, Java SE Embedded, JRockit component in Oracle Java SE 5.0u75, 6u85, 7u72, and 8u25; Java SE Embedded 7u71 and 8u6; and JRockit R27.8.4 and R28.3.4 allows remote attackers to affect availability via unknown vectors related to Security.
Android
CVE-2015-0410: Android Security Bulletin 2016-11-01
CVE: CVE-2015-0410
Severity: HIGH
Affected AOSP versions: 7
vendor_android·2016-11-01·CVSS 5.0
CVE-2015-0410 [MEDIUM] CVE-2015-0410: Android Security Bulletin 2016-11-01
CVE: CVE-2015-0410
Severity: HIGH
Affected AOSP versions: 7
Android Security Bulletin 2016-11-01
CVE: CVE-2015-0410
Severity: HIGH
Affected AOSP versions: 7.0
References: A-30703445
Ubuntu
OpenJDK 7 vulnerabilities
vendor_ubuntu·2015-01-28·CVSS 3.4
CVE-2014-3566 [LOW] OpenJDK 7 vulnerabilities
Title: OpenJDK 7 vulnerabilities
Summary: Several security issues were fixed in OpenJDK 7.
Several vulnerabilities were discovered in the OpenJDK JRE related to
information disclosure, data integrity and availability. An attacker could
exploit these to cause a denial of service or expose sensitive data over
the network. (CVE-2014-3566, CVE-2014-6587, CVE-2014-6601, CVE-2015-0395,
CVE-2015-0408, CVE-2015-0412)
Several vulnerabilities were discovered in the OpenJDK JRE related to
information disclosure. An attacker could exploit these to expose sensitive
data over the network. (CVE-2014-6585, CVE-2014-6591, CVE-2015-0400,
CVE-2015-0407)
A vulnerability was discovered in the OpenJDK JRE related to
information disclosure and integrity. An attacker could exploit this to
expose sensitive dat
Ubuntu
OpenJDK 6 vulnerabilities
vendor_ubuntu·2015-01-27·CVSS 3.4
CVE-2014-3566 [LOW] OpenJDK 6 vulnerabilities
Title: OpenJDK 6 vulnerabilities
Summary: Several security issues were fixed in OpenJDK 6.
Several vulnerabilities were discovered in the OpenJDK JRE related to
information disclosure, data integrity and availability. An attacker could
exploit these to cause a denial of service or expose sensitive data over
the network. (CVE-2014-3566, CVE-2014-6587, CVE-2014-6601, CVE-2015-0395,
CVE-2015-0408, CVE-2015-0412)
Several vulnerabilities were discovered in the OpenJDK JRE related to
information disclosure. An attacker could exploit these to expose sensitive
data over the network. (CVE-2014-6585, CVE-2014-6591, CVE-2015-0400,
CVE-2015-0407)
A vulnerability was discovered in the OpenJDK JRE related to
information disclosure and integrity. An attacker could exploit this to
expose sensitive dat
Red Hat
OpenJDK: DER decoder infinite loop (Security, 8059485)
vendor_redhat·2015-01-20·CVSS 5.0
CVE-2015-0410 [MEDIUM] CWE-835 OpenJDK: DER decoder infinite loop (Security, 8059485)
OpenJDK: DER decoder infinite loop (Security, 8059485)
Unspecified vulnerability in the Java SE, Java SE Embedded, JRockit component in Oracle Java SE 5.0u75, 6u85, 7u72, and 8u25; Java SE Embedded 7u71 and 8u6; and JRockit R27.8.4 and R28.3.4 allows remote attackers to affect availability via unknown vectors related to Security.
A flaw was found in the way the DER (Distinguished Encoding Rules) decoder in the Security component in OpenJDK handled negative length values. A specially crafted, DER-encoded input could cause a Java application to enter an infinite loop when decoded.
Package: java-1.8.0-openjdk (Red Hat Enterprise Linux 7) - Not affected
Package: java-1.8.0-oracle (Red Hat Enterprise Linux 7) - Not affected
Debian
CVE-2015-0410: openjdk-8 - Unspecified vulnerability in the Java SE, Java SE Embedded, JRockit component in...
vendor_debian·2015·CVSS 5.0
CVE-2015-0410 [MEDIUM] CVE-2015-0410: openjdk-8 - Unspecified vulnerability in the Java SE, Java SE Embedded, JRockit component in...
Unspecified vulnerability in the Java SE, Java SE Embedded, JRockit component in Oracle Java SE 5.0u75, 6u85, 7u72, and 8u25; Java SE Embedded 7u71 and 8u6; and JRockit R27.8.4 and R28.3.4 allows remote attackers to affect availability via unknown vectors related to Security.
Scope: local
sid: resolved (fixed in 8u40~b22-1)
No detection rules found.
No public exploits indexed.
Bugzilla
pcre: Buffer overflow caused by certain patterns with an unmatched closing parenthesis (8.38/18)
bugzilla·2015-12-02·CVSS 9.1
CVE-2015-5073 [CRITICAL] pcre: Buffer overflow caused by certain patterns with an unmatched closing parenthesis (8.38/18)
pcre: Buffer overflow caused by certain patterns with an unmatched closing parenthesis (8.38/18)
It was discovered that PCRE before 8.38 mishandles the /(?=di(?
Date: Tue Jun 23 16:34:53 2015 +0000
Fix buffer overflow for forward reference within backward assertion with exc
ess
closing parenthesis. Bugzilla 1651.
git-svn-id: svn://vcs.exim.org/pcre/code/trunk@1571 2f5784b3-3f2a-0410-8824-
cb99058d5e15
---
Is this CVE a duplicate of CVE-2015-5073?
---
I think it is.
---
*** This bug has been marked as a duplicate of bug 1237223 ***
Bugzilla
CVE-2015-0410 OpenJDK: DER decoder infinite loop (Security, 8059485)
bugzilla·2015-01-16·CVSS 5.0
CVE-2015-0410 [MEDIUM] CVE-2015-0410 OpenJDK: DER decoder infinite loop (Security, 8059485)
CVE-2015-0410 OpenJDK: DER decoder infinite loop (Security, 8059485)
A flaw was found in the way the DER (Distinguished Encoding Rules) decoder in the Security component in OpenJDK handled negative length values. A specially crafted DER encoded input could cause a Java application to enter an infinite loop when decoded.
Discussion:
Public now via Oracle Critical Patch Update - January 2015. Fixed in Oracle Java SE 5.0u81, 6u91, 7u75, and 8u31.
External References:
http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html#AppendixJAVA
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 5
Via RHSA-2015:0068 https://rhn.redhat.com/errata/RHSA-2015-0068.html
---
This issue has been addressed in the following products:
Red Hat Enterp
http://h20564.www2.hp.com/hpsc/doc/public/display?docId=emr_na-c04583581http://lists.opensuse.org/opensuse-security-announce/2015-02/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-02/msg00024.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-03/msg00018.htmlhttp://marc.info/?l=bugtraq&m=142496355704097&w=2http://marc.info/?l=bugtraq&m=142607790919348&w=2http://rhn.redhat.com/errata/RHSA-2015-0068.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0079.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0080.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0085.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0086.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0136.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0264.htmlhttp://www.debian.org/security/2015/dsa-3144http://www.debian.org/security/2015/dsa-3147http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.htmlhttp://www.securityfocus.com/bid/72165http://www.securitytracker.com/id/1031580http://www.ubuntu.com/usn/USN-2486-1http://www.ubuntu.com/usn/USN-2487-1http://www.vmware.com/security/advisories/VMSA-2015-0003.htmlhttps://exchange.xforce.ibmcloud.com/vulnerabilities/100151https://kc.mcafee.com/corporate/index?page=content&id=SB10104https://security.gentoo.org/glsa/201507-14https://source.android.com/security/bulletin/2016-11-01.htmlhttps://www-304.ibm.com/support/docview.wss?uid=swg21695474http://h20564.www2.hp.com/hpsc/doc/public/display?docId=emr_na-c04583581http://lists.opensuse.org/opensuse-security-announce/2015-02/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-02/msg00024.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-03/msg00018.htmlhttp://marc.info/?l=bugtraq&m=142496355704097&w=2http://marc.info/?l=bugtraq&m=142607790919348&w=2http://rhn.redhat.com/errata/RHSA-2015-0068.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0079.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0080.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0085.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0086.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0136.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0264.htmlhttp://www.debian.org/security/2015/dsa-3144http://www.debian.org/security/2015/dsa-3147http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.htmlhttp://www.securityfocus.com/bid/72165http://www.securitytracker.com/id/1031580http://www.ubuntu.com/usn/USN-2486-1http://www.ubuntu.com/usn/USN-2487-1http://www.vmware.com/security/advisories/VMSA-2015-0003.htmlhttps://exchange.xforce.ibmcloud.com/vulnerabilities/100151https://kc.mcafee.com/corporate/index?page=content&id=SB10104https://security.gentoo.org/glsa/201507-14https://source.android.com/security/bulletin/2016-11-01.htmlhttps://www-304.ibm.com/support/docview.wss?uid=swg21695474
2015-01-21
Published