CVE-2015-0460
published 2015-04-16CVE-2015-0460: Unspecified vulnerability in Oracle Java SE 5.0u81, 6u91, 7u76, and 8u40 allows remote attackers to affect confidentiality, integrity, and availability via…
critical9.3CVSS 3.1
AVNACMAuNCCICAC
Unspecified vulnerability in Oracle Java SE 5.0u81, 6u91, 7u76, and 8u40 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Hotspot.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | openjdk-8 | < openjdk-8 8u45-b14-1 (sid) | openjdk-8 8u45-b14-1 (sid) |
| oracle | jdk | — | — |
| oracle | jdk | — | — |
| oracle | jdk | — | — |
| oracle | jdk | — | — |
| oracle | jre | — | — |
| oracle | jre | — | — |
| oracle | jre | — | — |
| oracle | jre | — | — |
CVSS provenance
nvd9.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv9.3CRITICAL
Ubuntu
OpenJDK 6 vulnerabilities
vendor_ubuntu·2015-04-21·CVSS 9.3
CVE-2015-0460 [CRITICAL] OpenJDK 6 vulnerabilities
Title: OpenJDK 6 vulnerabilities
Summary: Several security issues were fixed in OpenJDK 6.
Several vulnerabilities were discovered in the OpenJDK JRE related to
information disclosure, data integrity and availability. An attacker
could exploit these to cause a denial of service or expose sensitive
data over the network. (CVE-2015-0460, CVE-2015-0469)
Alexander Cherepanov discovered that OpenJDK JRE was vulnerable to
directory traversal issues with respect to handling jar files. An
attacker could use this to expose sensitive data. (CVE-2015-0480)
Florian Weimer discovered that the RSA implementation in the JCE
component in OpenJDK JRE did not follow recommended practices for
implementing RSA signatures. An attacker could use this to expose
sensitive data. (CVE-2015-0478)
A vulnerabilit
Ubuntu
OpenJDK 7 vulnerabilities
vendor_ubuntu·2015-04-21·CVSS 9.3
CVE-2015-0460 [CRITICAL] OpenJDK 7 vulnerabilities
Title: OpenJDK 7 vulnerabilities
Summary: Several security issues were fixed in OpenJDK 7.
Several vulnerabilities were discovered in the OpenJDK JRE related to
information disclosure, data integrity and availability. An attacker
could exploit these to cause a denial of service or expose sensitive
data over the network. (CVE-2015-0460, CVE-2015-0469)
Alexander Cherepanov discovered that OpenJDK JRE was vulnerable to
directory traversal issues with respect to handling jar files. An
attacker could use this to expose sensitive data. (CVE-2015-0480)
Florian Weimer discovered that the RSA implementation in the JCE
component in OpenJDK JRE did not follow recommended practices for
implementing RSA signatures. An attacker could use this to expose
sensitive data. (CVE-2015-0478)
A vulnerabilit
Red Hat
OpenJDK: incorrect handling of phantom references (Hotspot, 8071931)
vendor_redhat·2015-04-14·CVSS 9.3
CVE-2015-0460 [CRITICAL] OpenJDK: incorrect handling of phantom references (Hotspot, 8071931)
OpenJDK: incorrect handling of phantom references (Hotspot, 8071931)
Unspecified vulnerability in Oracle Java SE 5.0u81, 6u91, 7u76, and 8u40 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Hotspot.
A flaw was found in the way the Hotspot component in OpenJDK handled phantom references. An untrusted Java application or applet could use this flaw to corrupt the Java Virtual Machine memory and, possibly, execute arbitrary code, bypassing Java sandbox restrictions.
Debian
CVE-2015-0460: openjdk-8 - Unspecified vulnerability in Oracle Java SE 5.0u81, 6u91, 7u76, and 8u40 allows ...
vendor_debian·2015·CVSS 9.3
CVE-2015-0460 [CRITICAL] CVE-2015-0460: openjdk-8 - Unspecified vulnerability in Oracle Java SE 5.0u81, 6u91, 7u76, and 8u40 allows ...
Unspecified vulnerability in Oracle Java SE 5.0u81, 6u91, 7u76, and 8u40 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Hotspot.
Scope: local
sid: resolved (fixed in 8u45-b14-1)
GHSA
GHSA-hc84-v6qx-7xrf: Unspecified vulnerability in Oracle Java SE 5
ghsa_unreviewed·2022-05-13
CVE-2015-0460 [HIGH] GHSA-hc84-v6qx-7xrf: Unspecified vulnerability in Oracle Java SE 5
Unspecified vulnerability in Oracle Java SE 5.0u81, 6u91, 7u76, and 8u40 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Hotspot.
OSV
openjdk-7 vulnerabilities
osv·2015-04-21·CVSS 9.3
CVE-2015-0460 [CRITICAL] openjdk-7 vulnerabilities
openjdk-7 vulnerabilities
Several vulnerabilities were discovered in the OpenJDK JRE related to
information disclosure, data integrity and availability. An attacker
could exploit these to cause a denial of service or expose sensitive
data over the network. (CVE-2015-0460, CVE-2015-0469)
Alexander Cherepanov discovered that OpenJDK JRE was vulnerable to
directory traversal issues with respect to handling jar files. An
attacker could use this to expose sensitive data. (CVE-2015-0480)
Florian Weimer discovered that the RSA implementation in the JCE
component in OpenJDK JRE did not follow recommended practices for
implementing RSA signatures. An attacker could use this to expose
sensitive data. (CVE-2015-0478)
A vulnerability was discovered in the OpenJDK JRE related to data
integrity. An
OSV
CVE-2015-0460: Unspecified vulnerability in Oracle Java SE 5
osv·2015-04-15·CVSS 9.3
CVE-2015-0460 [CRITICAL] CVE-2015-0460: Unspecified vulnerability in Oracle Java SE 5
Unspecified vulnerability in Oracle Java SE 5.0u81, 6u91, 7u76, and 8u40 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Hotspot.
No detection rules found.
No public exploits indexed.
http://advisories.mageia.org/MGASA-2015-0158.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-04/msg00017.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-04/msg00018.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-05/msg00002.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0806.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0807.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0808.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0809.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0854.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0857.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0858.htmlhttp://www.debian.org/security/2015/dsa-3234http://www.debian.org/security/2015/dsa-3235http://www.debian.org/security/2015/dsa-3316http://www.mandriva.com/security/advisories?name=MDVSA-2015:212http://www.oracle.com/technetwork/topics/security/cpuapr2015-2365600.htmlhttp://www.securityfocus.com/bid/74097http://www.securitytracker.com/id/1032120http://www.ubuntu.com/usn/USN-2573-1http://www.ubuntu.com/usn/USN-2574-1https://security.gentoo.org/glsa/201603-11http://advisories.mageia.org/MGASA-2015-0158.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-04/msg00017.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-04/msg00018.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-05/msg00002.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0806.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0807.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0808.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0809.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0854.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0857.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0858.htmlhttp://www.debian.org/security/2015/dsa-3234http://www.debian.org/security/2015/dsa-3235http://www.debian.org/security/2015/dsa-3316http://www.mandriva.com/security/advisories?name=MDVSA-2015:212http://www.oracle.com/technetwork/topics/security/cpuapr2015-2365600.htmlhttp://www.securityfocus.com/bid/74097http://www.securitytracker.com/id/1032120http://www.ubuntu.com/usn/USN-2573-1http://www.ubuntu.com/usn/USN-2574-1https://security.gentoo.org/glsa/201603-11
2015-04-16
Published