CVE-2015-2590
published 2015-07-16CVE-2015-2590: Unspecified vulnerability in Oracle Java SE 6u95, 7u80, and 8u45, and Java SE Embedded 7u75 and 8u33 allows remote attackers to affect confidentiality…
PriorityP189critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2022-03-24
Exploited in the wild
EPSS
25.47%
97.7th percentile
Unspecified vulnerability in Oracle Java SE 6u95, 7u80, and 8u45, and Java SE Embedded 7u75 and 8u33 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries, a different vulnerability than CVE-2015-4732.
Affected
66 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | openjdk-8 | < openjdk-8 8u66-b01-1 (sid) | openjdk-8 8u66-b01-1 (sid) |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| oracle | jdk | — | — |
| oracle | jdk | — | — |
| oracle | jdk | — | — |
| oracle | jre | — | — |
| oracle | jre | — | — |
| oracle | jre | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_for_ibm_z_systems | — | — |
Detection & IOCsextracted from sources · hover to see the quote
path/PhantomSuper.class
snort
alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ET MALWARE Possible Java/Downloader Observed in Pawn Storm CVE-2015-2590 1"; flow:established,to_server; http.method; content:"GET"; http.uri; content:"/PhantomSuper.class"; fast_pattern; http.header; content:"Java/"; http.header_names; to_lowercase; content:!"\|0d 0a\|referer\|0d 0a\|"; reference:url,blog.trendmicro.com/trendlabs-security-intelligence/an-in-depth-look-at-how-pawn-storms-java-zero-day-was-used/; classtype:trojan-activity; sid:2021557; rev:4; metadata:created_at 2015_07_31, cve CVE_2015_2590, confidence Medium, signature_severity Major, tag CISA_KEV, updated_at 2024_04_20;)
- →Exploit delivery involves an HTTP GET request to fetch '/PhantomSuper.class' — a malicious Java class file associated with the Pawn Storm campaign exploiting CVE-2015-2590. Network detection should alert on outbound GET requests for this URI path.
- →Exploit traffic is identifiable by the presence of a 'Java/' string in HTTP request headers (User-Agent or similar), combined with the absence of a Referer header — indicating a direct, non-browser-initiated Java class fetch.
- →The root cause is a deserialization issue in ObjectInputStream.readSerialData() (bug 8076401). Detection of untrusted Java deserialization payloads targeting the Libraries component is relevant.
- ·The Emergent Threats (ET) Snort rule (sid:2021557) targets outbound traffic from $HOME_NET to $EXTERNAL_NET. Ensure HOME_NET is correctly scoped to your environment to avoid missed detections on internal lateral movement.
- ·The vulnerability is described as 'unspecified' with 'unknown vectors' by Oracle, meaning behavioral/network indicators (like the PhantomSuper.class fetch) from observed campaigns are the primary detection surface rather than a fully documented exploit mechanism.
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv9.8CRITICAL
vulncheck9.8CRITICAL
cisa9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
vendor_ubuntu9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Oracle Java SE 6u95/7u80/8u45 Library information disclosure (RHSA-2015:1229 / Nessus ID 84930)
vuldb·2026-04-22·CVSS 9.8
CVE-2015-2590 [CRITICAL] Oracle Java SE 6u95/7u80/8u45 Library information disclosure (RHSA-2015:1229 / Nessus ID 84930)
A vulnerability described as critical has been identified in Oracle Java SE 6u95/7u80/8u45. The impacted element is an unknown function of the component Library Handler. The manipulation results in information disclosure.
This vulnerability was named CVE-2015-2590. The attack may be performed from remote. In addition, an exploit is available.
GHSA
GHSA-mhp7-xhx6-9x45: Unspecified vulnerability in Oracle Java SE 6u95, 7u80, and 8u45, and Java SE Embedded 7u75 and 8u33 allows remote attackers to affect confidentiality
ghsa_unreviewed·2022-05-13·CVSS 10.0
CVE-2015-2590 [CRITICAL] GHSA-mhp7-xhx6-9x45: Unspecified vulnerability in Oracle Java SE 6u95, 7u80, and 8u45, and Java SE Embedded 7u75 and 8u33 allows remote attackers to affect confidentiality
Unspecified vulnerability in Oracle Java SE 6u95, 7u80, and 8u45, and Java SE Embedded 7u75 and 8u33 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries, a different vulnerability than CVE-2015-4732.
GHSA
GHSA-h7cx-3rw4-cg8f: Unspecified vulnerability in Oracle Java SE 6u95, 7u80, and 8u45, and Java SE Embedded 7u75 and 8u33 allows remote attackers to affect confidentiality
ghsa_unreviewed·2022-05-13·CVSS 9.8
CVE-2015-4732 [CRITICAL] GHSA-h7cx-3rw4-cg8f: Unspecified vulnerability in Oracle Java SE 6u95, 7u80, and 8u45, and Java SE Embedded 7u75 and 8u33 allows remote attackers to affect confidentiality
Unspecified vulnerability in Oracle Java SE 6u95, 7u80, and 8u45, and Java SE Embedded 7u75 and 8u33 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries, a different vulnerability than CVE-2015-2590.
OSV
openjdk-7 vulnerabilities
osv·2015-07-30·CVSS 9.8
CVE-2015-2590 [CRITICAL] openjdk-7 vulnerabilities
openjdk-7 vulnerabilities
Several vulnerabilities were discovered in the OpenJDK JRE related to
information disclosure, data integrity, and availability. An attacker
could exploit these to cause a denial of service or expose sensitive
data over the network. (CVE-2015-2590, CVE-2015-2628, CVE-2015-4731,
CVE-2015-4732, CVE-2015-4733, CVE-2015-4760, CVE-2015-4748)
Several vulnerabilities were discovered in the cryptographic components
of the OpenJDK JRE. An attacker could exploit these to expose sensitive
data over the network. (CVE-2015-2601, CVE-2015-2808, CVE-2015-4000,
CVE-2015-2625, CVE-2015-2613)
As a security improvement, this update modifies OpenJDK behavior to
disable RC4 TLS/SSL cipher suites by default.
As a security improvement, this update modifies OpenJDK behavior to
reject
OSV
CVE-2015-2590: Unspecified vulnerability in Oracle Java SE 6u95, 7u80, and 8u45, and Java SE Embedded 7u75 and 8u33 allows remote attackers to affect confidentiality
osv·2015-07-16·CVSS 9.8
CVE-2015-2590 [CRITICAL] CVE-2015-2590: Unspecified vulnerability in Oracle Java SE 6u95, 7u80, and 8u45, and Java SE Embedded 7u75 and 8u33 allows remote attackers to affect confidentiality
Unspecified vulnerability in Oracle Java SE 6u95, 7u80, and 8u45, and Java SE Embedded 7u75 and 8u33 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries, a different vulnerability than CVE-2015-4732.
OSV
CVE-2015-4732: Unspecified vulnerability in Oracle Java SE 6u95, 7u80, and 8u45, and Java SE Embedded 7u75 and 8u33 allows remote attackers to affect confidentiality
osv·2015-07-16·CVSS 9.8
CVE-2015-4732 [CRITICAL] CVE-2015-4732: Unspecified vulnerability in Oracle Java SE 6u95, 7u80, and 8u45, and Java SE Embedded 7u75 and 8u33 allows remote attackers to affect confidentiality
Unspecified vulnerability in Oracle Java SE 6u95, 7u80, and 8u45, and Java SE Embedded 7u75 and 8u33 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries, a different vulnerability than CVE-2015-2590.
VulnCheck
Oracle Java SE and Java SE Embedded Remote Code Execution Vulnerability
vulncheck·2015·CVSS 9.8
CVE-2015-2590 [CRITICAL] Oracle Java SE and Java SE Embedded Remote Code Execution Vulnerability
Oracle Java SE and Java SE Embedded Remote Code Execution Vulnerability
An unspecified vulnerability exists within Oracle Java Runtime Environment that allows an attacker to perform remote code execution.
Affected: Oracle Java SE
Required Action: Apply updates per vendor instructions.
Exploitation References: https://docs.google.com/spreadsheets/d/1lkNJ0uQwbeC1ZTRrxdtuPLCIl7mlUreoKfSIgajnSyY/edit; https://securelist.com/sofacy-apt-hits-high-profile-targets-with-updated-toolset/72924/; https://www.recordedfuture.com/russian-apt-toolkits; https://marcoramilli.com/2019/12/05/apt28-attacks-evolution/; https://dl.acm.org/doi/pdf/10.1145/3465481.3465758; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; https://strapi.eurepoc.eu/uploads/Eu_Repo_C_APT_profil
CISA
Oracle Java SE and Java SE Embedded Remote Code Execution Vulnerability
cisa·2022-03-03·CVSS 9.8
CVE-2015-2590 [CRITICAL] Oracle Java SE and Java SE Embedded Remote Code Execution Vulnerability
Vulnerability: Oracle Java SE and Java SE Embedded Remote Code Execution Vulnerability
Affected: Oracle Java SE
An unspecified vulnerability exists within Oracle Java Runtime Environment that allows an attacker to perform remote code execution.
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2015-2590
Remediation Due Date: 2022-03-24
Ubuntu
OpenJDK 6 vulnerabilities
vendor_ubuntu·2015-08-06·CVSS 9.8
CVE-2015-2590 [CRITICAL] OpenJDK 6 vulnerabilities
Title: OpenJDK 6 vulnerabilities
Summary: Several security issues were fixed in OpenJDK 6.
Several vulnerabilities were discovered in the OpenJDK JRE related to
information disclosure, data integrity, and availability. An attacker
could exploit these to cause a denial of service or expose sensitive
data over the network. (CVE-2015-2590, CVE-2015-2628, CVE-2015-4731,
CVE-2015-4732, CVE-2015-4733, CVE-2015-4760, CVE-2015-4748)
Several vulnerabilities were discovered in the cryptographic components
of the OpenJDK JRE. An attacker could exploit these to expose sensitive
data over the network. (CVE-2015-2601, CVE-2015-2808, CVE-2015-4000,
CVE-2015-2625, CVE-2015-2613)
As a security improvement, this update modifies OpenJDK behavior to
disable RC4 TLS/SSL cipher suites by default.
As a secu
Ubuntu
OpenJDK 7 vulnerabilities
vendor_ubuntu·2015-07-30·CVSS 9.8
CVE-2015-2808 [CRITICAL] OpenJDK 7 vulnerabilities
Title: OpenJDK 7 vulnerabilities
Summary: Several security issues were fixed in OpenJDK 7.
Several vulnerabilities were discovered in the OpenJDK JRE related to
information disclosure, data integrity, and availability. An attacker
could exploit these to cause a denial of service or expose sensitive
data over the network. (CVE-2015-2590, CVE-2015-2628, CVE-2015-4731,
CVE-2015-4732, CVE-2015-4733, CVE-2015-4760, CVE-2015-4748)
Several vulnerabilities were discovered in the cryptographic components
of the OpenJDK JRE. An attacker could exploit these to expose sensitive
data over the network. (CVE-2015-2601, CVE-2015-2808, CVE-2015-4000,
CVE-2015-2625, CVE-2015-2613)
As a security improvement, this update modifies OpenJDK behavior to
disable RC4 TLS/SSL cipher suites by default.
As a secu
Ubuntu
OpenJDK 7 vulnerabilities
vendor_ubuntu·2015-07-30·CVSS 9.8
CVE-2015-2613 [CRITICAL] OpenJDK 7 vulnerabilities
Title: OpenJDK 7 vulnerabilities
Summary: openjdk-7 vulnerabilities
Several vulnerabilities were discovered in the OpenJDK JRE related to
information disclosure, data integrity, and availability. An attacker
could exploit these to cause a denial of service or expose sensitive
data over the network. (CVE-2015-2590, CVE-2015-2628, CVE-2015-4731,
CVE-2015-4732, CVE-2015-4733, CVE-2015-4760, CVE-2015-4748)
Several vulnerabilities were discovered in the cryptographic components
of the OpenJDK JRE. An attacker could exploit these to expose sensitive
data over the network. (CVE-2015-2601, CVE-2015-2808, CVE-2015-4000,
CVE-2015-2625, CVE-2015-2613)
As a security improvement, this update modifies OpenJDK behavior to
disable RC4 TLS/SSL cipher suites by default.
As a security improvement, this
Red Hat
OpenJDK: insufficient context checks during object deserialization (Libraries, 8076405)
vendor_redhat·2015-07-14·CVSS 9.8
CVE-2015-4732 [CRITICAL] CWE-567 OpenJDK: insufficient context checks during object deserialization (Libraries, 8076405)
OpenJDK: insufficient context checks during object deserialization (Libraries, 8076405)
Unspecified vulnerability in Oracle Java SE 6u95, 7u80, and 8u45, and Java SE Embedded 7u75 and 8u33 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries, a different vulnerability than CVE-2015-2590.
Red Hat
OpenJDK: deserialization issue in ObjectInputStream.readSerialData() (Libraries, 8076401)
vendor_redhat·2015-07-14·CVSS 9.8
CVE-2015-2590 [CRITICAL] OpenJDK: deserialization issue in ObjectInputStream.readSerialData() (Libraries, 8076401)
OpenJDK: deserialization issue in ObjectInputStream.readSerialData() (Libraries, 8076401)
Unspecified vulnerability in Oracle Java SE 6u95, 7u80, and 8u45, and Java SE Embedded 7u75 and 8u33 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries, a different vulnerability than CVE-2015-4732.
Debian
CVE-2015-2590: openjdk-8 - Unspecified vulnerability in Oracle Java SE 6u95, 7u80, and 8u45, and Java SE Em...
vendor_debian·2015·CVSS 9.8
CVE-2015-2590 [CRITICAL] CVE-2015-2590: openjdk-8 - Unspecified vulnerability in Oracle Java SE 6u95, 7u80, and 8u45, and Java SE Em...
Unspecified vulnerability in Oracle Java SE 6u95, 7u80, and 8u45, and Java SE Embedded 7u75 and 8u33 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries, a different vulnerability than CVE-2015-4732.
Scope: local
sid: resolved (fixed in 8u66-b01-1)
Debian
CVE-2015-4732: openjdk-8 - Unspecified vulnerability in Oracle Java SE 6u95, 7u80, and 8u45, and Java SE Em...
vendor_debian·2015·CVSS 9.8
CVE-2015-4732 [CRITICAL] CVE-2015-4732: openjdk-8 - Unspecified vulnerability in Oracle Java SE 6u95, 7u80, and 8u45, and Java SE Em...
Unspecified vulnerability in Oracle Java SE 6u95, 7u80, and 8u45, and Java SE Embedded 7u75 and 8u33 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries, a different vulnerability than CVE-2015-2590.
Scope: local
sid: resolved (fixed in 8u66-b01-1)
Suricata
ET MALWARE Possible Java/Downloader Observed in Pawn Storm CVE-2015-2590 1
suricata·2015-07-31·CVSS 9.8
CVE-2015-2590 [CRITICAL] ET MALWARE Possible Java/Downloader Observed in Pawn Storm CVE-2015-2590 1
ET MALWARE Possible Java/Downloader Observed in Pawn Storm CVE-2015-2590 1
Rule: alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ET MALWARE Possible Java/Downloader Observed in Pawn Storm CVE-2015-2590 1"; flow:established,to_server; http.method; content:"GET"; http.uri; content:"/PhantomSuper.class"; fast_pattern; http.header; content:"Java/"; http.header_names; to_lowercase; content:!"|0d 0a|referer|0d 0a|"; reference:url,blog.trendmicro.com/trendlabs-security-intelligence/an-in-depth-look-at-how-pawn-storms-java-zero-day-was-used/; classtype:trojan-activity; sid:2021557; rev:4; metadata:created_at 2015_07_31, cve CVE_2015_2590, confidence Medium, signature_severity Major, tag CISA_KEV, updated_at 2024_04_20;)
Suricata
ET MALWARE Possible Java/Downloader Observed in Pawn Storm CVE-2015-2590 2
suricata·2015-07-31·CVSS 9.8
CVE-2015-2590 [CRITICAL] ET MALWARE Possible Java/Downloader Observed in Pawn Storm CVE-2015-2590 2
ET MALWARE Possible Java/Downloader Observed in Pawn Storm CVE-2015-2590 2
Rule: alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ET MALWARE Possible Java/Downloader Observed in Pawn Storm CVE-2015-2590 2"; flow:established,to_server; http.method; content:"GET"; http.uri; content:"/ArrayReplace.class"; fast_pattern; http.header; content:"Java/"; http.header_names; to_lowercase; content:!"|0d 0a|referer|0d 0a|"; reference:url,blog.trendmicro.com/trendlabs-security-intelligence/an-in-depth-look-at-how-pawn-storms-java-zero-day-was-used/; classtype:trojan-activity; sid:2021558; rev:4; metadata:created_at 2015_07_31, cve CVE_2015_2590, confidence Medium, signature_severity Major, tag CISA_KEV, updated_at 2024_04_20;)
No public exploits indexed.
arXiv
Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures
arxiv_fulltext·2025-02-12
Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures
Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures
Almuthanna Alageel
and
Sergio Maffeis
Department of Computing
Imperial College London
London, United Kingdom
plain
plain
## Abstract
The scarcity of data and the high complexity of Advanced Persistent Threats (APTs) attacks have created challenges in comprehending their behavior and hindered the exploration of effective detection techniques.
To create an effective APT detection strategy, it is important to examine the Tactics, Techniques, and Procedures (TTPs) that have been reported by the industry. These TTPs can be difficult to classify as either malicious or legitimate. When developing an approach for the next generation of network intrusion detection systems (NIDS), it is necessary to
Qualys
Update2: Patch Tuesday July 2015 | Qualys
blogs_qualys·2015-07-14·CVSS 9.8
[CRITICAL] Update2: Patch Tuesday July 2015 | Qualys
Update2: Microsoft released a critical bulletin MS15-078 for a font problem that affects all versions of Windows and allows Remote Code Execution. Microsoft credits Google’s Project Zero, Fireeye and TrendMicro. TrendMicro indicates that the vulnerability came out of the HackingTeam data breach. Google’s entry for the bug indicates that they are aware of exploit code avaliable in the wild, which explains Microsoft’s out-of-band release. Patch as quickly as possible.
Update : Oracle’s CPU July 2015 fixes the 0-day vulnerability CVE-2015-2590 in Java reported by Trend Micro. We recommend treating this patch with high priority. Note: if you think you cannot use new Java due to requirements for old versions, have you looked at Oracle’s deployment rulesets?
Original : When we started preparin
Qualys
Update2: Patch Tuesday July 2015 | Qualys
blogs_qualys·2015-07-14·CVSS 9.8
[CRITICAL] Update2: Patch Tuesday July 2015 | Qualys
Update2: Microsoft released a critical bulletin MS15-078 for a font problem that affects all versions of Windows and allows Remote Code Execution. Microsoft credits Google’s Project Zero, Fireeye and TrendMicro. TrendMicro indicates that the vulnerability came out of the HackingTeam data breach. Google’s entry for the bug indicates that they are aware of exploit code avaliable in the wild, which explains Microsoft’s out-of-band release. Patch as quickly as possible.
Update: Oracle’s CPU July 2015 fixes the 0-day vulnerability CVE-2015-2590 in Java reported by Trend Micro. We recommend treating this patch with high priority. Note: if you think you cannot use new Java due to requirements for old versions, have you looked at Oracle’s deployment rulesets?
Original: When we started preparing
Bugzilla
CVE-2015-2590 OpenJDK: deserialization issue in ObjectInputStream.readSerialData() (Libraries, 8076401)
bugzilla·2015-07-14·CVSS 9.8
CVE-2015-2590 [CRITICAL] CVE-2015-2590 OpenJDK: deserialization issue in ObjectInputStream.readSerialData() (Libraries, 8076401)
CVE-2015-2590 OpenJDK: deserialization issue in ObjectInputStream.readSerialData() (Libraries, 8076401)
An unspecified flaw was found in the Libraries component in OpenJDK. ObjectInputStream's readSerialData() could, in certain cases, incorrectly perform deserialization of data from serialized input. An untrusted Java application or applet could use this flaw to bypass Java sandbox restrictions.
Discussion:
Public now via Oracle Critical Patch Update - July 2015. Fixed in Oracle Java SE 6u101, 7u85, and 8u51.
External References:
http://www.oracle.com/technetwork/topics/security/cpujul2015-2367936.html#AppendixJAVA
---
According to the TrendMicro blog post, this is the issue that was recently announced as 0-day Java vulnerability exploited as part of the Pawn Storm campaign:
http:/
http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00039.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-07/msg00040.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-07/msg00046.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-07/msg00047.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1228.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1229.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1230.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1241.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1242.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1243.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1485.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1486.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1488.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1526.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1544.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1604.htmlhttp://www.debian.org/security/2015/dsa-3316http://www.debian.org/security/2015/dsa-3339http://www.oracle.com/technetwork/topics/security/cpujul2015-2367936.htmlhttp://www.securityfocus.com/bid/75818http://www.securitytracker.com/id/1032910http://www.ubuntu.com/usn/USN-2696-1http://www.ubuntu.com/usn/USN-2706-1https://security.gentoo.org/glsa/201603-11https://security.gentoo.org/glsa/201603-14http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00039.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-07/msg00040.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-07/msg00046.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-07/msg00047.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1228.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1229.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1230.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1241.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1242.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1243.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1485.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1486.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1488.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1526.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1544.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1604.htmlhttp://www.debian.org/security/2015/dsa-3316http://www.debian.org/security/2015/dsa-3339http://www.oracle.com/technetwork/topics/security/cpujul2015-2367936.htmlhttp://www.securityfocus.com/bid/75818http://www.securitytracker.com/id/1032910http://www.ubuntu.com/usn/USN-2696-1http://www.ubuntu.com/usn/USN-2706-1https://security.gentoo.org/glsa/201603-11https://security.gentoo.org/glsa/201603-14https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2015-2590
2015-07-16
Published
2022-03-03
Added to CISA KEV
Exploited in the wild