CVE-2015-2619
published 2015-07-16CVE-2015-2619: Unspecified vulnerability in Oracle Java SE 7u80 and 8u45, JavaFX 2.2.80, and Java SE Embedded 7u75 and 8u33 allows remote attackers to affect confidentiality…
PriorityP427medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
3.20%
86.8th percentile
Unspecified vulnerability in Oracle Java SE 7u80 and 8u45, JavaFX 2.2.80, and Java SE Embedded 7u75 and 8u33 allows remote attackers to affect confidentiality via unknown vectors related to 2D.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | openjdk-8 | — | — |
| oracle | javafx | — | — |
| oracle | jdk | — | — |
| oracle | jdk | — | — |
| oracle | jre | — | — |
| oracle | jre | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_debian5.0LOW
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
JDK: unspecified vulnerability fixed in 7u85 and 8u51 (2D)
vendor_redhat·2015-07-14·CVSS 5.0
CVE-2015-2619 [MEDIUM] JDK: unspecified vulnerability fixed in 7u85 and 8u51 (2D)
JDK: unspecified vulnerability fixed in 7u85 and 8u51 (2D)
Unspecified vulnerability in Oracle Java SE 7u80 and 8u45, JavaFX 2.2.80, and Java SE Embedded 7u75 and 8u33 allows remote attackers to affect confidentiality via unknown vectors related to 2D.
Debian
CVE-2015-2619: openjdk-8 - Unspecified vulnerability in Oracle Java SE 7u80 and 8u45, JavaFX 2.2.80, and Ja...
vendor_debian·2015·CVSS 5.0
CVE-2015-2619 [MEDIUM] CVE-2015-2619: openjdk-8 - Unspecified vulnerability in Oracle Java SE 7u80 and 8u45, JavaFX 2.2.80, and Ja...
Unspecified vulnerability in Oracle Java SE 7u80 and 8u45, JavaFX 2.2.80, and Java SE Embedded 7u75 and 8u33 allows remote attackers to affect confidentiality via unknown vectors related to 2D.
Scope: local
sid: resolved
GHSA
GHSA-gfgh-pcg4-5gm7: Unspecified vulnerability in Oracle Java SE 7u80 and 8u45, JavaFX 2
ghsa_unreviewed·2022-05-13
CVE-2015-2619 [MEDIUM] GHSA-gfgh-pcg4-5gm7: Unspecified vulnerability in Oracle Java SE 7u80 and 8u45, JavaFX 2
Unspecified vulnerability in Oracle Java SE 7u80 and 8u45, JavaFX 2.2.80, and Java SE Embedded 7u75 and 8u33 allows remote attackers to affect confidentiality via unknown vectors related to 2D.
Project0
Enabling QR codes in Internet Explorer, or a story of a cross-platform memory disclosure - Project Zero
project_zero·2015-09-01·CVSS 5.0
CVE-2015-0089 [MEDIUM] Enabling QR codes in Internet Explorer, or a story of a cross-platform memory disclosure - Project Zero
Posted by Mateusz Jurczyk of Google Project Zero
In the previous series of posts (parts #1 #2 #3 #4), we discussed the exploitation process of a serious “blend” vulnerability (CVE-2015-0093 / CVE-2015-3052), which was special in that it provided the attacker with an extremely powerful primitive (arbitrary out-of-bounds stack operations) allowing a fully reliable arbitrary remote code execution, and affected both a client-side application – Adobe Reader – and the Microsoft Windows kernel. While that bug was definitely the most severe and technically challenging issue discovered during my Type 1 / OpenType Charstring research conducted several months ago, it was not the only one affecting multiple platforms and certainly not the only interesting one.
In today’s post, I would like to expl
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-5212 libreoffice: Integer underflow in PrinterSetup length
bugzilla·2015-11-06·CVSS 6.8
CVE-2015-5212 [MEDIUM] CVE-2015-5212 libreoffice: Integer underflow in PrinterSetup length
CVE-2015-5212 libreoffice: Integer underflow in PrinterSetup length
It was found that crafted ODF document can be used to create a buffer that is too small for the amount of data loaded into it, allowing an attacker to cause denial of service (memory corruption and application crash) and possible execution of arbitrary code.
Products affected are LibreOffice < 4.4.5 and OpenOffice <= 4.1.1.
External reference:
http://www.libreoffice.org/about-us/security/advisories/cve-2015-5212/
http://www.openoffice.org/security/cves/CVE-2015-5212.html
Discussion:
Created libreoffice tracking bugs for this issue:
Affects: fedora-all [bug 1278821]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Red Hat Enterprise Linux 7
Via RHSA-2015:2619 https://rhn.red
Bugzilla
CVE-2015-5214 libreoffice: Bookmarks in DOC documents are insufficiently checked causing memory corruption
bugzilla·2015-11-06·CVSS 6.8
CVE-2015-5214 [MEDIUM] CVE-2015-5214 libreoffice: Bookmarks in DOC documents are insufficiently checked causing memory corruption
CVE-2015-5214 libreoffice: Bookmarks in DOC documents are insufficiently checked causing memory corruption
It was found that indexes into the bookmark array were insufficiently checked for validity. A document can be constructed which refers to bookmarks that don't exist, causing memory corruption.
Products affected are LibreOffice < 4.4.6 and OpenOffice <= 4.1.1.
External reference:
http://www.libreoffice.org/about-us/security/advisories/cve-2015-5214/
http://www.openoffice.org/security/cves/CVE-2015-5214.html
Discussion:
Created libreoffice tracking bugs for this issue:
Affects: fedora-all [bug 1278829]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Red Hat Enterprise Linux 7
Via RHSA-2015:2619 https://rhn.redhat.com/errata/RHSA-2015-26
Bugzilla
CVE-2015-2619 Oracle JDK: unspecified vulnerability fixed in 7u85 and 8u51 (2D)
bugzilla·2015-07-15·CVSS 5.0
CVE-2015-2619 [MEDIUM] CVE-2015-2619 Oracle JDK: unspecified vulnerability fixed in 7u85 and 8u51 (2D)
CVE-2015-2619 Oracle JDK: unspecified vulnerability fixed in 7u85 and 8u51 (2D)
Oracle Java SE 7u85 and 8u51 fixes an unspecified vulnerability in the 2D component (CVE-2015-2619). Upstream has CVSSv2 scored this issue as: 5.0/AV:N/AC:L/Au:N/C:P/I:N/A:N
External Reference:
http://www.oracle.com/technetwork/topics/security/cpujul2015-2367936.html#AppendixJAVA
Discussion:
This issue has been addressed in the following products:
Oracle Java for Red Hat Enterprise Linux 6
Oracle Java for Red Hat Enterprise Linux 7
Oracle Java for Red Hat Enterprise Linux 5
Via RHSA-2015:1242 https://rhn.redhat.com/errata/RHSA-2015-1242.html
---
This issue has been addressed in the following products:
Oracle Java for Red Hat Enterprise Linux 6
Oracle Java for Red Hat Enterprise Linux 7
Via RHSA-2015:
http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00039.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-07/msg00040.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-07/msg00046.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-07/msg00047.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1241.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1242.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1485.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1488.htmlhttp://www.oracle.com/technetwork/topics/security/cpujul2015-2367936.htmlhttp://www.securityfocus.com/bid/75881http://www.securitytracker.com/id/1032910https://security.gentoo.org/glsa/201603-11http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00039.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-07/msg00040.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-07/msg00046.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-07/msg00047.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1241.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1242.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1485.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1488.htmlhttp://www.oracle.com/technetwork/topics/security/cpujul2015-2367936.htmlhttp://www.securityfocus.com/bid/75881http://www.securitytracker.com/id/1032910https://security.gentoo.org/glsa/201603-11
2015-07-16
Published