cbcvebase.
CVE-2015-4843
published 2015-10-21

CVE-2015-4843: Unspecified vulnerability in Oracle Java SE 6u101, 7u85, and 8u60, and Java SE Embedded 8u51, allows remote attackers to affect confidentiality, integrity, and…

PriorityP357critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
9.99%
95.1th percentile
Unspecified vulnerability in Oracle Java SE 6u101, 7u85, and 8u60, and Java SE Embedded 8u51, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries.

Affected

7 ranges
VendorProductVersion rangeFixed in
debianopenjdk-8< openjdk-8 8u66-b17-1 (sid)openjdk-8 8u66-b17-1 (sid)
oraclejdk
oraclejdk
oraclejdk
oraclejre
oraclejre
oraclejre

Detection & IOCsextracted from sources · hover to see the quote

  • Vulnerability resides in java.nio Buffers (Non-blocking I/O) implementation within the Libraries component of OpenJDK/Oracle Java SE; look for untrusted Java applet or application execution triggering integer overflow in Buffer operations leading to out-of-bounds memory access or JVM memory corruption
  • Affected versions for triage/detection scope: Oracle Java SE 6u101, 7u85, 8u60, and Java SE Embedded 8u51; fixed in Oracle Java SE 6u105, 7u91, and 8u65 — flag systems still running vulnerable versions
  • OpenJDK upstream patch commit for this issue can be used to diff vulnerable vs. patched Buffer code for YARA/binary signature development
  • ·Vulnerability details are unspecified by Oracle; attack vectors are described as 'unknown', limiting precise detection rule creation beyond version-based identification
  • ·Debian scoped this as 'local' impact, which may differ from Oracle's 'remote' classification — detection posture should account for both local and remote exploitation scenarios

CVSS provenance

nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv10.0CRITICAL
vendor_debian10.0CRITICAL
vendor_redhat10.0CRITICAL
vendor_ubuntu5.0MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.