CVE-2016-0636

CWE-35812 documents9 sources
Severity
8.1HIGH
EPSS
13.0%
top 5.91%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 24
Latest updateMay 13

Description

Unspecified vulnerability in Oracle Java SE 7u97, 8u73, and 8u74 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to the Hotspot sub-component.

CVSS vector

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 2.2 | Impact: 5.9

Affected Packages8 packages

NVDoracle/jdk1.7.0, 1.8.0+1
NVDoracle/jre1.7.0, 1.8.0+1
Ubuntuopenjdk-7< 7u95-2.6.4-0ubuntu0.14.04.2
NVDredhat/icedtea72.6.6

🔴Vulnerability Details

3
GHSA
GHSA-3wjc-73w5-99qg: Unspecified vulnerability in Oracle Java SE 7u97, 8u73, and 8u74 allows remote attackers to affect confidentiality, integrity, and availability via un2022-05-13
CVEList
CVE-2016-0636: Unspecified vulnerability in Oracle Java SE 7u97, 8u73, and 8u74 allows remote attackers to affect confidentiality, integrity, and availability via un2016-03-24
OSV
CVE-2016-0636: Unspecified vulnerability in Oracle Java SE 7u97, 8u73, and 8u74 allows remote attackers to affect confidentiality, integrity, and availability via un2016-03-23

📋Vendor Advisories

3
Ubuntu
OpenJDK 7 vulnerability2016-03-24
Red Hat
OpenJDK: missing type safety checks for MethodHandle calls across class loaders, incorrect CVE-2013-5838 fix (Hotspot, 8151666)2016-03-23
Debian
CVE-2016-0636: openjdk-8 - Unspecified vulnerability in Oracle Java SE 7u97, 8u73, and 8u74 allows remote a...2016

🕵️Threat Intelligence

4
Qualys
Oracle Critical Patch Update April 2016 | Qualys2016-04-22
Qualys
Oracle Critical Patch Update April 2016 | Qualys2016-04-22
Qualys
Oracle out-of-band release for Java 0-day | Qualys2016-03-24
Qualys
Oracle out-of-band release for Java 0-day | Qualys2016-03-24

💬Community

1
Bugzilla
CVE-2016-0636 OpenJDK: missing type safety checks for MethodHandle calls across class loaders, incorrect CVE-2013-5838 fix (Hotspot, 8151666)2016-03-23
CVE-2016-0636 (HIGH CVSS 8.1) | Unspecified vulnerability in Oracle | cvebase.io