CVE-2016-3425 — Oracle JDK vulnerability
12 documents8 sources
Severity
4.3MEDIUMNVD
EPSS
9.1%
top 7.32%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 21
Latest updateMay 13
Description
Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to affect availability via vectors related to JAXP.
CVSS vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:LExploitability: 2.8 | Impact: 1.4
Affected Packages3 packages
🔴Vulnerability Details
5GHSA▶
GHSA-588q-73q3-whvh: Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28↗2022-05-13
CVEList▶
CVE-2016-3425: Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28↗2016-04-21
OSV▶
CVE-2016-3425: Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28↗2016-04-21
📋Vendor Advisories
5Red Hat
▶
Debian▶
CVE-2016-3425: openjdk-8 - Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embed...↗2016
💬Community
1Bugzilla▶
CVE-2016-3425 OpenJDK: incorrect handling of surrogate pairs in XML attribute values (JAXP, 8143167)↗2016-04-18