CVE-2016-3426Oracle JDK vulnerability

9 documents8 sources
Severity
3.1LOWNVD
OSV9.6
EPSS
1.6%
top 18.29%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 21
Latest updateMay 13

Description

Unspecified vulnerability in Oracle Java SE 8u77 and Java SE Embedded 8u77 allows remote attackers to affect confidentiality via vectors related to JCE.

CVSS vector

CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:NExploitability: 1.6 | Impact: 1.4

Affected Packages2 packages

NVDoracle/jdk1.8.0
NVDoracle/jre1.8.0

🔴Vulnerability Details

4
GHSA
GHSA-3mj4-w4vq-39pp: Unspecified vulnerability in Oracle Java SE 8u77 and Java SE Embedded 8u77 allows remote attackers to affect confidentiality via vectors related to JC2022-05-13
OSV
openjdk-8 vulnerabilities2016-05-05
OSV
CVE-2016-3426: Unspecified vulnerability in Oracle Java SE 8u77 and Java SE Embedded 8u77 allows remote attackers to affect confidentiality via vectors related to JC2016-04-21
CVEList
CVE-2016-3426: Unspecified vulnerability in Oracle Java SE 8u77 and Java SE Embedded 8u77 allows remote attackers to affect confidentiality via vectors related to JC2016-04-21

📋Vendor Advisories

3
Ubuntu
OpenJDK 8 vulnerabilities2016-05-05
Red Hat
OpenJDK: non-constant time GCM authentication tag comparison (JCE, 8143945)2016-04-19
Debian
CVE-2016-3426: openjdk-8 - Unspecified vulnerability in Oracle Java SE 8u77 and Java SE Embedded 8u77 allow...2016

💬Community

1
Bugzilla
CVE-2016-3426 OpenJDK: non-constant time GCM authentication tag comparison (JCE, 8143945)2016-04-18
CVE-2016-3426 — Oracle JDK vulnerability | cvebase