CVE-2016-3426 — Oracle JDK vulnerability
9 documents8 sources
Severity
3.1LOWNVD
OSV9.6
EPSS
1.6%
top 18.29%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 21
Latest updateMay 13
Description
Unspecified vulnerability in Oracle Java SE 8u77 and Java SE Embedded 8u77 allows remote attackers to affect confidentiality via vectors related to JCE.
CVSS vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:NExploitability: 1.6 | Impact: 1.4
Affected Packages2 packages
🔴Vulnerability Details
4GHSA▶
GHSA-3mj4-w4vq-39pp: Unspecified vulnerability in Oracle Java SE 8u77 and Java SE Embedded 8u77 allows remote attackers to affect confidentiality via vectors related to JC↗2022-05-13
OSV▶
CVE-2016-3426: Unspecified vulnerability in Oracle Java SE 8u77 and Java SE Embedded 8u77 allows remote attackers to affect confidentiality via vectors related to JC↗2016-04-21
CVEList▶
CVE-2016-3426: Unspecified vulnerability in Oracle Java SE 8u77 and Java SE Embedded 8u77 allows remote attackers to affect confidentiality via vectors related to JC↗2016-04-21
📋Vendor Advisories
3💬Community
1Bugzilla▶
CVE-2016-3426 OpenJDK: non-constant time GCM authentication tag comparison (JCE, 8143945)↗2016-04-18