CVE-2016-5573
published 2016-10-25CVE-2016-5573: Unspecified vulnerability in Oracle Java SE 6u121, 7u111, 8u102; and Java SE Embedded 8u101 allows remote attackers to affect confidentiality, integrity, and…
PriorityP350high8.3CVSS 3.0
AVNACHPRNUIRSCCHIHAH
EPSS
3.26%
87.0th percentile
Unspecified vulnerability in Oracle Java SE 6u121, 7u111, 8u102; and Java SE Embedded 8u101 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Hotspot, a different vulnerability than CVE-2016-5582.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | openjdk-8 | < openjdk-8 8u111-b14-1 (sid) | openjdk-8 8u111-b14-1 (sid) |
| oracle | jdk | — | — |
| oracle | jdk | — | — |
| oracle | jdk | — | — |
| oracle | jre | — | — |
| oracle | jre | — | — |
| oracle | jre | — | — |
CVSS provenance
nvdv3.08.3HIGHCVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.3HIGH
vendor_debian8.3HIGH
vendor_redhat8.3HIGH
vendor_ubuntu3.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-xpxv-6ccf-795w: Unspecified vulnerability in Oracle Java SE 6u121, 7u111, 8u102; and Java SE Embedded 8u101 allows remote attackers to affect confidentiality, integri
ghsa_unreviewed·2022-05-13·CVSS 9.6
CVE-2016-5573 [CRITICAL] GHSA-xpxv-6ccf-795w: Unspecified vulnerability in Oracle Java SE 6u121, 7u111, 8u102; and Java SE Embedded 8u101 allows remote attackers to affect confidentiality, integri
Unspecified vulnerability in Oracle Java SE 6u121, 7u111, 8u102; and Java SE Embedded 8u101 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Hotspot, a different vulnerability than CVE-2016-5582.
GHSA
GHSA-f57p-w7p5-298g: Unspecified vulnerability in Oracle Java SE 6u121, 7u111, 8u102; and Java SE Embedded 8u101 allows remote attackers to affect confidentiality, integri
ghsa_unreviewed·2022-05-13·CVSS 8.3
CVE-2016-5582 [HIGH] CWE-284 GHSA-f57p-w7p5-298g: Unspecified vulnerability in Oracle Java SE 6u121, 7u111, 8u102; and Java SE Embedded 8u101 allows remote attackers to affect confidentiality, integri
Unspecified vulnerability in Oracle Java SE 6u121, 7u111, 8u102; and Java SE Embedded 8u101 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Hotspot, a different vulnerability than CVE-2016-5573.
OSV
openjdk-7 vulnerabilities
osv·2016-11-17·CVSS 3.1
CVE-2016-5542 [LOW] openjdk-7 vulnerabilities
openjdk-7 vulnerabilities
It was discovered that OpenJDK did not restrict the set of algorithms used
for Jar integrity verification. An attacker could use this to modify
without detection the content of a JAR file, affecting system integrity.
(CVE-2016-5542)
It was discovered that the JMX component of OpenJDK did not sufficiently
perform classloader consistency checks. An attacker could use this to
bypass Java sandbox restrictions. (CVE-2016-5554)
It was discovered that the Hotspot component of OpenJDK did not properly
check received Java Debug Wire Protocol (JDWP) packets. An attacker could
use this to send debugging commands to a Java application with debugging
enabled. (CVE-2016-5573)
It was discovered that the Hotspot component of OpenJDK did not properly
check arguments of the Sys
OSV
openjdk-8 vulnerabilities
osv·2016-11-03·CVSS 3.1
CVE-2016-5582 [LOW] openjdk-8 vulnerabilities
openjdk-8 vulnerabilities
It was discovered that the Hotspot component of OpenJDK did not properly
check arguments of the System.arraycopy() function in certain cases. An
attacker could use this to bypass Java sandbox restrictions.
(CVE-2016-5582)
It was discovered that OpenJDK did not restrict the set of algorithms used
for Jar integrity verification. An attacker could use this to modify
without detection the content of a JAR file, affecting system integrity.
(CVE-2016-5542)
It was discovered that the JMX component of OpenJDK did not sufficiently
perform classloader consistency checks. An attacker could use this to
bypass Java sandbox restrictions. (CVE-2016-5554)
It was discovered that the Hotspot component of OpenJDK did not properly
check received Java Debug Wire Protocol (JDWP) pa
OSV
CVE-2016-5582: Unspecified vulnerability in Oracle Java SE 6u121, 7u111, 8u102; and Java SE Embedded 8u101 allows remote attackers to affect confidentiality, integri
osv·2016-10-25·CVSS 8.3
CVE-2016-5582 [HIGH] CVE-2016-5582: Unspecified vulnerability in Oracle Java SE 6u121, 7u111, 8u102; and Java SE Embedded 8u101 allows remote attackers to affect confidentiality, integri
Unspecified vulnerability in Oracle Java SE 6u121, 7u111, 8u102; and Java SE Embedded 8u101 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Hotspot, a different vulnerability than CVE-2016-5573.
OSV
CVE-2016-5573: Unspecified vulnerability in Oracle Java SE 6u121, 7u111, 8u102; and Java SE Embedded 8u101 allows remote attackers to affect confidentiality, integri
osv·2016-10-25·CVSS 8.3
CVE-2016-5573 [HIGH] CVE-2016-5573: Unspecified vulnerability in Oracle Java SE 6u121, 7u111, 8u102; and Java SE Embedded 8u101 allows remote attackers to affect confidentiality, integri
Unspecified vulnerability in Oracle Java SE 6u121, 7u111, 8u102; and Java SE Embedded 8u101 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Hotspot, a different vulnerability than CVE-2016-5582.
Ubuntu
OpenJDK 6 vulnerabilities
vendor_ubuntu·2016-12-08·CVSS 3.1
CVE-2016-5542 [LOW] OpenJDK 6 vulnerabilities
Title: OpenJDK 6 vulnerabilities
Summary: Several security issues were fixed in OpenJDK 6.
It was discovered that OpenJDK did not restrict the set of algorithms used
for Jar integrity verification. An attacker could use this to modify
without detection the content of a JAR file, affecting system integrity.
(CVE-2016-5542)
It was discovered that the JMX component of OpenJDK did not sufficiently
perform classloader consistency checks. An attacker could use this to
bypass Java sandbox restrictions. (CVE-2016-5554)
It was discovered that the Hotspot component of OpenJDK did not properly
check received Java Debug Wire Protocol (JDWP) packets. An attacker could
use this to send debugging commands to a Java application with debugging
enabled. (CVE-2016-5573)
It was discovered that the Hotspo
Ubuntu
OpenJDK 7 vulnerabilities
vendor_ubuntu·2016-11-17·CVSS 3.1
CVE-2016-5542 [LOW] OpenJDK 7 vulnerabilities
Title: OpenJDK 7 vulnerabilities
Summary: Several security issues were fixed in OpenJDK 7.
It was discovered that OpenJDK did not restrict the set of algorithms used
for Jar integrity verification. An attacker could use this to modify
without detection the content of a JAR file, affecting system integrity.
(CVE-2016-5542)
It was discovered that the JMX component of OpenJDK did not sufficiently
perform classloader consistency checks. An attacker could use this to
bypass Java sandbox restrictions. (CVE-2016-5554)
It was discovered that the Hotspot component of OpenJDK did not properly
check received Java Debug Wire Protocol (JDWP) packets. An attacker could
use this to send debugging commands to a Java application with debugging
enabled. (CVE-2016-5573)
It was discovered that the Hotspo
Ubuntu
OpenJDK 8 vulnerabilities
vendor_ubuntu·2016-11-03·CVSS 3.1
CVE-2016-5542 [LOW] OpenJDK 8 vulnerabilities
Title: OpenJDK 8 vulnerabilities
Summary: Several security issues were fixed in OpenJDK 8.
It was discovered that the Hotspot component of OpenJDK did not properly
check arguments of the System.arraycopy() function in certain cases. An
attacker could use this to bypass Java sandbox restrictions.
(CVE-2016-5582)
It was discovered that OpenJDK did not restrict the set of algorithms used
for Jar integrity verification. An attacker could use this to modify
without detection the content of a JAR file, affecting system integrity.
(CVE-2016-5542)
It was discovered that the JMX component of OpenJDK did not sufficiently
perform classloader consistency checks. An attacker could use this to
bypass Java sandbox restrictions. (CVE-2016-5554)
It was discovered that the Hotspot component of OpenJDK
Red Hat
OpenJDK: insufficient checks of JDWP packets (Hotspot, 8159519)
vendor_redhat·2016-10-18·CVSS 8.3
CVE-2016-5573 [HIGH] CWE-20 OpenJDK: insufficient checks of JDWP packets (Hotspot, 8159519)
OpenJDK: insufficient checks of JDWP packets (Hotspot, 8159519)
Unspecified vulnerability in Oracle Java SE 6u121, 7u111, 8u102; and Java SE Embedded 8u101 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Hotspot, a different vulnerability than CVE-2016-5582.
It was discovered that the Hotspot component of OpenJDK did not properly check received Java Debug Wire Protocol (JDWP) packets. An attacker could possibly use this flaw to send debugging commands to a Java program running with debugging enabled if they could make victim's browser send HTTP requests to the JDWP port of the debugged application.
Red Hat
OpenJDK: incomplete type checks of System.arraycopy arguments (Hotspot, 8160591)
vendor_redhat·2016-10-18·CVSS 8.3
CVE-2016-5582 [HIGH] CWE-843 OpenJDK: incomplete type checks of System.arraycopy arguments (Hotspot, 8160591)
OpenJDK: incomplete type checks of System.arraycopy arguments (Hotspot, 8160591)
Unspecified vulnerability in Oracle Java SE 6u121, 7u111, 8u102; and Java SE Embedded 8u101 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Hotspot, a different vulnerability than CVE-2016-5573.
It was discovered that the Hotspot component of OpenJDK did not properly check arguments of the System.arraycopy() function in certain cases. An untrusted Java application or applet could use this flaw to corrupt virtual machine's memory and completely bypass Java sandbox restrictions.
Debian
CVE-2016-5573: openjdk-8 - Unspecified vulnerability in Oracle Java SE 6u121, 7u111, 8u102; and Java SE Emb...
vendor_debian·2016·CVSS 8.3
CVE-2016-5573 [HIGH] CVE-2016-5573: openjdk-8 - Unspecified vulnerability in Oracle Java SE 6u121, 7u111, 8u102; and Java SE Emb...
Unspecified vulnerability in Oracle Java SE 6u121, 7u111, 8u102; and Java SE Embedded 8u101 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Hotspot, a different vulnerability than CVE-2016-5582.
Scope: local
sid: resolved (fixed in 8u111-b14-1)
Debian
CVE-2016-5582: openjdk-8 - Unspecified vulnerability in Oracle Java SE 6u121, 7u111, 8u102; and Java SE Emb...
vendor_debian·2016·CVSS 8.3
CVE-2016-5582 [HIGH] CVE-2016-5582: openjdk-8 - Unspecified vulnerability in Oracle Java SE 6u121, 7u111, 8u102; and Java SE Emb...
Unspecified vulnerability in Oracle Java SE 6u121, 7u111, 8u102; and Java SE Embedded 8u101 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Hotspot, a different vulnerability than CVE-2016-5573.
Scope: local
sid: resolved (fixed in 8u111-b14-1)
No detection rules found.
No public exploits indexed.
http://rhn.redhat.com/errata/RHSA-2016-2079.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2088.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2089.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2090.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2136.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2137.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2138.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2658.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2659.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0061.htmlhttp://www.debian.org/security/2016/dsa-3707http://www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.htmlhttp://www.securityfocus.com/bid/93628http://www.securitytracker.com/id/1037040http://www.ubuntu.com/usn/USN-3130-1http://www.ubuntu.com/usn/USN-3154-1https://access.redhat.com/errata/RHSA-2017:1216https://security.gentoo.org/glsa/201611-04https://security.gentoo.org/glsa/201701-43https://security.netapp.com/advisory/ntap-20161019-0001/http://rhn.redhat.com/errata/RHSA-2016-2079.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2088.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2089.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2090.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2136.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2137.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2138.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2658.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2659.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0061.htmlhttp://www.debian.org/security/2016/dsa-3707http://www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.htmlhttp://www.securityfocus.com/bid/93628http://www.securitytracker.com/id/1037040http://www.ubuntu.com/usn/USN-3130-1http://www.ubuntu.com/usn/USN-3154-1https://access.redhat.com/errata/RHSA-2017:1216https://security.gentoo.org/glsa/201611-04https://security.gentoo.org/glsa/201701-43https://security.netapp.com/advisory/ntap-20161019-0001/
2016-10-25
Published