CVE-2016-8281
published 2016-10-25CVE-2016-8281: Unspecified vulnerability in the Oracle Platform Security for Java component in Oracle Fusion Middleware 12.1.3.0.0, 12.2.1.0.0, and 12.2.1.1.0 allows remote…
PriorityP344high7.6CVSS 3.0
AVNACLPRLUINSUCHILAL
EPSS
1.81%
76.1th percentile
Unspecified vulnerability in the Oracle Platform Security for Java component in Oracle Fusion Middleware 12.1.3.0.0, 12.2.1.0.0, and 12.2.1.1.0 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors, a different vulnerability than CVE-2016-5536.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | platform_security_for_java | — | — |
| oracle | platform_security_for_java | — | — |
| oracle | platform_security_for_java | — | — |
CVSS provenance
nvdv3.07.6HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-cpr5-2h98-5m4q: Unspecified vulnerability in the Oracle Platform Security for Java component in Oracle Fusion Middleware 12
ghsa_unreviewed·2022-05-17·CVSS 7.6
CVE-2016-5536 [HIGH] CWE-284 GHSA-cpr5-2h98-5m4q: Unspecified vulnerability in the Oracle Platform Security for Java component in Oracle Fusion Middleware 12
Unspecified vulnerability in the Oracle Platform Security for Java component in Oracle Fusion Middleware 12.1.3.0.0, 12.2.1.0.0, and 12.2.1.1.0 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors, a different vulnerability than CVE-2016-8281.
GHSA
GHSA-g5j9-qj8v-w5r9: Unspecified vulnerability in the Oracle Platform Security for Java component in Oracle Fusion Middleware 12
ghsa_unreviewed·2022-05-17·CVSS 7.6
CVE-2016-8281 [HIGH] CWE-284 GHSA-g5j9-qj8v-w5r9: Unspecified vulnerability in the Oracle Platform Security for Java component in Oracle Fusion Middleware 12
Unspecified vulnerability in the Oracle Platform Security for Java component in Oracle Fusion Middleware 12.1.3.0.0, 12.2.1.0.0, and 12.2.1.1.0 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors, a different vulnerability than CVE-2016-5536.
Red Hat
kernel: use after free in the recvmmsg exit path
vendor_redhat·2016-03-14·CVSS 9.8
CVE-2017-8281 [CRITICAL] CWE-416 kernel: use after free in the recvmmsg exit path
kernel: use after free in the recvmmsg exit path
In all Qualcomm products with Android releases from CAF using the Linux kernel, a race condition can allow access to already freed memory while querying event status via DCI.
Statement: This issue is a duplicate of CVE-2016-7117; refer to that CVE for details. It has already been fixed in all supported Red Hat products.
Package: kernel (Red Hat Enterprise Linux 5) - Not affected
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Not affected
Package: kernel-alt (Red Hat Enterprise Linux 7) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 7) - Not affected
Package: realtime-kernel (Red Hat Enterprise MRG 2) - Not affected
No detection rules found.
No public exploits indexed.
http://www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.htmlhttp://www.securityfocus.com/bid/93771http://www.securitytracker.com/id/1037051http://www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.htmlhttp://www.securityfocus.com/bid/93771http://www.securitytracker.com/id/1037051
2016-10-25
Published