CVE-2012-1713
Aliases:CGA-3pq5-wr33-7rq2CGA-4c5g-fm8c-m2x4CGA-4pf3-w579-fpjwCGA-5gh3-vcq4-cfq8CGA-6g8q-ch7f-2ffmCGA-6wqm-vxpq-5pg2CGA-87c3-gf93-fcmcCGA-8cjq-xmf5-wxvqCGA-8jx6-mcrv-crj8CGA-9qcg-7wwp-8w48CGA-c935-3367-6h8vCGA-fv2w-7g6m-rc4qCGA-g25c-4jfr-fxhwCGA-h664-v2hp-hvvcCGA-hh6m-v3pr-mqmqCGA-hq4h-g5wf-jvcpCGA-hx43-54vh-97qqCGA-j9hp-9jjv-4x74CGA-mjrr-7h88-phpxCGA-mxjf-59qr-v2g5CGA-mxp5-427m-m8p7CGA-p2jr-hww7-mc78CGA-q3g9-gx8c-rh6rCGA-q8cr-3284-j9xcCGA-r3m2-gp79-rm6qCGA-r75w-8v54-vrvpCGA-rhv6-v597-7rjvCGA-rqwh-w893-vpm9CGA-rr67-fp88-p8pmCGA-rrrg-hfgg-7mh3CGA-v858-jhxg-872vCGA-xrcf-997m-qvjw
Advisory lineage Upstream: 0 Downstream: 14
Modified
Published: 16 Jun 2012, 21:00
Last modified:06 Aug 2024, 19:08
Vulnerability Summary
Overall Risk (default)
high
70/100 CVSS Score
10 HIGH
v2.0 (nvd)
EPSS Score
5.98% LOW
6% probability -0.45%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected
Timeline
16 Jun 2012, 21:00
Published
Vulnerability first disclosed
06 Aug 2024, 19:08
Last Modified
Vulnerability information updated
Description
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update 4 and earlier, 6 update 32 and earlier, 5 update 35 and earlier, 1.4.2_37 and earlier, and JavaFX 2.1 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D.
CVSS Metrics
- v2.0•HIGH•Score: 10AV:N/AC:L/Au:N/C:C/I:C/A:C
EPSS Trends
Current EPSS score: 5.98%• Percentile: 93%
Affected Systems
- chainguard•openjdk-11-openj9-default-policy
< 0.53.0-r0
- chainguard•openjdk-17-openj9-default-policy
< 0.53.0-r0
- chainguard•openjdk-21-openj9-default-policy
< 0.48.0-r2
- chainguard•openjdk-25-openj9
< 0.59.0-r1
- chainguard•openjdk-25-openj9-dbg
< 0.59.0-r1
- chainguard•openjdk-25-openj9-default-jdk
< 0.59.0-r1
- chainguard•openjdk-25-openj9-default-jvm
< 0.59.0-r1
- chainguard•openjdk-25-openj9-jmods
< 0.59.0-r1
- chainguard•openjdk-25-openj9-jre
< 0.59.0-r1
- chainguard•openjdk-26-openj9
< 0.59.0-r1
- chainguard•openjdk-26-openj9-dbg
< 0.59.0-r1
- chainguard•openjdk-26-openj9-default-jdk
< 0.59.0-r1
- chainguard•openjdk-26-openj9-default-jvm
< 0.59.0-r1
- chainguard•openjdk-26-openj9-jmods
< 0.59.0-r1
- chainguard•openjdk-26-openj9-jre
< 0.59.0-r1
- chainguard•openjdk-8-openj9-dbg
< 0.53.0-r1
- oracle•javafx
≤ 2.1
- oracle•jdk
≤ 1.7.0 | ≤ 1.6.0
- oracle•jre
≤ 1.7.0 | ≤ 1.6.0
- sun•jdk
≤ 1.5.0 | ≤ 1.4.2_37
- sun•jre
≤ 1.5.0 | ≤ 1.4.2_37
References (20)
- http://lists.opensuse.org/opensuse-security-announce/2012-09/msg00035.html
- http://security.gentoo.org/glsa/glsa-201406-32.xml
- http://lists.opensuse.org/opensuse-security-announce/2012-09/msg00020.html
- http://lists.opensuse.org/opensuse-security-announce/2012-09/msg00032.html
- http://rhn.redhat.com/errata/RHSA-2012-0734.html
- http://www.oracle.com/technetwork/topics/security/javacpujun2012-1515912.html
- http://rhn.redhat.com/errata/RHSA-2012-1243.html
- http://mail.openjdk.java.net/pipermail/distro-pkg-dev/2012-June/019076.html
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16502
- http://secunia.com/advisories/50659
- http://marc.info/?l=bugtraq&m=134496371727681&w=2
- http://lists.opensuse.org/opensuse-security-announce/2012-09/msg00028.html
- http://rhn.redhat.com/errata/RHSA-2013-1455.html
- http://www.mandriva.com/security/advisories?name=MDVSA-2012:095
- http://www.securityfocus.com/bid/53946
- http://www.oracle.com/technetwork/topics/security/cpujul2012-392727.html
- http://rhn.redhat.com/errata/RHSA-2013-1456.html
- http://www.ibm.com/support/docview.wss?uid=swg21615246
- http://www.mandriva.com/security/advisories?name=MDVSA-2013:150
- http://secunia.com/advisories/51080