CVE-2016-0483

Advisory lineage Upstream: 0 Downstream: 32
Modified
Published: 21 Jan 2016, 02:00
Last modified:05 Aug 2024, 22:22

Vulnerability Summary

Overall Risk (default)
high
70/100
CVSS Score
10 HIGH
v2.0 (nvd)
EPSS Score
9.9% LOW
10% probability -2.70%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

21 Jan 2016, 02:00
Published
Vulnerability first disclosed
05 Aug 2024, 22:22
Last Modified
Vulnerability information updated

Description

Unspecified vulnerability in Oracle Java SE 6u105, 7u91, and 8u66; Java SE Embedded 8u65; and JRockit R28.3.8 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to AWT. NOTE: the previous information is from the January 2016 CPU. Oracle has not commented on third-party claims that this is a heap-based buffer overflow in the readImage function, which allows remote attackers to execute arbitrary code via crafted image data.

CVSS Metrics

  • v2.0HIGHScore: 10AV:N/AC:L/Au:N/C:C/I:C/A:C

EPSS Trends

Current EPSS score: 9.90% Percentile: 93%

Affected Systems

  • canonicalubuntu_linux

    12.04 | 14.04 | 15.04 | 15.10

  • oraclejdk

    1.6.0:update105 | 1.7.0:update91 | 1.8.0:update66

  • oraclejre

    1.6.0:update105 | 1.7.0:update91 | 1.8.0:update66

  • oraclejrockit

    r28.3.8

References (27)