CVE-2016-0483

Aliases:CGA-243q-vrhm-6g63CGA-28p8-45gw-fqxvCGA-2cm7-mp4f-mw38CGA-3jfm-g7xr-pjqrCGA-58mc-p85q-q23pCGA-6hrh-rcv6-g7pxCGA-7h4f-q8p3-52v3CGA-8hv2-mqm2-g9fwCGA-8jq9-8rqr-jpvwCGA-97xx-vmhj-j697CGA-9rf5-gj8x-4c8hCGA-ch7v-3q8c-g329CGA-g299-x6mr-hj42CGA-g2f6-4975-rxjhCGA-gh6h-q7h7-q4hjCGA-gqvq-rj58-2cmvCGA-gw7g-5qqr-4mfpCGA-gxv7-6m32-3vv7CGA-j8f2-x6r2-hhfhCGA-p2x6-wrx8-65rhCGA-p357-qcrx-mfm4CGA-q66c-c7fr-vcfxCGA-r3wc-6w8p-mg2wCGA-r6mm-7w9m-5h95CGA-rqp5-m3h6-fcprCGA-v7ch-2f59-28g4CGA-vvf6-jxmw-8jhcCGA-w78f-xpvp-vmv9CGA-w8rw-xfr3-5pm9CGA-wfh5-qx69-5223CGA-wwq3-9rxg-7877CGA-x2pj-vjh9-5g4m
Advisory lineage Upstream: 0 Downstream: 32
Modified
Published: 21 Jan 2016, 02:00
Last modified:05 Aug 2024, 22:22

Vulnerability Summary

Overall Risk (default)
high
70/100
CVSS Score
10 HIGH
v2.0 (nvd)
EPSS Score
14.71% MEDIUM
15% probability +2.12%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

21 Jan 2016, 02:00
Published
Vulnerability first disclosed
05 Aug 2024, 22:22
Last Modified
Vulnerability information updated

Description

Unspecified vulnerability in Oracle Java SE 6u105, 7u91, and 8u66; Java SE Embedded 8u65; and JRockit R28.3.8 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to AWT. NOTE: the previous information is from the January 2016 CPU. Oracle has not commented on third-party claims that this is a heap-based buffer overflow in the readImage function, which allows remote attackers to execute arbitrary code via crafted image data.

CVSS Metrics

  • v2.0HIGHScore: 10AV:N/AC:L/Au:N/C:C/I:C/A:C

EPSS Trends

Current EPSS score: 14.71% Percentile: 97%

Affected Systems

  • chainguardopenjdk-11-openj9-default-policy

    < 0.53.0-r0

  • chainguardopenjdk-17-openj9-default-policy

    < 0.53.0-r0

  • chainguardopenjdk-21-openj9-default-policy

    < 0.53.0-r0

  • chainguardopenjdk-25-openj9

    < 0.59.0-r1

  • chainguardopenjdk-25-openj9-dbg

    < 0.59.0-r1

  • chainguardopenjdk-25-openj9-default-jdk

    < 0.59.0-r1

  • chainguardopenjdk-25-openj9-default-jvm

    < 0.59.0-r1

  • chainguardopenjdk-25-openj9-jmods

    < 0.59.0-r1

  • chainguardopenjdk-25-openj9-jre

    < 0.59.0-r1

  • chainguardopenjdk-26-openj9

    < 0.59.0-r1

  • chainguardopenjdk-26-openj9-dbg

    < 0.59.0-r1

  • chainguardopenjdk-26-openj9-default-jdk

    < 0.59.0-r1

  • chainguardopenjdk-26-openj9-default-jvm

    < 0.59.0-r1

  • chainguardopenjdk-26-openj9-jmods

    < 0.59.0-r1

  • chainguardopenjdk-26-openj9-jre

    < 0.59.0-r1

  • chainguardopenjdk-8-openj9-dbg

    < 0.53.0-r1

  • canonicalubuntu_linux

    12.04 | 14.04 | 15.04 | 15.10

  • oraclejdk

    1.6.0:update105 | 1.7.0:update91 | 1.8.0:update66

  • oraclejre

    1.6.0:update105 | 1.7.0:update91 | 1.8.0:update66

  • oraclejrockit

    r28.3.8

References (27)