← All CVEs

CVE-2016-0483

high · 10

Unspecified vulnerability in Oracle Java SE 6u105, 7u91, and 8u66; Java SE Embedded 8u65; and JRockit R28.3.8 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to AWT. NOTE: the previous information is from the January 2016 CPU. Oracle has not commented on third-party claims that this is a heap-based buffer overflow in the readImage function, which allows remote attackers to execute arbitrary code via crafted image data.

10
CVSS
14.7%
EPSS (exploit prob.)
97th
EPSS percentile
2016-01-21
Published

AV:N/AC:L/Au:N/C:C/I:C/A:C

Affected products

VendorProductAffected versions
oraclejdk1.6.0
oraclejdk1.7.0
oraclejdk1.8.0
oraclejre1.6.0
oraclejre1.7.0
oraclejre1.8.0
oraclejrockitr28.3.8
canonicalubuntu_linux12.04
canonicalubuntu_linux14.04
canonicalubuntu_linux15.04
canonicalubuntu_linux15.10

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2016-0483