MEDIUM · 5.6

CVE-2016-0264

Buffer overflow in the Java Virtual Machine (JVM) in IBM SDK, Java Technology Edition 6 before SR16 FP25 (6.0.16.25), 6 R1 before SR8 FP25 (6.1.8.25), 7 before SR9 FP40 (7.0.9.40), 7 R1 before SR3 FP4...

Vulnerability Description

Buffer overflow in the Java Virtual Machine (JVM) in IBM SDK, Java Technology Edition 6 before SR16 FP25 (6.0.16.25), 6 R1 before SR8 FP25 (6.1.8.25), 7 before SR9 FP40 (7.0.9.40), 7 R1 before SR3 FP40 (7.1.3.40), and 8 before SR3 (8.0.3.0) allows remote attackers to execute arbitrary code via unspecified vectors.

CVSS Score

5.6

MEDIUM

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
LOW
Integrity
LOW
Availability
LOW

Affected Products

VendorProductVersions
SuseLinux Enterprise Server11
SuseLinux Enterprise Software Development Kit11
IbmJava Sdk>= 6.0.0.0, < 6.0.16.25
RedhatSatellite5.6
RedhatEnterprise Linux Desktop5.0
RedhatEnterprise Linux Hpc Node Supplementary6.0
RedhatEnterprise Linux Server5.0
RedhatEnterprise Linux Server Eus6.7
RedhatEnterprise Linux Workstation5.0
SuseSuse Linux Enterprise Server12
SuseManager2.1
SuseManager Proxy2.1
SuseOpenstack Cloud5

Related Weaknesses (CWE)

References

FAQ

What is CVE-2016-0264?

CVE-2016-0264 is a vulnerability with a CVSS score of 5.6 (MEDIUM). Buffer overflow in the Java Virtual Machine (JVM) in IBM SDK, Java Technology Edition 6 before SR16 FP25 (6.0.16.25), 6 R1 before SR8 FP25 (6.1.8.25), 7 before SR9 FP40 (7.0.9.40), 7 R1 before SR3 FP4...

How severe is CVE-2016-0264?

CVE-2016-0264 has been rated MEDIUM with a CVSS base score of 5.6/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2016-0264?

Check the references section above for vendor advisories and patch information. Affected products include: Suse Linux Enterprise Server, Suse Linux Enterprise Software Development Kit, Ibm Java Sdk, Redhat Satellite, Redhat Enterprise Linux Desktop.