HIGH · 10.0

CVE-2016-0483

Unspecified vulnerability in Oracle Java SE 6u105, 7u91, and 8u66; Java SE Embedded 8u65; and JRockit R28.3.8 allows remote attackers to affect confidentiality, integrity, and availability via vectors...

Vulnerability Description

Unspecified vulnerability in Oracle Java SE 6u105, 7u91, and 8u66; Java SE Embedded 8u65; and JRockit R28.3.8 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to AWT. NOTE: the previous information is from the January 2016 CPU. Oracle has not commented on third-party claims that this is a heap-based buffer overflow in the readImage function, which allows remote attackers to execute arbitrary code via crafted image data.

CVSS Score

10.0

HIGH

AV:N/AC:L/Au:N/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
OracleJdk1.6.0
OracleJre1.6.0
OracleJrockitr28.3.8
CanonicalUbuntu Linux12.04

References

FAQ

What is CVE-2016-0483?

CVE-2016-0483 is a vulnerability with a CVSS score of 10.0 (HIGH). Unspecified vulnerability in Oracle Java SE 6u105, 7u91, and 8u66; Java SE Embedded 8u65; and JRockit R28.3.8 allows remote attackers to affect confidentiality, integrity, and availability via vectors...

How severe is CVE-2016-0483?

CVE-2016-0483 has been rated HIGH with a CVSS base score of 10.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2016-0483?

Check the references section above for vendor advisories and patch information. Affected products include: Oracle Jdk, Oracle Jre, Oracle Jrockit, Canonical Ubuntu Linux.