CVE-2016-0483

Unspecified vulnerability in Oracle Java SE 6u105, 7u91, and 8u66; Java SE Embedded 8u65; and JRockit R28.3.8 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to AWT.  NOTE: the previous information is from the January 2016 CPU. Oracle has not commented on third-party claims that this is a heap-based buffer overflow in the readImage function, which allows remote attackers to execute arbitrary code via crafted image data.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
10 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:C/I:C/A:C
oracleCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 95%
VendorProductVersion
oraclejdk
1.6.0
oraclejdk
1.7.0
oraclejdk
1.8.0
oraclejre
1.6.0
oraclejre
1.7.0
oraclejre
1.8.0
oraclejrockit
r28.3.8
canonicalubuntu_linux
12.04
canonicalubuntu_linux
14.04
canonicalubuntu_linux
15.04
canonicalubuntu_linux
15.10
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
openjdk-8
sid
8u432-b06-2
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
openjdk-6
xenial
dne
wily
Fixed 6b38-1.13.10-0ubuntu0.15.10.1
released
vivid
Fixed 6b38-1.13.10-0ubuntu0.15.04.1
released
trusty
Fixed 6b38-1.13.10-0ubuntu0.14.04.1
released
precise
Fixed 6b38-1.13.10-0ubuntu0.12.04.1
released
openjdk-7
xenial
dne
wily
Fixed 7u95-2.6.4-0ubuntu0.15.10.1
released
vivid
Fixed 7u95-2.6.4-0ubuntu0.15.04.1
released
trusty
Fixed 7u95-2.6.4-0ubuntu0.14.04.1
released
precise
Fixed 7u95-2.6.4-0ubuntu0.12.04.1
released
openjdk-8
xenial
not-affected
wily
Fixed 8u91-b14-0ubuntu4~15.10.1
released
vivid
ignored
trusty
dne
precise
dne
References