CVE-2016-3443

Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to 2D.  NOTE: the previous information is from the April 2016 CPU. Oracle has not commented on third-party claims that this issue allows remote attackers to obtain sensitive information via crafted font data, which triggers an out-of-bounds read.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.6 CRITICAL
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 85%
Affected Products (NVD)
VendorProductVersion
oraclejdk
1.6.0
oraclejdk
1.7.0
oraclejdk
1.8.0
oraclejre
1.6.0
oraclejre
1.7.0
oraclejre
1.8.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
openjdk-8
sid
8u432-b06-2
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
openjdk-6
precise
not-affected
trusty
dne
wily
not-affected
xenial
dne
openjdk-7
precise
not-affected
trusty
dne
wily
not-affected
xenial
dne
openjdk-8
precise
dne
trusty
dne
wily
not-affected
xenial
not-affected
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
java-1.6.0-ibm
RHEL 6
1:1.6.0.16.25-1jpp.1.el6_7
fixed
java-1.6.0-ibm-demo
RHEL 6
1:1.6.0.16.25-1jpp.1.el6_7
fixed
java-1.6.0-ibm-devel
RHEL 6
1:1.6.0.16.25-1jpp.1.el6_7
fixed
java-1.6.0-ibm-javacomm
RHEL 6
1:1.6.0.16.25-1jpp.1.el6_7
fixed
java-1.6.0-ibm-jdbc
RHEL 6
1:1.6.0.16.25-1jpp.1.el6_7
fixed
java-1.6.0-ibm-plugin
RHEL 6
1:1.6.0.16.25-1jpp.1.el6_7
fixed
java-1.6.0-ibm-src
RHEL 6
1:1.6.0.16.25-1jpp.1.el6_7
fixed
java-1.7.1-ibm
RHEL 6
1:1.7.1.3.40-1jpp.1.el6_7
fixed
RHEL 7
1:1.7.1.3.40-1jpp.1.el7
fixed
java-1.7.1-ibm-demo
RHEL 6
1:1.7.1.3.40-1jpp.1.el6_7
fixed
RHEL 7
1:1.7.1.3.40-1jpp.1.el7
fixed
java-1.7.1-ibm-devel
RHEL 6
1:1.7.1.3.40-1jpp.1.el6_7
fixed
RHEL 7
1:1.7.1.3.40-1jpp.1.el7
fixed
java-1.7.1-ibm-jdbc
RHEL 6
1:1.7.1.3.40-1jpp.1.el6_7
fixed
RHEL 7
1:1.7.1.3.40-1jpp.1.el7
fixed
java-1.7.1-ibm-plugin
RHEL 6
1:1.7.1.3.40-1jpp.1.el6_7
fixed
RHEL 7
1:1.7.1.3.40-1jpp.1.el7
fixed
java-1.7.1-ibm-src
RHEL 6
1:1.7.1.3.40-1jpp.1.el6_7
fixed
RHEL 7
1:1.7.1.3.40-1jpp.1.el7
fixed
java-1.8.0-ibm
RHEL 6
1:1.8.0.3.0-1jpp.1.el6
fixed
RHEL 7
1:1.8.0.3.0-1jpp.1.el7
fixed
java-1.8.0-ibm-demo
RHEL 6
1:1.8.0.3.0-1jpp.1.el6
fixed
RHEL 7
1:1.8.0.3.0-1jpp.1.el7
fixed
java-1.8.0-ibm-devel
RHEL 6
1:1.8.0.3.0-1jpp.1.el6
fixed
RHEL 7
1:1.8.0.3.0-1jpp.1.el7
fixed
java-1.8.0-ibm-jdbc
RHEL 6
1:1.8.0.3.0-1jpp.1.el6
fixed
RHEL 7
1:1.8.0.3.0-1jpp.1.el7
fixed
java-1.8.0-ibm-plugin
RHEL 6
1:1.8.0.3.0-1jpp.1.el6
fixed
RHEL 7
1:1.8.0.3.0-1jpp.1.el7
fixed
java-1.8.0-ibm-src
RHEL 6
1:1.8.0.3.0-1jpp.1.el6
fixed
RHEL 7
1:1.8.0.3.0-1jpp.1.el7
fixed
References