Skip to main content

Oracle Java SE Multiple Vulnerabilities

Last Update Date: 15 Feb 2012 10:26 Release Date: 15 Feb 2012 4719 Views

RISK: High Risk

TYPE: Operating Systems - Application Platforms

TYPE: Application Platforms

Multiple vulnerabilities have been identified in Oracle Java SE, which can be exploited by attackers to execute arbitrary code, cause denial of service, and manipulate data.

  1. A remote user can send specially crafted data to execute arbitrary code on the target system or cause complete denial of service conditions. The Java 2D, deploy, and install components are affected. JavaFX is also affected.
  2. A remote user can partially access and modify data and partially deny service on the target system. The I18n and serialization components are affected.
  3. A remote user can partially access data and partially deny service on the target system. The AWT and sound components are affected.
  4. A remote user can cause partial denial of service conditions on the target system. The JRE component is affected.
  5. A remote user can partially modify data on the target system. The CORBA component is affected.

Impact

  • Denial of Service
  • Remote Code Execution
  • Data Manipulation

System / Technologies affected

  • Java SE 1.4.2_35 and prior
  • Java SE 5.0 Update 33 and prior
  • Java SE 6 Update 30 and prior
  • Java SE 7 Update 2 and prior

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.


Vulnerability Identifier


Source


Related Link