peter bassill · operator
$ cve CVE-2012-0547 JSON

CVE-2012-0547 EXPLOIT

0.0
LOW · CVSS 2.0 · EPSS 12.5% (pctl 96)

Patch early

A public exploit exists.

Description

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier, and 6 Update 34 and earlier, has no impact and remote attack vectors involving AWT and "a security-in-depth issue that is not directly exploitable but which can be used to aggravate security vulnerabilities that can be directly exploited." NOTE: this identifier was assigned by the Oracle CNA, but CVE is not intended to cover defense-in-depth issues that are only exposed by the presence of other vulnerabilities. NOTE: Oracle has not commented on claims from a downstream vendor that this issue is related to "toolkit internals references."

Scoring

CVSS0.0 (LOW, v2.0)
VectorAV:N/AC:L/Au:N/C:N/I:N/A:N
EPSS12.47% — more likely to be exploited than 96% of all CVEs
On CISA KEVno
Public exploityes
Published2012-08-30
Last modified2026-06-16

Affected (4)

VendorProduct
oraclejdk
oraclejre
sunjdk
sunjre

Public exploits

SourceTitleDate
exploit-dbJava 7 Applet - Remote Code Execution (Metasploit)2012-08-27

References

→ the Explorer  ·  watch your stack  ·  NVD