← Back

CVE-2012-0507

nvd nist
Published: Jun 7, 2012Modified: Apr 22, 2026CISA KEV

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)

Description

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, and 5.0 Update 33 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Concurrency. NOTE: the previous information was obtained from the February 2012 Oracle CPU. Oracle has not commented on claims from a downstream vendor and third party researchers that this issue occurs because the AtomicReferenceArray class implementation does not ensure that the array is of the Object[] type, which allows attackers to cause a denial of service (JVM crash) or bypass Java sandbox restrictions. NOTE: this issue was originally mapped to CVE-2011-3571, but that identifier was already assigned to a different issue.

Affected (74)

Products: Sun: Jre · Oracle: Jre · Debian: Debian Linux · +1 more
Show all products
1 product
Jre
1 product
Jre
1 product
Debian Linux
4 products
Linux Enterprise Desktop
Linux Enterprise Java
Linux Enterprise Server
Configuration A
32 vulnerable
Vulnerable SoftwareAffected Versions
Sun
Version 1.5.0
Version 1.5.0 update10
Version 1.5.0 update11
Version 1.5.0 update12
Version 1.5.0 update13
Version 1.5.0 update14
Version 1.5.0 update15
Version 1.5.0 update16
Version 1.5.0 update17
Version 1.5.0 update18
Version 1.5.0 update19
Version 1.5.0 update1
Version 1.5.0 update20
Version 1.5.0 update21
Version 1.5.0 update22
Version 1.5.0 update23
Version 1.5.0 update24
Version 1.5.0 update25
Version 1.5.0 update26
Version 1.5.0 update27
Version 1.5.0 update28
Version 1.5.0 update29
Version 1.5.0 update2
Version 1.5.0 update31
Version 1.5.0 update33
Version 1.5.0 update3
Version 1.5.0 update4
Version 1.5.0 update5
Version 1.5.0 update6
Version 1.5.0 update7
Version 1.5.0 update8
Version 1.5.0 update9
Configuration B
28 vulnerable
Vulnerable SoftwareAffected Versions
Oracle
Version 1.6.0 update22
Version 1.6.0 update23
Version 1.6.0 update24
Version 1.6.0 update25
Version 1.6.0 update26
Version 1.6.0 update27
Version 1.6.0 update29
Version 1.6.0 update30
Sun
Version 1.6.0
Version 1.6.0 update_10
Version 1.6.0 update_11
Version 1.6.0 update_12
Version 1.6.0 update_13
Version 1.6.0 update_14
Version 1.6.0 update_15
Version 1.6.0 update_16
Version 1.6.0 update_17
Version 1.6.0 update_18
Version 1.6.0 update_19
Version 1.6.0 update_1
Version 1.6.0 update_20
Version 1.6.0 update_21
Version 1.6.0 update_2
Version 1.6.0 update_3
Version 1.6.0 update_4
Version 1.6.0 update_5
Version 1.6.0 update_6
Version 1.6.0 update_7
Configuration C
3 vulnerable
Vulnerable SoftwareAffected Versions
Oracle
Version 1.7.0
Version 1.7.0 update1
Version 1.7.0 update2
Configuration D
2 vulnerable
Vulnerable SoftwareAffected Versions
Debian
Version 6.0
Version 7.0
Configuration E
9 vulnerable
Vulnerable SoftwareAffected Versions
Version 10 sp4
Suse
Version 10 sp4
Version 11 sp1
Suse
Version 10 sp4
Version 11 sp1
Version 11 sp1
Version 11 sp2
Suse
Version 11 sp1
Version 11 sp2

References (45)

Source: secalert_us@oracle.com
Issue TrackingThird Party Advisory
Source: secalert_us@oracle.com
Mailing ListThird Party Advisory
Source: secalert_us@oracle.com
Third Party Advisory
Source: secalert_us@oracle.com
Third Party Advisory
Source: secalert_us@oracle.com
Third Party Advisory
Source: secalert_us@oracle.com
Third Party Advisory
Source: secalert_us@oracle.com
Third Party Advisory
Source: secalert_us@oracle.com
Third Party Advisory
Source: secalert_us@oracle.com
Third Party Advisory
Source: secalert_us@oracle.com
Third Party Advisory
Source: secalert_us@oracle.com
Broken LinkNot Applicable
Source: secalert_us@oracle.com
Broken LinkNot Applicable
Source: secalert_us@oracle.com
Broken LinkNot Applicable
Source: secalert_us@oracle.com
Broken LinkNot Applicable
Source: secalert_us@oracle.com
Broken LinkNot Applicable
Source: secalert_us@oracle.com
Mailing ListThird Party Advisory
Source: secalert_us@oracle.com
Broken LinkExploitThird Party AdvisoryVDB Entry
Source: secalert_us@oracle.com
Issue Tracking
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkNot Applicable
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkNot Applicable
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkNot Applicable
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkNot Applicable
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkNot Applicable
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkExploit
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkExploitThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Issue Tracking
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
US Government Resource

Timeline

No history available yet.