← Back

CVE-2016-0603

nvd nist
Published: Feb 8, 2016Modified: May 6, 2026

JSON object

Loading...
7.6
Vector
AV:N/AC:H/Au:N/C:C/I:C/A:C
Exploitability: 4.9 / Impact: 10.0
Source: NVD

Description

Unspecified vulnerability in the Java SE component in Oracle Java SE 6u111, 7u95, 8u71, and 8u72, when running on Windows, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Install. NOTE: the previous information is from Oracle's Security Alert for CVE-2016-0603. Oracle has not commented on third-party claims that this is an untrusted search path issue that allows local users to gain privileges via a Trojan horse dll in the "application directory."

Affected (7)

Products: Oracle: Jre, Jdk
2 products
Jre
Jdk
Configuration A
4 vulnerable
Vulnerable SoftwareAffected Versions
Oracle
Version 1.6.0 update111
Version 1.7.0 update95
Version 1.8.0 update71
Version 1.8.0 update72
Configuration B
3 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Oracle
Version 1.6.0 update111
Version 1.7.0 update95
Version 1.8.0 update72
Running on/withPlatform Versions
Microsoft
Windows
All versions

References (14)

Source: secalert_us@oracle.com
Source: secalert_us@oracle.com
Source: secalert_us@oracle.com
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.