Unspecified vulnerability in Oracle Java SE 7u97, 8u73, and 8u74 allows remote malicious users to affect confidentiality, integrity, and availability via unknown vectors related to the Hotspot sub-component.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
redhat enterprise linux desktop 7.0 |
||
redhat enterprise linux workstation 7.0 |
||
redhat enterprise linux server 7.0 |
||
redhat enterprise linux hpc node 6.0 |
||
redhat enterprise linux hpc node 7.0 |
||
redhat enterprise linux desktop 6.0 |
||
redhat enterprise linux server 6.0 |
||
redhat enterprise linux workstation 6.0 |
||
redhat icedtea7 |
||
oracle jdk 1.8.0 |
||
oracle jdk 1.7.0 |
||
oracle jre 1.7.0 |
||
oracle jre 1.8.0 |
Malicious web page could achieve remote PC takeover without authentication
Oracle is urging Java users to upgrade, ASAP, to crimp a very nasty bug in the desktop and browser plug-in versions of the software. Labelled CVE-2016-0636, the flaw scored a 9.3 on the Common Vulnerability Scoring System bug severity rating. That high score comes about because the flaw means attackers “can impact the availability, integrity, and confidentiality of the user's system.” Worse still, an attacker can do that remotely, without authentication. In other words, visit the wrong web s...