Lucene search

K
ubuntucveUbuntu.comUB:CVE-2016-3606
HistoryJul 21, 2016 - 12:00 a.m.

CVE-2016-3606

2016-07-2100:00:00
ubuntu.com
ubuntu.com
12

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

CVSS3

9.6

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

EPSS

0.012

Percentile

85.7%

Unspecified vulnerability in Oracle Java SE 7u101 and 8u92 and Java SE
Embedded 8u91 allows remote attackers to affect confidentiality, integrity,
and availability via vectors related to Hotspot.

Notes

Author Note
sbeattie likely does not affect openjdk-6
OSVersionArchitecturePackageVersionFilename
ubuntu12.04noarchopenjdk-6< 6b40-1.13.12-0ubuntu0.12.04.1UNKNOWN
ubuntu14.04noarchopenjdk-6< 6b40-1.13.12-0ubuntu0.14.04.2UNKNOWN
ubuntu12.04noarchopenjdk-7< 7u111-2.6.7-0ubuntu0.12.04.2UNKNOWN
ubuntu14.04noarchopenjdk-7< 7u111-2.6.7-0ubuntu0.14.04.3UNKNOWN
ubuntu15.10noarchopenjdk-8< 8u91-b14-3ubuntu1~15.10.1UNKNOWN
ubuntu16.04noarchopenjdk-8< 8u91-b14-3ubuntu1~16.04.1UNKNOWN

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

CVSS3

9.6

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

EPSS

0.012

Percentile

85.7%