Description
Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to 2D. NOTE: the previous information is from the April 2016 CPU. Oracle has not commented on third-party claims that this issue allows remote attackers to obtain sensitive information via crafted font data, which triggers an out-of-bounds read.
Published: 2016-04-21
Score: 9.6 Critical
EPSS: 2.3% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2016-4469 Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to 2D. NOTE: the previous information is from the April 2016 CPU. Oracle has not commented on third-party claims that this issue allows remote attackers to obtain sensitive information via crafted font data, which triggers an out-of-bounds read.
References
Link Providers
http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00039.html cve-icon cve-icon
http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00040.html cve-icon cve-icon
http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00042.html cve-icon cve-icon
http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00058.html cve-icon cve-icon
http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00059.html cve-icon cve-icon
http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00061.html cve-icon cve-icon
http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00067.html cve-icon cve-icon
http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00002.html cve-icon cve-icon
http://rhn.redhat.com/errata/RHSA-2016-0677.html cve-icon cve-icon
http://rhn.redhat.com/errata/RHSA-2016-0678.html cve-icon cve-icon
http://rhn.redhat.com/errata/RHSA-2016-0679.html cve-icon cve-icon
http://rhn.redhat.com/errata/RHSA-2016-0701.html cve-icon cve-icon
http://rhn.redhat.com/errata/RHSA-2016-0702.html cve-icon cve-icon
http://rhn.redhat.com/errata/RHSA-2016-0708.html cve-icon cve-icon
http://rhn.redhat.com/errata/RHSA-2016-0716.html cve-icon cve-icon
http://rhn.redhat.com/errata/RHSA-2016-1039.html cve-icon cve-icon
http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html cve-icon cve-icon
http://www.oracle.com/technetwork/topics/security/cpuapr2016-2881694.html#AppendixJAVA cve-icon
http://www.securityfocus.com/bid/86482 cve-icon cve-icon
http://www.securitytracker.com/id/1035596 cve-icon cve-icon
http://www.zerodayinitiative.com/advisories/ZDI-16-376 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2016:1430 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2017:1216 cve-icon cve-icon
https://nvd.nist.gov/vuln/detail/CVE-2016-3443 cve-icon
https://security.gentoo.org/glsa/201606-18 cve-icon cve-icon
https://security.netapp.com/advisory/ntap-20160420-0001/ cve-icon cve-icon
https://www.cve.org/CVERecord?id=CVE-2016-3443 cve-icon
History

Tue, 15 Oct 2024 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Subscriptions

Oracle Jdk Jre
Redhat Network Satellite Rhel Extras Rhel Extras Oracle Java
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2024-10-15T19:04:33.955Z

Reserved: 2016-03-17T00:00:00.000Z

Link: CVE-2016-3443

cve-icon Vulnrichment

Updated: 2024-08-05T23:56:13.564Z

cve-icon NVD

Status : Modified

Published: 2016-04-21T11:00:32.667

Modified: 2026-05-06T22:30:45.220

Link: CVE-2016-3443

cve-icon Redhat

Severity : Critical

Publid Date: 2016-04-19T00:00:00Z

Links: CVE-2016-3443 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses