CVE-2015-0470

MEDIUM
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

Unspecified vulnerability in Oracle Java SE 8u40 allows remote attackers to affect integrity via unknown vectors related to Hotspot.

References

http://lists.opensuse.org/opensuse-security-announce/2015-04/msg00017.html

http://rhn.redhat.com/errata/RHSA-2015-0809.html

http://rhn.redhat.com/errata/RHSA-2015-0854.html

http://www.debian.org/security/2015/dsa-3234

http://www.debian.org/security/2015/dsa-3235

http://www.debian.org/security/2015/dsa-3316

http://www.oracle.com/technetwork/topics/security/cpuapr2015-2365600.html

http://www.securityfocus.com/bid/74149

http://www.securitytracker.com/id/1032120

https://security.gentoo.org/glsa/201603-11

Details

Source: MITRE

Published: 2015-04-16

Updated: 2020-09-08

Risk Information

CVSS v2

Base Score: 4.3

Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Impact Score: 2.9

Exploitability Score: 8.6

Severity: MEDIUM

Tenable Plugins

View all (16 total)

IDNameProductFamilySeverity
700650Oracle Java SE 5 < Update 85 / 6 < Update 95 / 7 < Update 79 / 8 < Update 45 Multiple Vulnerabilities (April 2015 CPU) (FREAK)Nessus Network MonitorWeb Clients
critical
89904GLSA-201603-11 : Oracle JRE/JDK: Multiple vulnerabilities (Logjam)NessusGentoo Local Security Checks
low
85031Debian DSA-3316-1 : openjdk-7 - security update (Bar Mitzvah) (Logjam)NessusDebian Local Security Checks
low
83268Amazon Linux AMI : java-1.8.0-openjdk (ALAS-2015-517)NessusAmazon Linux Local Security Checks
critical
83165Debian DLA-213-1 : openjdk-6 security updateNessusDebian Local Security Checks
critical
83107openSUSE Security Update : java-1_8_0-openjdk (openSUSE-2015-332)NessusSuSE Local Security Checks
critical
83063Debian DSA-3235-1 : openjdk-7 - security updateNessusDebian Local Security Checks
critical
83062Debian DSA-3234-1 : openjdk-6 - security updateNessusDebian Local Security Checks
critical
82897RHEL 6 / 7 : java-1.8.0-oracle (RHSA-2015:0854)NessusRed Hat Local Security Checks
critical
82821Oracle Java SE Multiple Vulnerabilities (April 2015 CPU) (Unix) (FREAK)NessusMisc.
critical
82820Oracle Java SE Multiple Vulnerabilities (April 2015 CPU) (FREAK)NessusWindows
critical
82816Scientific Linux Security Update : java-1.8.0-openjdk on SL6.x, SL7.x i386/srpm/x86_64 (20150415)NessusScientific Linux Local Security Checks
critical
82811RHEL 6 / 7 : java-1.8.0-openjdk (RHSA-2015:0809)NessusRed Hat Local Security Checks
critical
82804CentOS 6 / 7 : java-1.8.0-openjdk (CESA-2015:0809)NessusCentOS Local Security Checks
critical
82789Oracle Linux 6 / 7 : java-1.8.0-openjdk (ELSA-2015-0809)NessusOracle Linux Local Security Checks
critical
8748Oracle Java SE 8 < Update 41 Multiple VulnerabilitiesNessus Network MonitorWeb Clients
critical