CVE-2012-0507 is a critical vulnerability in Oracle Java SE 7 and earlier, affecting products from Oracle, Debian, Sun, and SUSE. It allows remote attackers to compromise confidentiality, integrity, and availability, potentially leading to a denial of service (JVM crash) or sandbox bypass due to an AtomicReferenceArray class implementation flaw. With a CVSS score of 9.8 (CRITICAL) and an EPSS score indicating high exploitability, this vulnerability is easily exploitable over the network with low attack complexity. It is actively exploited in the wild, including in known ransomware campaigns, with public Metasploit modules and significant community discussion and media coverage confirming its widespread impact.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.5.0CPE matchmatch criteria | cpe:2.3:a:sun:jre:1.5.0:-:*:*:*:*:*:* | ||
1.5.0CPE matchmatch criteria | cpe:2.3:a:sun:jre:1.5.0:update1:*:*:*:*:*:* | ||
1.5.0CPE matchmatch criteria | cpe:2.3:a:sun:jre:1.5.0:update10:*:*:*:*:*:* | ||
1.5.0CPE matchmatch criteria | cpe:2.3:a:sun:jre:1.5.0:update11:*:*:*:*:*:* | ||
1.5.0CPE matchmatch criteria | cpe:2.3:a:sun:jre:1.5.0:update12:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.