CVE-2012-5076 is a critical vulnerability in the Java Runtime Environment (JRE) component, specifically affecting Java SE 7 Update 7 and earlier, impacting Oracle JRE, Oracle Linux Enterprise Desktop, SUSE JRE, and SUSE Linux Enterprise Desktop. This vulnerability allows remote attackers to compromise confidentiality, integrity, and availability with no user interaction required. It carries a CVSS score of 9.8 (Critical) due to its network-based attack vector, low attack complexity, and complete impact on all three security pillars. The vulnerability has been actively exploited in the wild, with multiple Metasploit modules and ExploitDB entries available, and has garnered significant community discussion and media coverage, indicating widespread awareness and potential for exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.7.0CPE matchmatch criteria | cpe:2.3:a:oracle:jre:1.7.0:-:*:*:*:*:*:* | ||
1.7.0CPE matchmatch criteria | cpe:2.3:a:oracle:jre:1.7.0:update1:*:*:*:*:*:* | ||
1.7.0CPE matchmatch criteria | cpe:2.3:a:oracle:jre:1.7.0:update2:*:*:*:*:*:* | ||
1.7.0CPE matchmatch criteria | cpe:2.3:a:oracle:jre:1.7.0:update3:*:*:*:*:*:* | ||
1.7.0CPE matchmatch criteria | cpe:2.3:a:oracle:jre:1.7.0:update4:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.