CVE-2011-0815 describes an unspecified vulnerability in the Java Runtime Environment (JRE) component of Oracle Java SE, affecting versions 6 Update 25 and earlier, 5.0 Update 29 and earlier, and 1.4.2_31 and earlier. This critical flaw, related to AWT, allows remote untrusted Java Web Start applications and applets to compromise confidentiality, integrity, and availability. With a CVSS score of 10.0, it is easily exploitable over the network with low attack complexity and no authentication required, leading to complete compromise. Despite its high severity and significant community discussion, there is no known active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or KEV entry, and it is not on the CISA Hot List.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.4.2_31CPE matchmatch criteria | cpe:2.3:a:sun:jdk:*:*:*:*:*:*:*:* | ||
1.4.2CPE matchmatch criteria | cpe:2.3:a:sun:jdk:1.4.2:*:*:*:*:*:*:* | ||
1.4.2_1CPE matchmatch criteria | cpe:2.3:a:sun:jdk:1.4.2_1:*:*:*:*:*:*:* | ||
1.4.2_2CPE matchmatch criteria | cpe:2.3:a:sun:jdk:1.4.2_2:*:*:*:*:*:*:* | ||
1.4.2_3CPE matchmatch criteria | cpe:2.3:a:sun:jdk:1.4.2_3:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.