CVE-2012-0500 is a critical, unspecified vulnerability in Oracle Java SE (JRE) and JavaFX versions prior to 7u3, 6u31, and 2.0.3 respectively. This flaw allows remote, untrusted Java Web Start applications or applets to compromise the confidentiality, integrity, and availability of a system through unknown vectors related to Deployment. With a CVSS score of 10.0, it represents a severe risk due to its network-based attack vector, low attack complexity, and complete impact on all three security pillars. While not listed in CISA KEV, exploit code, specifically a Metasploit module for command line argument injection, is publicly available, and it has garnered significant community and media attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.6.0CPE matchmatch criteria | cpe:2.3:a:oracle:jre:*:update30:*:*:*:*:*:* | ||
1.6.0CPE matchmatch criteria | cpe:2.3:a:oracle:jre:1.6.0:update22:*:*:*:*:*:* | ||
1.6.0CPE matchmatch criteria | cpe:2.3:a:oracle:jre:1.6.0:update23:*:*:*:*:*:* | ||
1.6.0CPE matchmatch criteria | cpe:2.3:a:oracle:jre:1.6.0:update24:*:*:*:*:*:* | ||
1.6.0CPE matchmatch criteria | cpe:2.3:a:oracle:jre:1.6.0:update25:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.