CVE-2014-4247 describes an unspecified vulnerability within Oracle Java SE 8u5, specifically impacting the JavaFX component. This flaw allows remote attackers to compromise confidentiality, integrity, and availability through unknown attack vectors. The vulnerability carries a critical CVSS score of 9.3, indicating a high-impact threat that can be exploited remotely with medium attack complexity, leading to complete compromise of all three security pillars. Its EPSS score is low, suggesting a minimal likelihood of exploitation in the wild. Despite its high severity, there is no evidence of active exploitation, no publicly available exploit code in Metasploit or ExploitDB, and no community discussion or media coverage surrounding this CVE. It is not listed in the CISA KEV catalog and is considered inactive on hot lists.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.8.0CPE matchmatch criteria | cpe:2.3:a:oracle:jdk:1.8.0:update5:*:*:*:*:*:* | ||
1.8.0CPE matchmatch criteria | cpe:2.3:a:oracle:jre:1.8.0:update5:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:C/I:C/A:C
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.