CVE-2014-6549 is an unspecified vulnerability in Oracle Java SE 8u25, impacting both Oracle JDK and JRE. This critical flaw carries a CVSS score of 10.0, indicating a severe risk where remote attackers can compromise confidentiality, integrity, and availability with low attack complexity and no authentication required. Despite its high severity, there is no evidence of active exploitation, and public exploit code is unavailable, though it has garnered some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.8.0CPE matchmatch criteria | cpe:2.3:a:oracle:jdk:1.8.0:update25:*:*:*:*:*:* | ||
1.8.0CPE matchmatch criteria | cpe:2.3:a:oracle:jre:1.8.0:update25:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.