CVE-2015-0491 is an unspecified vulnerability in Oracle Java SE versions 5.0u81, 6u91, 7u76, and 8u40, and Java FX 2.2.76, specifically related to the 2D component. This critical vulnerability, with a CVSS score of 10.0, allows remote attackers to compromise confidentiality, integrity, and availability without authentication via unknown vectors. While there is no known exploit code in Metasploit, Nuclei, or ExploitDB, and it is not listed in CISA's KEV catalog, it has garnered some community discussion and media coverage, indicating awareness of its potential impact.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.5.0CPE matchmatch criteria | cpe:2.3:a:oracle:jdk:1.5.0:update8:*:*:*:*:*:* | ||
1.6.0CPE matchmatch criteria | cpe:2.3:a:oracle:jdk:1.6.0:update91:*:*:*:*:*:* | ||
1.7.0CPE matchmatch criteria | cpe:2.3:a:oracle:jdk:1.7.0:update76:*:*:*:*:*:* | ||
1.8.0CPE matchmatch criteria | cpe:2.3:a:oracle:jdk:1.8.0:update40:*:*:*:*:*:* | ||
1.5.0CPE matchmatch criteria | cpe:2.3:a:oracle:jre:1.5.0:update81:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.