CVE-2016-3550 is an unspecified vulnerability in Oracle Java SE (versions 6u115, 7u101, 8u92) and Java SE Embedded (version 8u91), specifically affecting the Hotspot component. This medium-severity vulnerability (CVSS 4.3) allows remote attackers to impact confidentiality with low attack complexity, requiring user interaction, but does not affect integrity or availability. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or inclusion in CISA's KEV catalog, though it has received some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
5.0CPE matchmatch criteria | cpe:2.3:o:oracle:linux:5.0:*:*:*:*:*:*:* | ||
6CPE matchmatch criteria | cpe:2.3:o:oracle:linux:6:*:*:*:*:*:*:* | ||
7CPE matchmatch criteria | cpe:2.3:o:oracle:linux:7:*:*:*:*:*:*:* | ||
1.6.0CPE matchmatch criteria | cpe:2.3:a:oracle:jdk:1.6.0:update115:*:*:*:*:*:* | ||
1.7.0CPE matchmatch criteria | cpe:2.3:a:oracle:jdk:1.7.0:update101:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.