CVE-2016-3606 is an unspecified vulnerability within Oracle Java SE (versions 7u101, 8u92) and Java SE Embedded (version 8u91), specifically impacting the Hotspot component. This critical vulnerability, rated 9.6 CVSS, allows remote attackers to compromise confidentiality, integrity, and availability with low attack complexity, requiring user interaction. Despite its high severity, there is no known public exploit code (Metasploit, Nuclei, ExploitDB) and it is not listed in the KEV catalog, indicating it is not actively exploited. While there is limited community discussion and media coverage, its FAUCET Risk Score of 82/100 suggests a significant potential impact.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
5.0CPE matchmatch criteria | cpe:2.3:a:oracle:linux:5.0:*:*:*:*:*:*:* | ||
6.0CPE matchmatch criteria | cpe:2.3:a:oracle:linux:6.0:*:*:*:*:*:*:* | ||
7.0CPE matchmatch criteria | cpe:2.3:a:oracle:linux:7.0:*:*:*:*:*:*:* | ||
1.7.0CPE matchmatch criteria | cpe:2.3:a:oracle:jdk:1.7.0:update101:*:*:*:*:*:* | ||
1.8.0CPE matchmatch criteria | cpe:2.3:a:oracle:jdk:1.8.0:update91:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.8 Bluesky, 0.5 Mastodon, and 1.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.