CVE-2017-3514 is a high-severity vulnerability (CVSS 8.3) in the AWT subcomponent of Oracle Java SE versions 6u141, 7u131, and 8u121, as well as Oracle JDK, JRE, and JRockit. This flaw allows an unauthenticated attacker with network access to compromise Java SE, potentially leading to a full system takeover. Exploitation is difficult and requires user interaction, primarily affecting client-side Java deployments running untrusted code within a sandbox. There is currently no public exploit code available, nor is there evidence of active exploitation or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.6CPE matchmatch criteria | cpe:2.3:a:oracle:jdk:1.6:update_141:*:*:*:*:*:* | ||
1.7CPE matchmatch criteria | cpe:2.3:a:oracle:jdk:1.7:update_131:*:*:*:*:*:* | ||
1.8CPE matchmatch criteria | cpe:2.3:a:oracle:jdk:1.8:update_121:*:*:*:*:*:* | ||
1.6CPE matchmatch criteria | cpe:2.3:a:oracle:jre:1.6:update_141:*:*:*:*:*:* | ||
1.7CPE matchmatch criteria | cpe:2.3:a:oracle:jre:1.7:update_131:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.4 Bluesky, 0.2 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.6 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.