CVE-2018-3209 is a difficult-to-exploit vulnerability in the JavaFX subcomponent of Oracle Java SE 8u182, primarily affecting client-side Java deployments running untrusted code. An unauthenticated attacker with network access can compromise Java SE, requiring human interaction from a victim. Successful exploitation can lead to a complete takeover of the affected Java SE instance, impacting confidentiality, integrity, and availability, as reflected by its CVSS v3.0 score of 8.3 (High). There is currently no public exploit code available (Metasploit, Nuclei, ExploitDB), and the vulnerability has seen minimal community discussion or media coverage, indicating a low level of active exploitation or public awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.8.0CPE matchmatch criteria | cpe:2.3:a:oracle:jdk:1.8.0:update181:*:*:*:*:*:* | ||
1.8.0CPE matchmatch criteria | cpe:2.3:a:oracle:jre:1.8.0:update181:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.4 Bluesky, 0.2 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.6 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.