Kaffe is a niche Java Virtual Machine implementation with a modestly scoped product footprint centered on its OpenVM runtime. The observed vulnerability signal reflects the complexity of JVM implementation and runtime environments. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Kaffe over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2002-2022HIGH Format string vulnerability in Kaffe OpenVM 1.0.6 and earlier allows local users to execute arbitrary code, when a java.lang.NoClassDefFoundError is thrown, via format specifiers i | Dec 31, 2002 | 7.2 | 25 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Kaffe.
Media articles that mention a CVE ID that affects a product developed by Kaffe — matched by CVE ID, not by vendor name.