Evidence dossier

CVE-2012-0507

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, and 5.0 Update 33 and earlier…

Exploited in the wild (CISA KEV since Mar 3, 2022). NVD reports CVSS 2.0 10.0. EPSS estimates 98.1% exploit likelihood as of Aug 27, 2026.

92.092.5Priority evidence range
Evidence current through Aug 27, 2026, 6:09 PM UTC

As of Aug 27, 2026

Normalized restatement

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, and 5.0 Update 33 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Concurrency. NOTE: the previous information was obtained from the February 2012 Oracle CPU. Oracle has not commented on claims from a downstream vendor and third party researchers that this issue occurs because the AtomicReferenceArray class implementation does not ensure that the array is of the Object[] type, which allows attackers to cause a denial of service (JVM crash) or bypass Java sandbox restrictions. NOTE: this issue was originally mapped to CVE-2011-3571, but that identifier was already assigned to a different issue.

State
PUBLISHED
Published
Jun 7, 2012
Updated
Oct 22, 2025
Evidence coverage
99%

Evidence chronology

What was known when

Download this view's receipt →
  1. Source dateSource date omittedFirst observed by CASCA
    CISA-ADP

    Record text: CISA ADP Vulnrichment

    Inspect raw assertion
    Field
    container
    Value
    CISA ADP Vulnrichment
    Original evidence ↗
  2. Source dateSource date omittedFirst observed by CASCA
    CVE Program

    Record text: CVE Program Container

    Inspect raw assertion
    Field
    container
    Value
    CVE Program Container
    Original evidence ↗
  3. Source dateSource date omittedFirst observed by CASCA
    oracle

    Record text: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, and 5.0 Update 33 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Concurrency. NOTE: the previous information was obtained from the February 2012 Oracle CPU. Oracle has not commented on claims from a downstream vendor and third party researchers that this issue occurs because the AtomicReferenceArray class implementation does not ensure that the array is of the Object[] type, which allows attackers to cause a denial of service (JVM crash) or bypass Java sandbox restrictions. NOTE: this issue was originally mapped to CVE-2011-3571, but that identifier was already assigned to a different issue.

    Inspect raw assertion
    Field
    container
    Value
    Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, and 5.0 Update 33 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Concurrency. NOTE: the previous information was obtained from the February 2012 Oracle CPU. Oracle has not commented on claims from a downstream vendor and third party researchers that this issue occurs because the AtomicReferenceArray class implementation does not ensure that the array is of the Object[] type, which allows attackers to cause a denial of service (JVM crash) or bypass Java sandbox restrictions. NOTE: this issue was originally mapped to CVE-2011-3571, but that identifier was already assigned to a different issue.
    Original evidence ↗
  4. Source dateFirst observed by CASCA
    CISA KEV

    Exploitation cataloged: Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability

    Inspect raw assertion
    Field
    observed_exploitation
    Value
    Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability
    Original evidence ↗
  5. Source dateFirst observed by CASCA
    FIRST EPSS

    EPSS score: 98.11% probability · 99.91th percentile

    Inspect raw assertion
    Field
    model_probability
    Value
    Probability 0.981130000000; percentile 0.999090000000
    Original evidence ↗
ExploitationCatalog member

CISA KEV · catalog date Mar 3, 2022 · first observed Jul 19, 2026

Exploit likelihood98.11%

FIRST EPSS · score date Aug 27, 2026 · 99.9th percentile · first observed Aug 27, 2026

SeverityCVSS 10.0

NVD · CVSS 2.0 · first observed Jul 19, 2026 · same-version scores align in this snapshot

Evidence detail

Source limits and decisions

Why each evidence state has this value

Outside this view’s verified evidence

Reason detail begins outside this selected snapshot; the state remains source-bound.

Source comparison

Who said what

CISA-ADPIndependent enrichment
Record text

CISA ADP Vulnrichment

Inspect raw assertion
Field
container
Value
CISA ADP Vulnrichment
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗
CVE ProgramDerivative copy
Record text

CVE Program Container

Inspect raw assertion
Field
container
Value
CVE Program Container
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗
oracleOriginal assertion
Record text

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, and 5.0 Update 33 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Concurrency. NOTE: the previous information was obtained from the February 2012 Oracle CPU. Oracle has not commented on claims from a downstream vendor and third party researchers that this issue occurs because the AtomicReferenceArray class implementation does not ensure that the array is of the Object[] type, which allows attackers to cause a denial of service (JVM crash) or bypass Java sandbox restrictions. NOTE: this issue was originally mapped to CVE-2011-3571, but that identifier was already assigned to a different issue.

Inspect raw assertion
Field
container
Value
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, and 5.0 Update 33 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Concurrency. NOTE: the previous information was obtained from the February 2012 Oracle CPU. Oracle has not commented on claims from a downstream vendor and third party researchers that this issue occurs because the AtomicReferenceArray class implementation does not ensure that the array is of the Object[] type, which allows attackers to cause a denial of service (JVM crash) or bypass Java sandbox restrictions. NOTE: this issue was originally mapped to CVE-2011-3571, but that identifier was already assigned to a different issue.
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗
CISA KEVOriginal assertion
Exploitation cataloged

Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability

Inspect raw assertion
Field
observed_exploitation
Value
Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability
Source dateFirst observed by CASCAOriginal evidence ↗
FIRST EPSSOriginal assertion
EPSS score

98.11% probability · 99.91th percentile

Inspect raw assertion
Field
model_probability
Value
Probability 0.981130000000; percentile 0.999090000000
Source dateFirst observed by CASCAOriginal evidence ↗

Applicability

Cited product scope

Trace impact →
74Underlying assertions
7Canonical products
74Target assertions
0Constraint assertions

Grouped from 5 configuration nodes in this exact snapshot. Visual grouping is navigational; asset exposure and root cause require cited evidence.

Identity source boundaries
  • Cpe dictionary1,775,266 records · observed through 2026-07-21T06:45:29.809Z27d65b0f-b718-4b4f-bb79-c47c68d09dfa
  • Cpe match643,502 records · observed through 2026-07-21T08:13:17.697Z955dae73-7302-438b-aee1-058d7cc5d48e

8 scope groups

oracle · source assertedn/an/aDirect source scope
Affected: n/a
Source-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Inspect raw assertion[{"status": "affected", "version": "n/a"}]
NVD CPE · OPERATING SYSTEMdebiandebian_linuxVulnerable target · 2 assertions
Version 6.0; Version 7.0Canonical identity product-3ccb4bc87dfae98fa2f2a06435fe5b3d9be78572fb958a89f2d7a96b4066447eLinked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:o:debian:debian_linux:6.0:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    3 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    036e8a89-7a16-411f-9d31-676313bb7244
  2. cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    3 · node/0 · match 1
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    16f59a04-14cf-49e2-9973-645477ea09da
NVD CPE · APPLICATIONoraclejreVulnerable target · 11 assertions
Version 1.6.0; Version 1.7.0Canonical identity product-70c0761d49c3bbe44615490ef7b613557bcd3ccdfa71d09d74202c114d277fb7Linked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:a:oracle:jre:1.7.0:update1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 1
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    f4b153fd-e20b-4909-8b10-884e48f5b590
  2. cpe:2.3:a:oracle:jre:1.6.0:update23:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 1
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    d1a2d440-d966-41a6-955d-38b28dde0fdb
  3. cpe:2.3:a:oracle:jre:1.7.0:-:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    dfaa351a-93cd-46a8-a480-ce2783ccd620
  4. cpe:2.3:a:oracle:jre:1.6.0:update24:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 2
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    b1c57774-ad93-4162-8e45-92b09139c808
  5. cpe:2.3:a:oracle:jre:1.6.0:update30:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 7
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    0d60d98d-4363-44a0-aab4-b61ba623ee21
  6. cpe:2.3:a:oracle:jre:1.6.0:update25:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 3
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    cd7c4194-d34a-418f-9b00-5c6012844aae
  7. cpe:2.3:a:oracle:jre:1.6.0:update26:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 4
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    daf7d86b-1b4d-4e1f-9ef0-da7e419d7e99
  8. cpe:2.3:a:oracle:jre:1.7.0:update2:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 2
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    cb106fa9-26ce-48c5-aea5-fd1a5454aee2
  9. cpe:2.3:a:oracle:jre:1.6.0:update29:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 6
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    a0a67640-2f4a-488a-9d8f-3fe1f4da8def
  10. cpe:2.3:a:oracle:jre:1.6.0:update22:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    ef13b96d-1f80-4672-8da3-f86f6d3bf070
  11. cpe:2.3:a:oracle:jre:1.6.0:update27:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 5
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    f0b82fb1-0f0e-44f9-87ae-628517279e4d
NVD CPE · APPLICATIONsunjreVulnerable target · 52 assertions
Version 1.5.0; Version 1.6.0Canonical identity product-e24bd6c1d86d6df9c425d9bad331eddd1e2be5933a99d4054300f066e687940cLinked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:a:sun:jre:1.5.0:update6:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 28
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    724c972f-74fe-4044-bbc4-7e0e61fc9002
  2. cpe:2.3:a:sun:jre:1.5.0:update18:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 10
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    b83b2ce1-45d7-47ad-bc0a-6ec74d5f8f5a
  3. cpe:2.3:a:sun:jre:1.5.0:update4:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 26
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    f296acf3-1373-429d-b991-8b5ba704a7ef
  4. cpe:2.3:a:sun:jre:1.5.0:update1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 1
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    a7fc09e8-7f30-4fe4-912e-588aa250e2a3
  5. cpe:2.3:a:sun:jre:1.5.0:update16:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 8
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    e42cf0f7-418c-4bb6-9b73-fa3b9171d092
  6. cpe:2.3:a:sun:jre:1.5.0:update31:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 24
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    4c061911-fb19-45eb-8e88-7450224f4023
  7. cpe:2.3:a:sun:jre:1.6.0:update_15:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 15
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    1db1de6a-66ae-499b-ad92-9e6ace474c6d
  8. cpe:2.3:a:sun:jre:1.5.0:update10:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 2
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    a586de4e-8a46-41de-9fdb-5fdb81dcc87b
  9. cpe:2.3:a:sun:jre:1.5.0:update29:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 22
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    1d75c40d-62ae-47f2-a6e0-53f3495260bd
  10. cpe:2.3:a:sun:jre:1.5.0:update20:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 13
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    04344167-530e-4a4d-90ef-74c684943df1
  11. cpe:2.3:a:sun:jre:1.5.0:update14:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 6
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    3e8c6aac-c90b-4220-a69b-2a886a35cf5d
  12. cpe:2.3:a:sun:jre:1.5.0:update3:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 23
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    44051cfe-d15d-4416-a123-f3e49c67a9e7
  13. cpe:2.3:a:sun:jre:1.6.0:-:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 8
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    9af0780e-830e-4971-8f79-8fcf5d2ebc20
  14. cpe:2.3:a:sun:jre:1.6.0:update_19:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 19
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    be409d5c-8f9f-4de9-acb7-0e0b813f6399
  15. cpe:2.3:a:sun:jre:1.5.0:update5:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 27
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    b863420b-de16-416a-9640-1a1340a9b855
  16. cpe:2.3:a:sun:jre:1.6.0:update_18:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 18
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    c4fde9eb-08fe-436e-a265-30e83b15db23
  17. cpe:2.3:a:sun:jre:1.6.0:update_17:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 17
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    49260b94-05de-4b78-9068-6f5f6bfdd19e
  18. cpe:2.3:a:sun:jre:1.5.0:update7:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 29
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    46f41c15-0ef4-4115-bfaa-eead56faeedb
  19. cpe:2.3:a:sun:jre:1.6.0:update_13:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 13
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    2dbb6b73-8d6b-41ff-bee0-e0c7f5f1eb41
  20. cpe:2.3:a:sun:jre:1.6.0:update_11:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 11
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    c3c5879a-a608-4230-9dc1-c27f0f48a13b
  21. cpe:2.3:a:sun:jre:1.5.0:update24:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 17
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    7e0a0a2d-62b9-4a00-84ef-90c15e47a632
  22. cpe:2.3:a:sun:jre:1.6.0:update_5:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 25
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    a99dab4c-272b-4c91-bc70-7729e1152590
  23. cpe:2.3:a:sun:jre:1.5.0:update27:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 20
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    044baddd-a80b-4ae2-8595-5f8186314550
  24. cpe:2.3:a:sun:jre:1.5.0:update8:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 30
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    ebe909de-e55a-4bd3-a5bf-ade407432193
  25. cpe:2.3:a:sun:jre:1.5.0:update28:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 21
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    b7fc11be-8cf7-4d45-bb4a-3efa1ddbb10d
  26. cpe:2.3:a:sun:jre:1.6.0:update_21:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 22
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    f587e635-3a15-4186-b6a1-f99be0a56820
  27. cpe:2.3:a:sun:jre:1.5.0:-:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    5f0ad0f9-e797-4e16-95f3-c1afda557d78
  28. cpe:2.3:a:sun:jre:1.5.0:update33:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 25
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    0e8009bc-f5a8-4d00-9f5f-8635475c6065
  29. cpe:2.3:a:sun:jre:1.5.0:update21:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 14
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    b0e0373b-201d-408f-9234-a7efe8b4970d
  30. cpe:2.3:a:sun:jre:1.6.0:update_6:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 26
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    30dfc10a-a4d9-4f89-b17c-ab9260087d29
  31. cpe:2.3:a:sun:jre:1.5.0:update19:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 11
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    8a32f326-ea92-43cd-930e-e527b60cdd3b
  32. cpe:2.3:a:sun:jre:1.5.0:update17:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 9
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    a5467e9d-07d8-4beb-84d5-a3136c133519
  33. cpe:2.3:a:sun:jre:1.6.0:update_3:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 23
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    90ec6c13-4b37-48e5-8199-a702a944d5a6
  34. cpe:2.3:a:sun:jre:1.6.0:update_2:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 20
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    7158d2c0-e9ac-4cd6-b777-ea7b7a181997
  35. cpe:2.3:a:sun:jre:1.5.0:update12:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 4
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    02565d6f-4cb2-4671-a4ef-3169bcfa6154
  36. cpe:2.3:a:sun:jre:1.6.0:update_10:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 10
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    0a0fec28-0707-4f42-9740-78f3d2d551ee
  37. cpe:2.3:a:sun:jre:1.6.0:update_14:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 14
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    12a3b254-8580-45db-bde4-5b5a29cbffb3
  38. cpe:2.3:a:sun:jre:1.5.0:update11:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 3
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    9919d091-73d7-465a-80ff-f37d6caf9f46
  39. cpe:2.3:a:sun:jre:1.5.0:update22:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 15
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    15ead76d-d5d0-4984-9d07-c1451d791083
  40. cpe:2.3:a:sun:jre:1.6.0:update_16:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 16
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    aadbb4f9-e43e-428b-9979-f47a15696c85
  41. cpe:2.3:a:sun:jre:1.5.0:update15:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 7
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    55231b6b-9298-4363-9b5a-14c2da7b1f50
  42. cpe:2.3:a:sun:jre:1.6.0:update_4:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 24
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    2528152c-e20a-4d97-931c-a5ec3ceaa06d
  43. cpe:2.3:a:sun:jre:1.5.0:update26:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 19
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    3ecae71b-c549-4efb-a509-bfd599f5917a
  44. cpe:2.3:a:sun:jre:1.5.0:update2:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 12
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    7ea5b9e9-654d-44f7-ae98-3d8b382804ac
  45. cpe:2.3:a:sun:jre:1.5.0:update23:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 16
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    de949ebf-2bc0-4355-8b28-b494023d45fe
  46. cpe:2.3:a:sun:jre:1.5.0:update9:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 31
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    5dac04d2-68fd-4793-a8e7-4690a543d7d4
  47. cpe:2.3:a:sun:jre:1.5.0:update13:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 5
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    452a3e51-9eac-451d-ba04-a1e7b7d917eb
  48. cpe:2.3:a:sun:jre:1.6.0:update_7:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 27
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    272a5c44-18ec-41a9-8233-e9d4d0734ea6
  49. cpe:2.3:a:sun:jre:1.6.0:update_12:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 12
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    0c71089a-bdde-41fc-9df9-9aef4c2374df
  50. cpe:2.3:a:sun:jre:1.6.0:update_1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 9
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    09027c19-d442-446f-b7a8-21db6787cf43
  51. cpe:2.3:a:sun:jre:1.6.0:update_20:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 21
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    b08c075b-9fc0-4381-a9e4-fff0362bd308
  52. cpe:2.3:a:sun:jre:1.5.0:update25:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 18
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    a070a282-cbd6-4041-b149-5e310bd12e7b
NVD CPE · OPERATING SYSTEMsuselinux_enterprise_desktopVulnerable target · 1 assertions
Version 10Canonical identity product-908c58b965f5cdd7f6621821fd6c68d62c5a5ce89de01a9e91af7286e0b17d41Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:suse:linux_enterprise_desktop:10:sp4:*:*:-:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    4 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    4339de06-19fb-4b8e-b6ae-3495f605ad05
NVD CPE · OPERATING SYSTEMsuselinux_enterprise_javaVulnerable target · 2 assertions
Version 10; Version 11Canonical identity product-4bed2322ee2f3c6046cc5e2544c025ebca9d0b203d3e86bbe13a28ee7ba092f8Linked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:o:suse:linux_enterprise_java:11:sp1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    4 · node/0 · match 2
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    6c92e342-b485-49e3-bc3a-4397d3ca8453
  2. cpe:2.3:o:suse:linux_enterprise_java:10:sp4:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    4 · node/0 · match 1
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    3cf5c5b9-2cb9-4cd8-b94f-a674ed909cc3
NVD CPE · OPERATING SYSTEMsuselinux_enterprise_serverVulnerable target · 4 assertions
Version 10; Version 11Canonical identity product-4f2240e45c4385f8980643ce838561b90551012dc317022ee66a7d71a9db8e28Linked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:o:suse:linux_enterprise_server:11:sp1:*:*:*:vmware:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    4 · node/0 · match 5
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    a6b7cdca-6f39-4113-b5d3-3aa9d7f3d809
  2. cpe:2.3:o:suse:linux_enterprise_server:11:sp1:*:*:*:-:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    4 · node/0 · match 4
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    a44c3422-0d42-473e-abb4-279d7494ee2f
  3. cpe:2.3:o:suse:linux_enterprise_server:11:sp2:*:*:*:-:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    4 · node/0 · match 6
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    88d6e858-fd8f-4c55-b7d5-ceeda2bba898
  4. cpe:2.3:o:suse:linux_enterprise_server:10:sp4:*:*:-:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    4 · node/0 · match 3
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    d1d7b467-58dd-45f1-9f1f-632620df072a
NVD CPE · OPERATING SYSTEMsuselinux_enterprise_software_development_kitVulnerable target · 2 assertions
Version 11Canonical identity product-bd4950335ff1f3f03b9dd6fa5c596f7c67c9ea6d150272de074ec3767af3532aLinked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:o:suse:linux_enterprise_software_development_kit:11:sp1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    4 · node/0 · match 7
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    e8c91701-df37-4f7b-ab9a-b1bfdb4991f8
  2. cpe:2.3:o:suse:linux_enterprise_software_development_kit:11:sp2:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    4 · node/0 · match 8
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    5aa37837-3083-4dc7-94f4-54fd5d7cb53c

Affected-product evidence

Accepted scope and product mapping

0 canonical links · 0 source-reported links

Applicability remains source-scoped; safety and exposure remain unassessed.

Assessments

CVSS by origin

10.0
NVDCVSS 2.0 · role Primary · priority eligiblevalid_matchAV:N/AC:L/Au:N/C:C/I:C/A:C
9.8
CVE Program sourceCVSS 3.1 · role Secondary · priority eligiblevalid_matchCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
9.8
CISA-ADPCVSS 3.1 · role unknown · display onlyDirect record assessment retained outside normalized eligibilityCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Evidence boundaries

  • KEV membership is authoritative for the catalog, not proof of exposure in any environment.
  • EPSS is a dated model probability and not an individual-environment prediction.
  • Affected or fixed status applies only to the exact cited product and version scope; remaining scope stays source-scoped.
  • NVD-carried upstream facts remain derivative; independent corroboration requires a separately authored source.
  • Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
  • NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
  • Affected-product evidence remains source-scoped; canonical linkage is required before applicability scoring.
  • Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.
  • OSV aggregation and OSV-converted NVD material are not independent corroboration.
  • Red Hat facts are vendor assertions for the exact supplied products.
  • Nonmembership and not-yet-observed states are not proof of safety.