Evidence dossier

CVE-2012-4681

Multiple vulnerabilities in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier allow remote attackers to execute arbitrary code via a crafted…

Exploited in the wild (CISA KEV since Mar 3, 2022). NVD reports CVSS 3.1 9.8. EPSS estimates 98.5% exploit likelihood as of Aug 3, 2026.

84.499.0Priority evidence range
Evidence current through Aug 27, 2026, 6:09 PM UTC

As of Aug 27, 2026

Normalized restatement

Multiple vulnerabilities in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier allow remote attackers to execute arbitrary code via a crafted applet that bypasses SecurityManager restrictions by (1) using com.sun.beans.finder.ClassFinder.findClass and leveraging an exception with the forName method to access restricted classes from arbitrary packages such as sun.awt.SunToolkit, then (2) using "reflection with a trusted immediate caller" to leverage the getField method to access and modify private fields, as exploited in the wild in August 2012 using Gondzz.class and Gondvv.class.

State
PUBLISHED
Published
Aug 28, 2012
Updated
Aug 6, 2026
Evidence coverage
85%

Evidence chronology

What was known when

Download this view's receipt →
  1. Source dateFirst observed by CASCA
    CISA KEV

    Exploitation cataloged: Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability

    Inspect raw assertion
    Field
    observed_exploitation
    Value
    Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability
    Original evidence ↗
  2. Source dateFirst observed by CASCA
    FIRST EPSS

    EPSS score: 98.54% probability · 99.92th percentile

    Inspect raw assertion
    Field
    model_probability
    Value
    Probability 0.985360000000; percentile 0.999170000000
    Original evidence ↗
  3. Source dateSource date omittedFirst observed by CASCA
    CISA-ADP

    Record text: CISA ADP Vulnrichment

    Inspect raw assertion
    Field
    container
    Value
    CISA ADP Vulnrichment
    Original evidence ↗
  4. Source dateSource date omittedFirst observed by CASCA
    CVE Program

    Record text: CVE Program Container

    Inspect raw assertion
    Field
    container
    Value
    CVE Program Container
    Original evidence ↗
  5. Source dateSource date omittedFirst observed by CASCA
    mitre

    Record text: Multiple vulnerabilities in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier allow remote attackers to execute arbitrary code via a crafted applet that bypasses SecurityManager restrictions by (1) using com.sun.beans.finder.ClassFinder.findClass and leveraging an exception with the forName method to access restricted classes from arbitrary packages such as sun.awt.SunToolkit, then (2) using "reflection with a trusted immediate caller" to leverage the getField method to access and modify private fields, as exploited in the wild in August 2012 using Gondzz.class and Gondvv.class.

    Inspect raw assertion
    Field
    container
    Value
    Multiple vulnerabilities in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier allow remote attackers to execute arbitrary code via a crafted applet that bypasses SecurityManager restrictions by (1) using com.sun.beans.finder.ClassFinder.findClass and leveraging an exception with the forName method to access restricted classes from arbitrary packages such as sun.awt.SunToolkit, then (2) using "reflection with a trusted immediate caller" to leverage the getField method to access and modify private fields, as exploited in the wild in August 2012 using Gondzz.class and Gondvv.class.
    Original evidence ↗
ExploitationCatalog member

CISA KEV · catalog date Mar 3, 2022 · first observed Jul 19, 2026

Exploit likelihood98.54%

FIRST EPSS · score date Aug 3, 2026 · 99.9th percentile · first observed Aug 3, 2026

SeverityCVSS 9.8

NVD · CVSS 3.1 · first observed Aug 6, 2026 · same-version scores align in this snapshot

Evidence detail

Source limits and decisions

Why each evidence state has this value

Outside this view’s verified evidence

Reason detail begins outside this selected snapshot; the state remains source-bound.

Source comparison

Who said what

CISA KEVOriginal assertion
Exploitation cataloged

Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability

Inspect raw assertion
Field
observed_exploitation
Value
Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability
Source dateFirst observed by CASCAOriginal evidence ↗
FIRST EPSSOriginal assertion
EPSS score

98.54% probability · 99.92th percentile

Inspect raw assertion
Field
model_probability
Value
Probability 0.985360000000; percentile 0.999170000000
Source dateFirst observed by CASCAOriginal evidence ↗
CISA-ADPIndependent enrichment
Record text

CISA ADP Vulnrichment

Inspect raw assertion
Field
container
Value
CISA ADP Vulnrichment
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗
CVE ProgramDerivative copy
Record text

CVE Program Container

Inspect raw assertion
Field
container
Value
CVE Program Container
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗
mitreOriginal assertion
Record text

Multiple vulnerabilities in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier allow remote attackers to execute arbitrary code via a crafted applet that bypasses SecurityManager restrictions by (1) using com.sun.beans.finder.ClassFinder.findClass and leveraging an exception with the forName method to access restricted classes from arbitrary packages such as sun.awt.SunToolkit, then (2) using "reflection with a trusted immediate caller" to leverage the getField method to access and modify private fields, as exploited in the wild in August 2012 using Gondzz.class and Gondvv.class.

Inspect raw assertion
Field
container
Value
Multiple vulnerabilities in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier allow remote attackers to execute arbitrary code via a crafted applet that bypasses SecurityManager restrictions by (1) using com.sun.beans.finder.ClassFinder.findClass and leveraging an exception with the forName method to access restricted classes from arbitrary packages such as sun.awt.SunToolkit, then (2) using "reflection with a trusted immediate caller" to leverage the getField method to access and modify private fields, as exploited in the wild in August 2012 using Gondzz.class and Gondvv.class.
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗

Applicability

Cited product scope

Trace impact →
85Underlying assertions
6Canonical products
85Target assertions
0Constraint assertions

Grouped from 2 configuration nodes in this exact snapshot. Visual grouping is navigational; asset exposure and root cause require cited evidence.

Identity source boundaries
  • Cpe dictionary1,775,266 records · observed through 2026-07-21T06:45:29.809Z27d65b0f-b718-4b4f-bb79-c47c68d09dfa
  • Cpe match643,502 records · observed through 2026-07-21T08:13:17.697Z955dae73-7302-438b-aee1-058d7cc5d48e

7 scope groups

mitre · source assertedn/an/aDirect source scope
Affected: n/a
Source-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Inspect raw assertion[{"status": "affected", "version": "n/a"}]
NVD CPE · APPLICATIONoraclejdkVulnerable target · 41 assertions
Version 1.6.0; Version 1.7.0Canonical identity product-6c94a14e5689a64227066e3f60eeb2b8b30045bcbf08047234f29f3fdd35d120Linked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:a:oracle:jdk:1.6.0:update33:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 26
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    0381ee39-2f60-49fd-a63a-b9e81c9033cb
  2. cpe:2.3:a:oracle:jdk:1.7.0:update3:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 37
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    52eeea5a-e77c-43cf-a063-9d5c64ea1870
  3. cpe:2.3:a:oracle:jdk:1.6.0:update25:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 18
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    c3ec13d3-4ce7-459c-a7d7-7d38c1284720
  4. cpe:2.3:a:oracle:jdk:1.6.0:update13:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 5
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    42c95c1d-0c2e-4733-ab1b-65650d88995d
  5. cpe:2.3:a:oracle:jdk:1.6.0:update19:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 11
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    81a4204e-6f50-45fb-a343-7a30c0cd6d3d
  6. cpe:2.3:a:oracle:jdk:1.7.0:update6:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 40
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    6bae3670-0938-480a-8472-dff0b3a0d0bf
  7. cpe:2.3:a:oracle:jdk:1.6.0:update24:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 17
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    352509fe-54d9-4a59-98b7-96e5e98bc2cf
  8. cpe:2.3:a:oracle:jdk:1.6.0:update23:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 16
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    6c9215d9-db64-4cee-85e6-e247035efb09
  9. cpe:2.3:a:oracle:jdk:1.6.0:update2:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 12
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    d6e07069-d6ee-4d44-94a6-cdca4a50e6f9
  10. cpe:2.3:a:oracle:jdk:1.6.0:update34:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 27
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    9ad75455-b7f0-4f42-98e7-caa43787d606
  11. cpe:2.3:a:oracle:jdk:1.6.0:update22:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 15
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    301e96a3-ad2f-48f3-9166-571bd6f9fae3
  12. cpe:2.3:a:oracle:jdk:1.6.0:update32:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 25
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    fb7e911c-c780-440a-abff-cce09061bb4f
  13. cpe:2.3:a:oracle:jdk:1.6.0:update21:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 14
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    6db4f19e-dfc4-42f4-87b9-32fb1c496649
  14. cpe:2.3:a:oracle:jdk:1.6.0:update12:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 4
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    1f3c1e65-929a-4468-8584-f086e6e59839
  15. cpe:2.3:a:oracle:jdk:1.6.0:update1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 1
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    b8ca8719-7abe-4279-b49e-c414794a4fe1
  16. cpe:2.3:a:oracle:jdk:1.6.0:update7:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 31
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    d5d9d9a7-8819-44a4-80ac-52d6b63a0c9b
  17. cpe:2.3:a:oracle:jdk:1.6.0:update17:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 9
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    3fc2226b-cfef-48a4-83ea-1f59f4af7528
  18. cpe:2.3:a:oracle:jdk:1.6.0:update8:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 32
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    feb2c8a3-e0dc-46a3-bd82-8e45da55ed0e
  19. cpe:2.3:a:oracle:jdk:1.7.0:-:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 34
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    acabc935-5dd6-4f85-992e-70ad517ef41d
  20. cpe:2.3:a:oracle:jdk:1.6.0:-:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    4a420da5-1346-446b-8d23-e1e6ddbe527e
  21. cpe:2.3:a:oracle:jdk:1.6.0:update4:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 28
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    d081a380-5aa4-4451-94a9-7b65810106e3
  22. cpe:2.3:a:oracle:jdk:1.6.0:update15:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 7
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    d45b0d7e-ba0f-4aaa-a7ba-2ada4cc90d94
  23. cpe:2.3:a:oracle:jdk:1.6.0:update27:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 20
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    1824da2d-26d5-4595-8376-8e41ab8c5e52
  24. cpe:2.3:a:oracle:jdk:1.6.0:update30:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 23
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    60d05860-9424-4727-b583-74a35bc9bdfd
  25. cpe:2.3:a:oracle:jdk:1.6.0:update31:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 24
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    f85db431-fea4-42e7-ac29-6b66174dcd9e
  26. cpe:2.3:a:oracle:jdk:1.6.0:update14:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 6
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    47a9f499-d1e3-41bd-ac18-e8d3d3231c12
  27. cpe:2.3:a:oracle:jdk:1.7.0:update2:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 36
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    d375cecb-405c-4e18-a7e8-9c5a2f97bd69
  28. cpe:2.3:a:oracle:jdk:1.7.0:update4:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 38
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    003746f6-def0-4d0f-ad97-9e335868e301
  29. cpe:2.3:a:oracle:jdk:1.7.0:update1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 35
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    6152036d-6421-4ae4-9223-766fe07b5a44
  30. cpe:2.3:a:oracle:jdk:1.6.0:update11:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 3
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    2abc1045-7d3d-4a14-b994-7e60a4bb4c9c
  31. cpe:2.3:a:oracle:jdk:1.6.0:update3:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 22
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    344fa3ea-9e25-493c-976a-211d1404b251
  32. cpe:2.3:a:oracle:jdk:1.6.0:update10:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 2
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    dc92b7ec-849f-4255-9d55-43681b8dadc4
  33. cpe:2.3:a:oracle:jdk:1.6.0:update20:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 13
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    4b151882-47c0-400e-bbab-a949e6140c86
  34. cpe:2.3:a:oracle:jdk:1.6.0:update29:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 21
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    b72f78b7-10d1-49cf-ac4d-3b10921cb633
  35. cpe:2.3:a:oracle:jdk:1.6.0:update18:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 10
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    f29dc78f-4d02-47b4-a955-32080b22356c
  36. cpe:2.3:a:oracle:jdk:1.6.0:update16:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 8
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    d58a3e4f-2409-440a-891e-0b84d79ab480
  37. cpe:2.3:a:oracle:jdk:1.6.0:update9:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 33
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    64b5b16d-061a-438d-a8cf-9e63d6c748d7
  38. cpe:2.3:a:oracle:jdk:1.6.0:update5:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 29
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    112e7575-a3a0-4a94-ad39-7b2325b150b8
  39. cpe:2.3:a:oracle:jdk:1.6.0:update26:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 19
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    8cdcd1b4-c5f3-4188-b05f-23922f7de517
  40. cpe:2.3:a:oracle:jdk:1.7.0:update5:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 39
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    cf830e0e-0169-4b6a-81ff-2e9fcd7d913b
  41. cpe:2.3:a:oracle:jdk:1.6.0:update6:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 30
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    708e8cef-82ee-4d4b-abf9-87aa4878f517
NVD CPE · APPLICATIONoraclejreVulnerable target · 40 assertions
Version 1.6.0; Version 1.7.0Canonical identity product-70c0761d49c3bbe44615490ef7b613557bcd3ccdfa71d09d74202c114d277fb7Linked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:a:oracle:jre:1.6.0:update34:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 68
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    738ec3e5-a4eb-47fe-9c9a-7c8e8c669765
  2. cpe:2.3:a:oracle:jre:1.6.0:update4:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 69
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    964ccfd6-316a-48c6-9a6b-7cfd1a1fb027
  3. cpe:2.3:a:oracle:jre:1.6.0:update19:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 52
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    77c54e00-0197-4c87-9bff-01a099ac3006
  4. cpe:2.3:a:oracle:jre:1.6.0:update10:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 43
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    d16229b8-1642-4c10-8650-a9cea9d4c98c
  5. cpe:2.3:a:oracle:jre:1.6.0:update25:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 59
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    cd7c4194-d34a-418f-9b00-5c6012844aae
  6. cpe:2.3:a:oracle:jre:1.6.0:update27:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 61
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    f0b82fb1-0f0e-44f9-87ae-628517279e4d
  7. cpe:2.3:a:oracle:jre:1.7.0:update1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 75
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    f4b153fd-e20b-4909-8b10-884e48f5b590
  8. cpe:2.3:a:oracle:jre:1.7.0:update3:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 77
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    5831d70b-3854-4cb8-b88d-40f1743daee0
  9. cpe:2.3:a:oracle:jre:1.6.0:update14:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 47
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    3b02f361-0c64-4cb8-8dad-a63f1a9cc025
  10. cpe:2.3:a:oracle:jre:1.6.0:update21:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 55
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    52fa600c-08b6-4143-9c72-db31e489de3e
  11. cpe:2.3:a:oracle:jre:1.6.0:update29:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 62
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    a0a67640-2f4a-488a-9d8f-3fe1f4da8def
  12. cpe:2.3:a:oracle:jre:1.6.0:update1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 42
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    f199b346-b95e-4dca-b750-148a36d559ba
  13. cpe:2.3:a:oracle:jre:1.6.0:update32:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 66
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    8e76476e-4120-46a9-90a8-a95fe89636cd
  14. cpe:2.3:a:oracle:jre:1.6.0:update6:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 71
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    6c59c275-5964-4e5d-be80-ba4ea34bea62
  15. cpe:2.3:a:oracle:jre:1.7.0:update4:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 78
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    eeb101c9-ca38-4421-bc0c-c1ad47aa2cc9
  16. cpe:2.3:a:oracle:jre:1.6.0:update17:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 50
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    d7823ae6-cb18-47de-8a4f-1f98394b7237
  17. cpe:2.3:a:oracle:jre:1.6.0:update12:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 45
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    830a3a51-f17a-4c61-8f5c-6a4582a64da6
  18. cpe:2.3:a:oracle:jre:1.6.0:update31:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 65
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    23cda4f0-c32b-4b08-a377-7d4426c2f569
  19. cpe:2.3:a:oracle:jre:1.6.0:update26:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 60
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    daf7d86b-1b4d-4e1f-9ef0-da7e419d7e99
  20. cpe:2.3:a:oracle:jre:1.6.0:update13:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 46
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    9de0e496-719d-4cef-837f-b060a898099f
  21. cpe:2.3:a:oracle:jre:1.6.0:update9:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 73
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    6b3a8681-3eac-4d02-811a-5fcccc7b5635
  22. cpe:2.3:a:oracle:jre:1.6.0:update24:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 58
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    b1c57774-ad93-4162-8e45-92b09139c808
  23. cpe:2.3:a:oracle:jre:1.7.0:update5:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 79
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    ba302df3-abbb-4262-b206-4c0f7b5b1e91
  24. cpe:2.3:a:oracle:jre:1.6.0:update30:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 64
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    0d60d98d-4363-44a0-aab4-b61ba623ee21
  25. cpe:2.3:a:oracle:jre:1.6.0:update5:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 70
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    dc8771d7-9531-4a1d-b2de-faa7a7549801
  26. cpe:2.3:a:oracle:jre:1.7.0:-:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 74
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    dfaa351a-93cd-46a8-a480-ce2783ccd620
  27. cpe:2.3:a:oracle:jre:1.6.0:update20:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 54
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    7415177f-a2fe-47ab-8d92-194a4f6d75c8
  28. cpe:2.3:a:oracle:jre:1.6.0:update15:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 48
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    fd4cc3e2-7bea-4d8c-811c-c5012327a9aa
  29. cpe:2.3:a:oracle:jre:1.6.0:update11:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 44
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    1714bdef-6b0e-42bb-9510-3f9b52e170bc
  30. cpe:2.3:a:oracle:jre:1.6.0:update18:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 51
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    381efa43-db73-48ea-a4b1-f451ef60d845
  31. cpe:2.3:a:oracle:jre:1.6.0:update16:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 49
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    9f63a8ac-893d-4d75-b467-85e70b62541d
  32. cpe:2.3:a:oracle:jre:1.6.0:update3:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 63
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    2752b83a-6dd2-4829-9e4f-42cddcbc38c0
  33. cpe:2.3:a:oracle:jre:1.7.0:update6:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 80
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    f9a8ebcb-5e6a-42f0-8d07-f3a3d1c850f0
  34. cpe:2.3:a:oracle:jre:1.6.0:update33:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 67
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    97a84689-0ced-404f-8dc3-708beb37d2ce
  35. cpe:2.3:a:oracle:jre:1.6.0:update7:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 72
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    47c1922b-37e8-4009-97c7-b243f6f96704
  36. cpe:2.3:a:oracle:jre:1.7.0:update2:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 76
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    cb106fa9-26ce-48c5-aea5-fd1a5454aee2
  37. cpe:2.3:a:oracle:jre:1.6.0:update22:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 56
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    ef13b96d-1f80-4672-8da3-f86f6d3bf070
  38. cpe:2.3:a:oracle:jre:1.6.0:update23:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 57
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    d1a2d440-d966-41a6-955d-38b28dde0fdb
  39. cpe:2.3:a:oracle:jre:1.6.0:update2:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 53
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    64ad6007-eb92-4d0e-a0cb-8ffddb61aa6d
  40. cpe:2.3:a:oracle:jre:1.6.0:-:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 41
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    eb864346-1429-46b5-a91e-a1126c486421
NVD CPE · OPERATING SYSTEMredhatenterprise_linux_desktopVulnerable target · 1 assertions
Version 6.0Canonical identity product-ebce605e64c58caa7df6a30e91702332cd8c0be8f801e44353e6350e913ec5aeLinked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:redhat:enterprise_linux_desktop:6.0:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    ee249e1b-a1fd-4e08-aa71-a0e1f10ffe97
NVD CPE · OPERATING SYSTEMredhatenterprise_linux_eusVulnerable target · 1 assertions
Version 6.3Canonical identity product-8abf8d7f0342f690712d750b6cf7fbf4068eb0134c40a51c5b57b074f81c6378Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:redhat:enterprise_linux_eus:6.3:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 1
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    8382a145-cdd9-437e-9de7-a349956778b3
NVD CPE · OPERATING SYSTEMredhatenterprise_linux_serverVulnerable target · 1 assertions
Version 6.0Canonical identity product-8db20157ede2f731f576213a7e555a24d2424bb17aed8e43ad9b77c3587f9deaLinked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:redhat:enterprise_linux_server:6.0:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 2
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    9bbcd86a-e6c7-4444-9d74-f861084090f0
NVD CPE · OPERATING SYSTEMredhatenterprise_linux_workstationVulnerable target · 1 assertions
Version 6.0Canonical identity product-b2aa744c9fb2b4ef0e3b842acbf37879ad4ac43af291292cfb0906170b204ab9Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:redhat:enterprise_linux_workstation:6.0:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 3
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    e5ed5807-55b7-47c5-97a6-03233f4fbc3a

Affected-product evidence

Accepted scope and product mapping

0 canonical links · 0 source-reported links

Applicability remains source-scoped; safety and exposure remain unassessed.

Assessments

CVSS by origin

9.8
NVDCVSS 3.1 · role Primary · priority eligiblevalid_matchCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
10.0
NVDCVSS 2.0 · role Primary · priority eligiblevalid_matchAV:N/AC:L/Au:N/C:C/I:C/A:C
9.8
CVE Program sourceCVSS 3.1 · role Secondary · priority eligiblevalid_matchCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
9.8
CISA-ADPCVSS 3.1 · role unknown · display onlyDirect record assessment retained outside normalized eligibilityCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Evidence boundaries

  • KEV membership is authoritative for the catalog, not proof of exposure in any environment.
  • EPSS is a dated model probability and not an individual-environment prediction.
  • Affected or fixed status applies only to the exact cited product and version scope; remaining scope stays source-scoped.
  • NVD-carried upstream facts remain derivative; independent corroboration requires a separately authored source.
  • Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
  • NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
  • Affected-product evidence remains source-scoped; canonical linkage is required before applicability scoring.
  • Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.
  • OSV aggregation and OSV-converted NVD material are not independent corroboration.
  • Red Hat facts are vendor assertions for the exact supplied products.
  • Nonmembership and not-yet-observed states are not proof of safety.