CISA KEV · catalog date Mar 3, 2022 · first observed Jul 19, 2026
Evidence dossier
CVE-2012-4681
Multiple vulnerabilities in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier allow remote attackers to execute arbitrary code via a crafted…
Exploited in the wild (CISA KEV since Mar 3, 2022). NVD reports CVSS 3.1 9.8. EPSS estimates 98.5% exploit likelihood as of Aug 3, 2026.
As of Aug 27, 2026
Normalized restatement
Multiple vulnerabilities in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier allow remote attackers to execute arbitrary code via a crafted applet that bypasses SecurityManager restrictions by (1) using com.sun.beans.finder.ClassFinder.findClass and leveraging an exception with the forName method to access restricted classes from arbitrary packages such as sun.awt.SunToolkit, then (2) using "reflection with a trusted immediate caller" to leverage the getField method to access and modify private fields, as exploited in the wild in August 2012 using Gondzz.class and Gondvv.class.
- State
- PUBLISHED
- Published
- Aug 28, 2012
- Updated
- Aug 6, 2026
- Evidence coverage
- 85%
Evidence chronology
What was known when
- Source dateFirst observed by CASCACISA KEVOriginal evidence ↗
Exploitation cataloged: Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability
- Source dateFirst observed by CASCAFIRST EPSSOriginal evidence ↗
EPSS score: 98.54% probability · 99.92th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.985360000000; percentile 0.999170000000
- Source dateSource date omittedFirst observed by CASCACISA-ADPOriginal evidence ↗
Record text: CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
- Source dateSource date omittedFirst observed by CASCACVE ProgramOriginal evidence ↗
Record text: CVE Program Container
Inspect raw assertion
- Field
container- Value
- CVE Program Container
- Source dateSource date omittedFirst observed by CASCAmitreOriginal evidence ↗
Record text: Multiple vulnerabilities in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier allow remote attackers to execute arbitrary code via a crafted applet that bypasses SecurityManager restrictions by (1) using com.sun.beans.finder.ClassFinder.findClass and leveraging an exception with the forName method to access restricted classes from arbitrary packages such as sun.awt.SunToolkit, then (2) using "reflection with a trusted immediate caller" to leverage the getField method to access and modify private fields, as exploited in the wild in August 2012 using Gondzz.class and Gondvv.class.
Inspect raw assertion
- Field
container- Value
- Multiple vulnerabilities in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier allow remote attackers to execute arbitrary code via a crafted applet that bypasses SecurityManager restrictions by (1) using com.sun.beans.finder.ClassFinder.findClass and leveraging an exception with the forName method to access restricted classes from arbitrary packages such as sun.awt.SunToolkit, then (2) using "reflection with a trusted immediate caller" to leverage the getField method to access and modify private fields, as exploited in the wild in August 2012 using Gondzz.class and Gondvv.class.
FIRST EPSS · score date Aug 3, 2026 · 99.9th percentile · first observed Aug 3, 2026
NVD · CVSS 3.1 · first observed Aug 6, 2026 · same-version scores align in this snapshot
Evidence detail
Source limits and decisions
Why each evidence state has this value
Outside this view’s verified evidenceReason detail begins outside this selected snapshot; the state remains source-bound.
Source comparison
Who said what
Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability
98.54% probability · 99.92th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.985360000000; percentile 0.999170000000
CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
CVE Program Container
Inspect raw assertion
- Field
container- Value
- CVE Program Container
Multiple vulnerabilities in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier allow remote attackers to execute arbitrary code via a crafted applet that bypasses SecurityManager restrictions by (1) using com.sun.beans.finder.ClassFinder.findClass and leveraging an exception with the forName method to access restricted classes from arbitrary packages such as sun.awt.SunToolkit, then (2) using "reflection with a trusted immediate caller" to leverage the getField method to access and modify private fields, as exploited in the wild in August 2012 using Gondzz.class and Gondvv.class.
Inspect raw assertion
- Field
container- Value
- Multiple vulnerabilities in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier allow remote attackers to execute arbitrary code via a crafted applet that bypasses SecurityManager restrictions by (1) using com.sun.beans.finder.ClassFinder.findClass and leveraging an exception with the forName method to access restricted classes from arbitrary packages such as sun.awt.SunToolkit, then (2) using "reflection with a trusted immediate caller" to leverage the getField method to access and modify private fields, as exploited in the wild in August 2012 using Gondzz.class and Gondvv.class.
Applicability
Cited product scope
Grouped from 2 configuration nodes in this exact snapshot. Visual grouping is navigational; asset exposure and root cause require cited evidence.
Identity source boundaries
- Cpe dictionary1,775,266 records · observed through 2026-07-21T06:45:29.809Z
27d65b0f-b718-4b4f-bb79-c47c68d09dfa - Cpe match643,502 records · observed through 2026-07-21T08:13:17.697Z
955dae73-7302-438b-aee1-058d7cc5d48e
7 scope groups
Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "n/a"}]product-6c94a14e5689a64227066e3f60eeb2b8b30045bcbf08047234f29f3fdd35d120Linked exactInspect raw assertions
cpe:2.3:a:oracle:jdk:1.6.0:update33:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 26
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
0381ee39-2f60-49fd-a63a-b9e81c9033cb
cpe:2.3:a:oracle:jdk:1.7.0:update3:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 37
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
52eeea5a-e77c-43cf-a063-9d5c64ea1870
cpe:2.3:a:oracle:jdk:1.6.0:update25:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 18
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
c3ec13d3-4ce7-459c-a7d7-7d38c1284720
cpe:2.3:a:oracle:jdk:1.6.0:update13:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 5
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
42c95c1d-0c2e-4733-ab1b-65650d88995d
cpe:2.3:a:oracle:jdk:1.6.0:update19:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 11
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
81a4204e-6f50-45fb-a343-7a30c0cd6d3d
cpe:2.3:a:oracle:jdk:1.7.0:update6:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 40
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
6bae3670-0938-480a-8472-dff0b3a0d0bf
cpe:2.3:a:oracle:jdk:1.6.0:update24:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 17
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
352509fe-54d9-4a59-98b7-96e5e98bc2cf
cpe:2.3:a:oracle:jdk:1.6.0:update23:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 16
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
6c9215d9-db64-4cee-85e6-e247035efb09
cpe:2.3:a:oracle:jdk:1.6.0:update2:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 12
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
d6e07069-d6ee-4d44-94a6-cdca4a50e6f9
cpe:2.3:a:oracle:jdk:1.6.0:update34:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 27
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
9ad75455-b7f0-4f42-98e7-caa43787d606
cpe:2.3:a:oracle:jdk:1.6.0:update22:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 15
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
301e96a3-ad2f-48f3-9166-571bd6f9fae3
cpe:2.3:a:oracle:jdk:1.6.0:update32:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 25
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
fb7e911c-c780-440a-abff-cce09061bb4f
cpe:2.3:a:oracle:jdk:1.6.0:update21:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 14
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
6db4f19e-dfc4-42f4-87b9-32fb1c496649
cpe:2.3:a:oracle:jdk:1.6.0:update12:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 4
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
1f3c1e65-929a-4468-8584-f086e6e59839
cpe:2.3:a:oracle:jdk:1.6.0:update1:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 1
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
b8ca8719-7abe-4279-b49e-c414794a4fe1
cpe:2.3:a:oracle:jdk:1.6.0:update7:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 31
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
d5d9d9a7-8819-44a4-80ac-52d6b63a0c9b
cpe:2.3:a:oracle:jdk:1.6.0:update17:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 9
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
3fc2226b-cfef-48a4-83ea-1f59f4af7528
cpe:2.3:a:oracle:jdk:1.6.0:update8:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 32
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
feb2c8a3-e0dc-46a3-bd82-8e45da55ed0e
cpe:2.3:a:oracle:jdk:1.7.0:-:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 34
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
acabc935-5dd6-4f85-992e-70ad517ef41d
cpe:2.3:a:oracle:jdk:1.6.0:-:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
4a420da5-1346-446b-8d23-e1e6ddbe527e
cpe:2.3:a:oracle:jdk:1.6.0:update4:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 28
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
d081a380-5aa4-4451-94a9-7b65810106e3
cpe:2.3:a:oracle:jdk:1.6.0:update15:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 7
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
d45b0d7e-ba0f-4aaa-a7ba-2ada4cc90d94
cpe:2.3:a:oracle:jdk:1.6.0:update27:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 20
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
1824da2d-26d5-4595-8376-8e41ab8c5e52
cpe:2.3:a:oracle:jdk:1.6.0:update30:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 23
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
60d05860-9424-4727-b583-74a35bc9bdfd
cpe:2.3:a:oracle:jdk:1.6.0:update31:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 24
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
f85db431-fea4-42e7-ac29-6b66174dcd9e
cpe:2.3:a:oracle:jdk:1.6.0:update14:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 6
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
47a9f499-d1e3-41bd-ac18-e8d3d3231c12
cpe:2.3:a:oracle:jdk:1.7.0:update2:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 36
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
d375cecb-405c-4e18-a7e8-9c5a2f97bd69
cpe:2.3:a:oracle:jdk:1.7.0:update4:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 38
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
003746f6-def0-4d0f-ad97-9e335868e301
cpe:2.3:a:oracle:jdk:1.7.0:update1:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 35
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
6152036d-6421-4ae4-9223-766fe07b5a44
cpe:2.3:a:oracle:jdk:1.6.0:update11:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 3
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
2abc1045-7d3d-4a14-b994-7e60a4bb4c9c
cpe:2.3:a:oracle:jdk:1.6.0:update3:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 22
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
344fa3ea-9e25-493c-976a-211d1404b251
cpe:2.3:a:oracle:jdk:1.6.0:update10:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 2
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
dc92b7ec-849f-4255-9d55-43681b8dadc4
cpe:2.3:a:oracle:jdk:1.6.0:update20:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 13
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
4b151882-47c0-400e-bbab-a949e6140c86
cpe:2.3:a:oracle:jdk:1.6.0:update29:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 21
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
b72f78b7-10d1-49cf-ac4d-3b10921cb633
cpe:2.3:a:oracle:jdk:1.6.0:update18:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 10
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
f29dc78f-4d02-47b4-a955-32080b22356c
cpe:2.3:a:oracle:jdk:1.6.0:update16:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 8
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
d58a3e4f-2409-440a-891e-0b84d79ab480
cpe:2.3:a:oracle:jdk:1.6.0:update9:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 33
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
64b5b16d-061a-438d-a8cf-9e63d6c748d7
cpe:2.3:a:oracle:jdk:1.6.0:update5:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 29
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
112e7575-a3a0-4a94-ad39-7b2325b150b8
cpe:2.3:a:oracle:jdk:1.6.0:update26:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 19
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
8cdcd1b4-c5f3-4188-b05f-23922f7de517
cpe:2.3:a:oracle:jdk:1.7.0:update5:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 39
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
cf830e0e-0169-4b6a-81ff-2e9fcd7d913b
cpe:2.3:a:oracle:jdk:1.6.0:update6:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 30
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
708e8cef-82ee-4d4b-abf9-87aa4878f517
product-70c0761d49c3bbe44615490ef7b613557bcd3ccdfa71d09d74202c114d277fb7Linked exactInspect raw assertions
cpe:2.3:a:oracle:jre:1.6.0:update34:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 68
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
738ec3e5-a4eb-47fe-9c9a-7c8e8c669765
cpe:2.3:a:oracle:jre:1.6.0:update4:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 69
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
964ccfd6-316a-48c6-9a6b-7cfd1a1fb027
cpe:2.3:a:oracle:jre:1.6.0:update19:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 52
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
77c54e00-0197-4c87-9bff-01a099ac3006
cpe:2.3:a:oracle:jre:1.6.0:update10:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 43
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
d16229b8-1642-4c10-8650-a9cea9d4c98c
cpe:2.3:a:oracle:jre:1.6.0:update25:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 59
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
cd7c4194-d34a-418f-9b00-5c6012844aae
cpe:2.3:a:oracle:jre:1.6.0:update27:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 61
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
f0b82fb1-0f0e-44f9-87ae-628517279e4d
cpe:2.3:a:oracle:jre:1.7.0:update1:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 75
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
f4b153fd-e20b-4909-8b10-884e48f5b590
cpe:2.3:a:oracle:jre:1.7.0:update3:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 77
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
5831d70b-3854-4cb8-b88d-40f1743daee0
cpe:2.3:a:oracle:jre:1.6.0:update14:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 47
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
3b02f361-0c64-4cb8-8dad-a63f1a9cc025
cpe:2.3:a:oracle:jre:1.6.0:update21:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 55
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
52fa600c-08b6-4143-9c72-db31e489de3e
cpe:2.3:a:oracle:jre:1.6.0:update29:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 62
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
a0a67640-2f4a-488a-9d8f-3fe1f4da8def
cpe:2.3:a:oracle:jre:1.6.0:update1:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 42
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
f199b346-b95e-4dca-b750-148a36d559ba
cpe:2.3:a:oracle:jre:1.6.0:update32:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 66
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
8e76476e-4120-46a9-90a8-a95fe89636cd
cpe:2.3:a:oracle:jre:1.6.0:update6:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 71
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
6c59c275-5964-4e5d-be80-ba4ea34bea62
cpe:2.3:a:oracle:jre:1.7.0:update4:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 78
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
eeb101c9-ca38-4421-bc0c-c1ad47aa2cc9
cpe:2.3:a:oracle:jre:1.6.0:update17:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 50
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
d7823ae6-cb18-47de-8a4f-1f98394b7237
cpe:2.3:a:oracle:jre:1.6.0:update12:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 45
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
830a3a51-f17a-4c61-8f5c-6a4582a64da6
cpe:2.3:a:oracle:jre:1.6.0:update31:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 65
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
23cda4f0-c32b-4b08-a377-7d4426c2f569
cpe:2.3:a:oracle:jre:1.6.0:update26:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 60
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
daf7d86b-1b4d-4e1f-9ef0-da7e419d7e99
cpe:2.3:a:oracle:jre:1.6.0:update13:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 46
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
9de0e496-719d-4cef-837f-b060a898099f
cpe:2.3:a:oracle:jre:1.6.0:update9:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 73
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
6b3a8681-3eac-4d02-811a-5fcccc7b5635
cpe:2.3:a:oracle:jre:1.6.0:update24:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 58
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
b1c57774-ad93-4162-8e45-92b09139c808
cpe:2.3:a:oracle:jre:1.7.0:update5:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 79
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
ba302df3-abbb-4262-b206-4c0f7b5b1e91
cpe:2.3:a:oracle:jre:1.6.0:update30:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 64
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
0d60d98d-4363-44a0-aab4-b61ba623ee21
cpe:2.3:a:oracle:jre:1.6.0:update5:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 70
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
dc8771d7-9531-4a1d-b2de-faa7a7549801
cpe:2.3:a:oracle:jre:1.7.0:-:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 74
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
dfaa351a-93cd-46a8-a480-ce2783ccd620
cpe:2.3:a:oracle:jre:1.6.0:update20:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 54
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
7415177f-a2fe-47ab-8d92-194a4f6d75c8
cpe:2.3:a:oracle:jre:1.6.0:update15:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 48
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
fd4cc3e2-7bea-4d8c-811c-c5012327a9aa
cpe:2.3:a:oracle:jre:1.6.0:update11:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 44
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
1714bdef-6b0e-42bb-9510-3f9b52e170bc
cpe:2.3:a:oracle:jre:1.6.0:update18:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 51
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
381efa43-db73-48ea-a4b1-f451ef60d845
cpe:2.3:a:oracle:jre:1.6.0:update16:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 49
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
9f63a8ac-893d-4d75-b467-85e70b62541d
cpe:2.3:a:oracle:jre:1.6.0:update3:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 63
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
2752b83a-6dd2-4829-9e4f-42cddcbc38c0
cpe:2.3:a:oracle:jre:1.7.0:update6:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 80
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
f9a8ebcb-5e6a-42f0-8d07-f3a3d1c850f0
cpe:2.3:a:oracle:jre:1.6.0:update33:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 67
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
97a84689-0ced-404f-8dc3-708beb37d2ce
cpe:2.3:a:oracle:jre:1.6.0:update7:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 72
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
47c1922b-37e8-4009-97c7-b243f6f96704
cpe:2.3:a:oracle:jre:1.7.0:update2:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 76
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
cb106fa9-26ce-48c5-aea5-fd1a5454aee2
cpe:2.3:a:oracle:jre:1.6.0:update22:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 56
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
ef13b96d-1f80-4672-8da3-f86f6d3bf070
cpe:2.3:a:oracle:jre:1.6.0:update23:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 57
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
d1a2d440-d966-41a6-955d-38b28dde0fdb
cpe:2.3:a:oracle:jre:1.6.0:update2:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 53
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
64ad6007-eb92-4d0e-a0cb-8ffddb61aa6d
cpe:2.3:a:oracle:jre:1.6.0:-:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 41
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
eb864346-1429-46b5-a91e-a1126c486421
product-ebce605e64c58caa7df6a30e91702332cd8c0be8f801e44353e6350e913ec5aeLinked exactInspect raw assertion
cpe:2.3:o:redhat:enterprise_linux_desktop:6.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
ee249e1b-a1fd-4e08-aa71-a0e1f10ffe97
product-8abf8d7f0342f690712d750b6cf7fbf4068eb0134c40a51c5b57b074f81c6378Linked exactInspect raw assertion
cpe:2.3:o:redhat:enterprise_linux_eus:6.3:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 1
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
8382a145-cdd9-437e-9de7-a349956778b3
product-8db20157ede2f731f576213a7e555a24d2424bb17aed8e43ad9b77c3587f9deaLinked exactInspect raw assertion
cpe:2.3:o:redhat:enterprise_linux_server:6.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 2
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
9bbcd86a-e6c7-4444-9d74-f861084090f0
product-b2aa744c9fb2b4ef0e3b842acbf37879ad4ac43af291292cfb0906170b204ab9Linked exactInspect raw assertion
cpe:2.3:o:redhat:enterprise_linux_workstation:6.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 3
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
e5ed5807-55b7-47c5-97a6-03233f4fbc3a
Affected-product evidence
Accepted scope and product mapping
0 canonical links · 0 source-reported links
Applicability remains source-scoped; safety and exposure remain unassessed.
Assessments
CVSS by origin
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HAV:N/AC:L/Au:N/C:C/I:C/A:CCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HEvidence boundaries
- KEV membership is authoritative for the catalog, not proof of exposure in any environment.
- EPSS is a dated model probability and not an individual-environment prediction.
- Affected or fixed status applies only to the exact cited product and version scope; remaining scope stays source-scoped.
- NVD-carried upstream facts remain derivative; independent corroboration requires a separately authored source.
- Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
- NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
- Affected-product evidence remains source-scoped; canonical linkage is required before applicability scoring.
- Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.
- OSV aggregation and OSV-converted NVD material are not independent corroboration.
- Red Hat facts are vendor assertions for the exact supplied products.
- Nonmembership and not-yet-observed states are not proof of safety.