CVE-2015-0460: Critical severity oracle java se 7 vulnerability
A flaw was found in the way the Hotspot JVM handled phantom references. An untrusted Java application or applet could use this flaw to corrupt JVM memory and, possibly, execute arbitrary code, bypassing Java sandbox restrictions.
This fix corrects the patch for CVE-2015-0395 (bug 1183031) fixed in Jan 2015 CPU.
Other sources
Unspecified vulnerability in Oracle Java SE 5.0u81, 6u91, 7u76, and 8u40 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Hotspot.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-0460?
CVE-2015-0460 is a significant vulnerability that can affect confidentiality, integrity, and availability, making it critical to address.
How do I fix CVE-2015-0460?
To remediate CVE-2015-0460, update your Oracle Java SE or IcedTea packages to the latest recommended versions.
Which versions of Oracle Java are affected by CVE-2015-0460?
CVE-2015-0460 affects Oracle Java SE versions 5.0u81, 6u91, 7u76, and 8u40.
Is IcedTea vulnerable to CVE-2015-0460?
Yes, IcedTea6 and IcedTea7 are vulnerable to CVE-2015-0460 if they are at versions below 1.13.7 and 2.5.5 respectively.
What applications are impacted by CVE-2015-0460?
Applications utilizing vulnerable versions of Oracle Java or IcedTea can be impacted by CVE-2015-0460, particularly untrusted Java applications.