CVE-2015-0460: Critical severity oracle java se 7 vulnerability

Published Apr 13, 2015
·
Updated

A flaw was found in the way the Hotspot JVM handled phantom references. An untrusted Java application or applet could use this flaw to corrupt JVM memory and, possibly, execute arbitrary code, bypassing Java sandbox restrictions.

This fix corrects the patch for CVE-2015-0395 (bug 1183031) fixed in Jan 2015 CPU.

Other sources

Unspecified vulnerability in Oracle Java SE 5.0u81, 6u91, 7u76, and 8u40 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Hotspot.

MITRE

Affected Software

10 affected componentsFixes available
redhat/IcedTea6<1.13.7
1.13.7
redhat/IcedTea7<2.5.5
2.5.5
Oracle JDK=1.5.0-update8
Oracle JDK=1.6.0-update91
Oracle JDK=1.7.0-update76
Oracle JDK=1.8.0-update40
ORACLE JRE=1.5.0-update81
ORACLE JRE=1.6.0-update91
ORACLE JRE=1.7.0-update76
ORACLE JRE=1.8.0-update40

Event History

Apr 16, 2015
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description

Frequently Asked Questions

1

What is the severity of CVE-2015-0460?

CVE-2015-0460 is a significant vulnerability that can affect confidentiality, integrity, and availability, making it critical to address.

2

How do I fix CVE-2015-0460?

To remediate CVE-2015-0460, update your Oracle Java SE or IcedTea packages to the latest recommended versions.

3

Which versions of Oracle Java are affected by CVE-2015-0460?

CVE-2015-0460 affects Oracle Java SE versions 5.0u81, 6u91, 7u76, and 8u40.

4

Is IcedTea vulnerable to CVE-2015-0460?

Yes, IcedTea6 and IcedTea7 are vulnerable to CVE-2015-0460 if they are at versions below 1.13.7 and 2.5.5 respectively.

5

What applications are impacted by CVE-2015-0460?

Applications utilizing vulnerable versions of Oracle Java or IcedTea can be impacted by CVE-2015-0460, particularly untrusted Java applications.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203