Описание
Multiple serious vulnerabilities were found in Oracle Java SE. Malicious users can exploit these vulnerabilities to execute arbitrary code, obtain sensitive information, cause denial of service, bypass security restrictions.
Below is a complete list of vulnerabilities:
- An unspecified vulnerability in Scripting component can be exploited remotely to execute arbitrary code;
- An unspecified vulnerability in JavaFX component can be exploited remotely to execute arbitrary code;
- An unspecified vulnerability in Hotspot component can be exploited remotely to execute arbitrary code;
- An unspecified vulnerability in JNDI component can be exploited locally to execute arbitrary code;
- An unspecified vulnerability in Serviceability component can be exploited remotely to obtain sensitive information;
- An unspecified vulnerability in JSSE component can be exploited remotely to obtain sensitive information;
- An unspecified vulnerability in Sound component can be exploited remotely to cause denial of service;
- An unspecified vulnerability in Sound component can be exploited remotely to obtain sensitive information;
- An unspecified vulnerability in Utility component can be exploited remotely to bypass security restrictions;
- An unspecified vulnerability in libpng can be exploited remotely to cause denial of service;
- An unspecified vulnerability in Security component can be exploited remotely to bypass security restrictions;
- An unspecified vulnerability in Networking component can be exploited remotely to bypass security restrictions;
Первичный источник обнаружения
Эксплуатация
Public exploits exist for this vulnerability.
Связанные продукты
Список CVE
- CVE-2018-3183 critical
- CVE-2018-3209 critical
- CVE-2018-3169 critical
- CVE-2018-3149 critical
- CVE-2018-3211 high
- CVE-2018-3180 high
- CVE-2018-3214 high
- CVE-2018-3157 warning
- CVE-2018-3150 warning
- CVE-2018-13785 high
- CVE-2018-3136 warning
- CVE-2018-3139 warning
Смотрите также
Узнай статистику распространения уязвимостей в своем регионе statistics.securelist.com
Нашли неточность в описании этой уязвимости? Дайте нам знать!