CVE-2012-0500

Oracle Java SE <7.2 - Info Disclosure

Title source: llm

Description

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, and JavaFX 2.0.2 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality, integrity, and availability via unknown vectors related to Deployment.

Exploits (3)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotewindows
https://www.exploit-db.com/exploits/18520
metasploit WORKING POC EXCELLENT
rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/browser/java_ws_double_quote.rb
metasploit WORKING POC EXCELLENT
rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/browser/java_ws_vmargs.rb

Scores

EPSS 0.7485
EPSS Percentile 98.9%

Details

Status published
Products (12)
oracle/javafx 1.2
oracle/javafx 1.2.2
oracle/javafx 1.2.3
oracle/javafx 1.3.0
oracle/javafx 1.3.1
oracle/javafx 2.0
oracle/javafx < 2.0.2
oracle/jre 1.6.0 update22 (7 CPE variants)
oracle/jre 1.7.0 (2 CPE variants)
oracle/jre < 1.6.0
... and 2 more
Published Feb 15, 2012
Tracked Since Feb 18, 2026