CVE-2015-4877

Oracle Fusion Middleware 8.5.0-8.5.2 - Denial of Service in Outside In Filters

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2015-4877. PoCs published by Francis Provencher.

AI-analyzed exploit summary The document describes a heap memory corruption vulnerability in Oracle Outside In Technology (CVE-2015-4877) when processing PDFs with malformed JPEG height values. It includes a timeline and references to PoC files but does not contain exploit code itself.

Description

Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.5.0, 8.5.1, and 8.5.2 allows local users to affect availability via unknown vectors related to Outside In Filters, a different vulnerability than CVE-2015-4878.

Exploits (1)

exploitdb WRITEUP
by Francis Provencher · textdoswindows
https://www.exploit-db.com/exploits/38788

The document describes a heap memory corruption vulnerability in Oracle Outside In Technology (CVE-2015-4877) when processing PDFs with malformed JPEG height values. It includes a timeline and references to PoC files but does not contain exploit code itself.

Classification
Writeup 90%
Attack Type
Rce
Complexity
Moderate
Reliability
Theoretical
Target: Oracle Outside In Technology 8.5.2
No auth needed
Prerequisites: User interaction to open a malicious PDF file
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (6)

Core 6
Core References
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/536762/100/0/threaded
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/38788/
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1033898
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/77130

Scores

EPSS 0.0091
EPSS Percentile 55.2%

Details

Status published
Products (3)
oracle/fusion_middleware 8.5.0
oracle/fusion_middleware 8.5.1
oracle/fusion_middleware 8.5.2
Published Oct 21, 2015
Tracked Since Feb 18, 2026