CVE-2011-0866

UnknownEPSS 2.95%

Last modified

CVE-2011-0866 is a vulnerability of currently unknown severity. Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 6 Update 25 and earlier, 5.0 Update 29 and earlier, and 1.4.2_31 and earlier, when running on Windows, allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality, integrity, and availability via unknown vectors related to Java Runtime Environment.. EPSS estimates a 2.95% chance of exploitation in the next 30 days.

Description

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 6 Update 25 and earlier, 5.0 Update 29 and earlier, and 1.4.2_31 and earlier, when running on Windows, allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality, integrity, and availability via unknown vectors related to Java Runtime Environment.

Metrics

EPSS Probability
2.95%

85.4th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

VendorProductVersionsUpdate
SunJdk<= 1.4.2_31
SunJdk1.4.2
SunJdk1.4.2_1
SunJdk1.4.2_2
SunJdk1.4.2_3
SunJdk1.4.2_4
SunJdk1.4.2_5
SunJdk1.4.2_6
SunJdk1.4.2_7
SunJdk1.4.2_8
SunJdk1.4.2_9
SunJdk1.4.2_10
SunJdk1.4.2_11
SunJdk1.4.2_12
SunJdk1.4.2_13
SunJdk1.4.2_14
SunJdk1.4.2_15
SunJdk1.4.2_16
SunJdk1.4.2_17
SunJdk1.4.2_18
SunJdk1.4.2_19
SunJdk1.4.2_20
SunJdk1.4.2_21
SunJdk1.4.2_22
SunJdk1.4.2_23
SunJdk1.4.2_24
SunJdk1.4.2_25
SunJdk1.4.2_26
SunJdk1.4.2_27
SunJdk1.4.2_28
SunJdk1.4.2_29
SunJdk1.4.2_30
SunJre<= 1.4.2_31
SunJre1.4.2
SunJre1.4.2_1
SunJre1.4.2_2
SunJre1.4.2_3
SunJre1.4.2_4
SunJre1.4.2_5
SunJre1.4.2_6
SunJre1.4.2_7
SunJre1.4.2_8
SunJre1.4.2_9
SunJre1.4.2_10
SunJre1.4.2_11
SunJre1.4.2_12
SunJre1.4.2_13
SunJre1.4.2_14
SunJre1.4.2_15
SunJre1.4.2_16

Showing 50 of 72 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2011-0866?
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 6 Update 25 and earlier, 5.0 Update 29 and earlier, and 1.4.2_31 and earlier, when running on Windows, allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality, integrity, and availability via unknown vectors related to Java Runtime Environment.
How severe is CVE-2011-0866?
Severity scoring for CVE-2011-0866 is pending analysis. The EPSS model estimates a 2.95% probability of exploitation in the next 30 days.
How do I fix CVE-2011-0866?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2011-0866?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST