Vulnerability Database

289,697

Total vulnerabilities in the database

CVE-2016-0483

Unspecified vulnerability in Oracle Java SE 6u105, 7u91, and 8u66; Java SE Embedded 8u65; and JRockit R28.3.8 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to AWT. NOTE: the previous information is from the January 2016 CPU. Oracle has not commented on third-party claims that this is a heap-based buffer overflow in the readImage function, which allows remote attackers to execute arbitrary code via crafted image data.

  • Published: Jan 21, 2016
  • Updated: Apr 13, 2023
  • CVE: CVE-2016-0483
  • Severity: High
  • Exploit:

CVSS v2:

  • Severity: High
  • Score: 10
  • AV:N/AC:L/Au:N/C:C/I:C/A:C

No CWE or OWASP classifications available.

Software From Fixed in
oracle / jdk 1.8.0-update66 1.8.0-update66.x
oracle / jdk 1.6.0-update105 1.6.0-update105.x
oracle / jdk 1.7.0-update91 1.7.0-update91.x
oracle / jre 1.6.0-update105 1.6.0-update105.x
oracle / jre 1.7.0-update91 1.7.0-update91.x
oracle / jre 1.8.0-update66 1.8.0-update66.x
oracle / jrockit r28.3.8 r28.3.8.x
canonical / ubuntu_linux 12.04 12.04.x
canonical / ubuntu_linux 15.10 15.10.x
canonical / ubuntu_linux 14.04 14.04.x
canonical / ubuntu_linux 15.04 15.04.x