CVE-2016-3508
Summary
| CVE | CVE-2016-3508 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2016-07-21 10:13:00 UTC |
| Updated | 2022-05-13 14:57:00 UTC |
| Description | Unspecified vulnerability in Oracle Java SE 6u115, 7u101, and 8u92; Java SE Embedded 8u91; and JRockit R28.3.10 allows remote attackers to affect availability via vectors related to JAXP, a different vulnerability than CVE-2016-3500. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Oracle | Jdk | 1.6.0 | update115 | All | All |
| Application | Oracle | Jdk | 1.6.0 | update_115 | All | All |
| Application | Oracle | Jdk | 1.7.0 | update101 | All | All |
| Application | Oracle | Jdk | 1.8.0 | update91 | All | All |
| Application | Oracle | Jdk | 1.8.0 | update92 | All | All |
| Application | Oracle | Jdk | 1.6.0 | update_115 | All | All |
| Application | Oracle | Jdk | 1.7.0 | update101 | All | All |
| Application | Oracle | Jdk | 1.8.0 | update91 | All | All |
| Application | Oracle | Jdk | 1.8.0 | update92 | All | All |
| Application | Oracle | Jre | 1.6.0 | update115 | All | All |
| Application | Oracle | Jre | 1.6.0 | update_115 | All | All |
| Application | Oracle | Jre | 1.7.0 | update101 | All | All |
| Application | Oracle | Jre | 1.7.0 | update_101 | All | All |
| Application | Oracle | Jre | 1.8.0 | update91 | All | All |
| Application | Oracle | Jre | 1.8.0 | update92 | All | All |
| Application | Oracle | Jre | 1.8.0 | update_91 | All | All |
| Application | Oracle | Jre | 1.8.0 | update_92 | All | All |
| Application | Oracle | Jre | 1.6.0 | update_115 | All | All |
| Application | Oracle | Jre | 1.7.0 | update_101 | All | All |
| Application | Oracle | Jre | 1.8.0 | update_91 | All | All |
| Application | Oracle | Jre | 1.8.0 | update_92 | All | All |
| Application | Oracle | Jrockit | r28.3.10 | All | All | All |
| Application | Oracle | Jrockit | r28.3.10 | All | All | All |
| Operating System | Oracle | Linux | 5.0 | All | All | All |
| Operating System | Oracle | Linux | 6 | All | All | All |
| Operating System | Oracle | Linux | 7 | All | All | All |
| Operating System | Oracle | Linux | 5.0 | All | All | All |
| Operating System | Oracle | Linux | 6 | All | All | All |
| Operating System | Oracle | Linux | 7 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Oracle Critical Patch Update - July 2016 | CONFIRM | www.oracle.com | Patch, Vendor Advisory |
| USN-3043-1: OpenJDK 8 vulnerabilities | Ubuntu | UBUNTU | www.ubuntu.com | |
| IcedTea: Multiple vulnerabilities (GLSA 201701-43) — Gentoo security | GENTOO | security.gentoo.org | |
| Oracle July 2016 Critical Patch Update Multiple Vulnerabilities | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| McAfee KnowledgeBase - Intel Security - Security Bulletin: ePolicy Orchestrator update fixes multiple Oracle Java vulnerabilities (CVE-2016-3500, CVE-2016-3508, and CVE-2016-3485) | CONFIRM | kc.mcafee.com | |
| Red Hat Customer Portal | REDHAT | rhn.redhat.com | |
| [security-announce] openSUSE-SU-2016:2052-1: important: Security update | SUSE | lists.opensuse.org | |
| [security-announce] openSUSE-SU-2016:2051-1: important: Security update | SUSE | lists.opensuse.org | |
| Debian -- Security Information -- DSA-3641-1 openjdk-7 | DEBIAN | www.debian.org | |
| Oracle Linux Bulletin - July 2016 | CONFIRM | www.oracle.com | Vendor Advisory |
| Oracle JRE/JDK: Multiple vulnerabilities (GLSA 201610-08) — Gentoo Security | GENTOO | security.gentoo.org | |
| Oracle Java SE Multiple Flaws Let Remote Users Access and Modify Data and Deny Service, Local Users Modify Data, and Remote and Local Users Gain Elevated Privileges - SecurityTracker | SECTRACK | www.securitytracker.com | |
| Oracle Java SE and JRockit CVE-2016-3508 Remote Security Vulnerability | BID | www.securityfocus.com | |
| USN-3077-1: OpenJDK 6 vulnerabilities | Ubuntu | UBUNTU | www.ubuntu.com | |
| Red Hat Customer Portal | REDHAT | rhn.redhat.com | |
| [security-announce] SUSE-SU-2016:1997-1: important: Security update for | SUSE | lists.opensuse.org | |
| USN-3062-1: OpenJDK 7 vulnerabilities | Ubuntu | UBUNTU | www.ubuntu.com | |
| [security-announce] SUSE-SU-2016:2012-1: important: Security update for | SUSE | lists.opensuse.org | |
| Red Hat Customer Portal | REDHAT | access.redhat.com | |
| July 2016 Java Platform Standard Edition Vulnerabilities in Multiple NetApp Products | NetApp Product Security | CONFIRM | security.netapp.com | |
| Red Hat Customer Portal | REDHAT | access.redhat.com | |
| [security-announce] openSUSE-SU-2016:2050-1: important: Security update | SUSE | lists.opensuse.org | |
| Red Hat Customer Portal | REDHAT | access.redhat.com | |
| [security-announce] openSUSE-SU-2016:2058-1: important: Security update | SUSE | lists.opensuse.org | |
| Red Hat Customer Portal | REDHAT | access.redhat.com | |
| openSUSE-SU-2016:1979-1: moderate: Security update for java-1_8_0-openjd | SUSE | lists.opensuse.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.