JDK: unspecified vulnerability fixed in 6u115, 7u101 and 8u91 (2D)
Published Apr 21, 2016
9.6
CRITICALCVSS 3.0
EPSS 5.48%
Description
Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to 2D. NOTE: the previous information is from the April 2016 CPU. Oracle has not commented on third-party claims that this issue allows remote attackers to obtain sensitive information via crafted font data, which triggers an out-of-bounds read.
Affected products
No data.
No data.
Oracle Java for Red Hat Enterprise Linux 5
java-1.6.0-sun-1:1.6.0.115-1jpp.1.el5_11
Fixed · RHSA-2016:0679
Oracle Java for Red Hat Enterprise Linux 5
java-1.7.0-oracle-1:1.7.0.101-1jpp.1.el5_11
Fixed · RHSA-2016:0678
Oracle Java for Red Hat Enterprise Linux 6
java-1.6.0-sun-1:1.6.0.115-1jpp.1.el6_7
Fixed · RHSA-2016:0679
Oracle Java for Red Hat Enterprise Linux 6
java-1.7.0-oracle-1:1.7.0.101-1jpp.1.el6_7
Fixed · RHSA-2016:0678
Oracle Java for Red Hat Enterprise Linux 6
java-1.8.0-oracle-1:1.8.0.91-1jpp.1.el6_7
Fixed · RHSA-2016:0677
Oracle Java for Red Hat Enterprise Linux 7
java-1.6.0-sun-1:1.6.0.115-1jpp.1.el7
Fixed · RHSA-2016:0679
Oracle Java for Red Hat Enterprise Linux 7
java-1.7.0-oracle-1:1.7.0.101-1jpp.1.el7
Fixed · RHSA-2016:0678
Oracle Java for Red Hat Enterprise Linux 7
java-1.8.0-oracle-1:1.8.0.91-1jpp.1.el7
Fixed · RHSA-2016:0677
Red Hat Enterprise Linux 5 Supplementary
java-1.6.0-ibm-1:1.6.0.16.25-1jpp.1.el5
Fixed · RHSA-2016:0708
Red Hat Enterprise Linux 5 Supplementary
java-1.7.0-ibm-1:1.7.0.9.40-1jpp.1.el5
Fixed · RHSA-2016:0702
Red Hat Enterprise Linux 6 Supplementary
java-1.6.0-ibm-1:1.6.0.16.25-1jpp.1.el6_7
Fixed · RHSA-2016:0708
Red Hat Enterprise Linux 6 Supplementary
java-1.7.1-ibm-1:1.7.1.3.40-1jpp.1.el6_7
Fixed · RHSA-2016:0701
Red Hat Enterprise Linux 6 Supplementary
java-1.8.0-ibm-1:1.8.0.3.0-1jpp.1.el6
Fixed · RHSA-2016:1039
Red Hat Enterprise Linux 7 Supplementary
java-1.7.1-ibm-1:1.7.1.3.40-1jpp.1.el7
Fixed · RHSA-2016:0701
Red Hat Enterprise Linux 7 Supplementary
java-1.8.0-ibm-1:1.8.0.3.0-1jpp.1.el7
Fixed · RHSA-2016:0716
Red Hat Satellite 5.6
java-1.7.0-ibm-1:1.7.0.9.40-1jpp.1.el5
Fixed · RHSA-2016:1430
Red Hat Satellite 5.6
java-1.7.1-ibm-1:1.7.1.3.40-1jpp.1.el6_7
Fixed · RHSA-2016:1430
Red Hat Satellite 5.6
java-1.7.1-ibm-1:1.7.1.4.1-1jpp.1.el6_8
Fixed · RHSA-2017:1216
Red Hat Satellite 5.6
spacewalk-java-0:2.0.2-109.el5sat
Fixed · RHSA-2016:1430
Red Hat Satellite 5.7
java-1.7.1-ibm-1:1.7.1.3.40-1jpp.1.el6_7
Fixed · RHSA-2016:1430
Red Hat Satellite 5.7
java-1.7.1-ibm-1:1.7.1.4.1-1jpp.1.el6_8
Fixed · RHSA-2017:1216
Red Hat Satellite 5.7
spacewalk-java-0:2.3.8-146.el6sat
Fixed · RHSA-2016:1430
| Product | Package | State | Advisory |
|---|---|---|---|
| Oracle Java for Red Hat Enterprise Linux 5 | java-1.6.0-sun-1:1.6.0.115-1jpp.1.el5_11 | Fixed | RHSA-2016:0679 |
| Oracle Java for Red Hat Enterprise Linux 5 | java-1.7.0-oracle-1:1.7.0.101-1jpp.1.el5_11 | Fixed | RHSA-2016:0678 |
| Oracle Java for Red Hat Enterprise Linux 6 | java-1.6.0-sun-1:1.6.0.115-1jpp.1.el6_7 | Fixed | RHSA-2016:0679 |
| Oracle Java for Red Hat Enterprise Linux 6 | java-1.7.0-oracle-1:1.7.0.101-1jpp.1.el6_7 | Fixed | RHSA-2016:0678 |
| Oracle Java for Red Hat Enterprise Linux 6 | java-1.8.0-oracle-1:1.8.0.91-1jpp.1.el6_7 | Fixed | RHSA-2016:0677 |
| Oracle Java for Red Hat Enterprise Linux 7 | java-1.6.0-sun-1:1.6.0.115-1jpp.1.el7 | Fixed | RHSA-2016:0679 |
| Oracle Java for Red Hat Enterprise Linux 7 | java-1.7.0-oracle-1:1.7.0.101-1jpp.1.el7 | Fixed | RHSA-2016:0678 |
| Oracle Java for Red Hat Enterprise Linux 7 | java-1.8.0-oracle-1:1.8.0.91-1jpp.1.el7 | Fixed | RHSA-2016:0677 |
| Red Hat Enterprise Linux 5 Supplementary | java-1.6.0-ibm-1:1.6.0.16.25-1jpp.1.el5 | Fixed | RHSA-2016:0708 |
| Red Hat Enterprise Linux 5 Supplementary | java-1.7.0-ibm-1:1.7.0.9.40-1jpp.1.el5 | Fixed | RHSA-2016:0702 |
| Red Hat Enterprise Linux 6 Supplementary | java-1.6.0-ibm-1:1.6.0.16.25-1jpp.1.el6_7 | Fixed | RHSA-2016:0708 |
| Red Hat Enterprise Linux 6 Supplementary | java-1.7.1-ibm-1:1.7.1.3.40-1jpp.1.el6_7 | Fixed | RHSA-2016:0701 |
| Red Hat Enterprise Linux 6 Supplementary | java-1.8.0-ibm-1:1.8.0.3.0-1jpp.1.el6 | Fixed | RHSA-2016:1039 |
| Red Hat Enterprise Linux 7 Supplementary | java-1.7.1-ibm-1:1.7.1.3.40-1jpp.1.el7 | Fixed | RHSA-2016:0701 |
| Red Hat Enterprise Linux 7 Supplementary | java-1.8.0-ibm-1:1.8.0.3.0-1jpp.1.el7 | Fixed | RHSA-2016:0716 |
| Red Hat Satellite 5.6 | java-1.7.0-ibm-1:1.7.0.9.40-1jpp.1.el5 | Fixed | RHSA-2016:1430 |
| Red Hat Satellite 5.6 | java-1.7.1-ibm-1:1.7.1.3.40-1jpp.1.el6_7 | Fixed | RHSA-2016:1430 |
| Red Hat Satellite 5.6 | java-1.7.1-ibm-1:1.7.1.4.1-1jpp.1.el6_8 | Fixed | RHSA-2017:1216 |
| Red Hat Satellite 5.6 | spacewalk-java-0:2.0.2-109.el5sat | Fixed | RHSA-2016:1430 |
| Red Hat Satellite 5.7 | java-1.7.1-ibm-1:1.7.1.3.40-1jpp.1.el6_7 | Fixed | RHSA-2016:1430 |
| Red Hat Satellite 5.7 | java-1.7.1-ibm-1:1.7.1.4.1-1jpp.1.el6_8 | Fixed | RHSA-2017:1216 |
| Red Hat Satellite 5.7 | spacewalk-java-0:2.3.8-146.el6sat | Fixed | RHSA-2016:1430 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
AV:N/AC:L/Au:N/C:C/I:C/A:C
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
TotalDecision
n/aAssessed Oct 15, 2024 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (15 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 5.48% (0.05479) | 92.51th | v5 (v2026.06.15) |
| Jun 15, 2026 | 5.48% (0.05479) | 91.72th | v5 (v2026.06.15) |
| May 1, 2026 | 3.00% (0.03005) | 86.62th | v4 (v2025.03.14) |
| Mar 30, 2025 | 4.20% (0.04203) | 87.67th | v4 (v2025.03.14) |
| Mar 29, 2025 | 9.90% (0.09898) | 88.25th | v4 (v2025.03.14) |
| Mar 17, 2025 | 4.20% (0.04203) | 87.98th | v4 (v2025.03.14) |
| Dec 27, 2024 | 7.57% (0.07574) | 94.11th | v3 (v2023.03.01) |
| May 21, 2024 | 4.39% (0.04388) | 92.36th | v3 (v2023.03.01) |
| Feb 12, 2024 | 3.14% (0.03144) | 90.76th | v3 (v2023.03.01) |
| Dec 8, 2023 | 2.73% (0.02729) | 89.40th | v3 (v2023.03.01) |
| Nov 4, 2023 | 2.52% (0.02520) | 88.99th | v3 (v2023.03.01) |
| Mar 7, 2023 | 2.05% (0.02051) | 87.20th | v3 (v2023.03.01) |
| Mar 6, 2023 | 3.93% (0.03932) | 85.88th | v2 (v2022.01.01) |
| Apr 1, 2022 | 3.93% (0.03932) | 84.43th | v2 (v2022.01.01) |
| Feb 4, 2022 | 3.93% (0.03932) | 67.70th | v2 (v2022.01.01) |
No CWE recorded.
References (29)
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00039.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00040.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00042.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00058.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00059.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00061.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00067.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00002.html vendor-advisoryx_refsource_SUSE
- http://rhn.redhat.com/errata/RHSA-2016-0677.html vendor-advisoryx_refsource_REDHAT
- http://rhn.redhat.com/errata/RHSA-2016-0678.html vendor-advisoryx_refsource_REDHAT
- http://rhn.redhat.com/errata/RHSA-2016-0679.html vendor-advisoryx_refsource_REDHAT
- http://rhn.redhat.com/errata/RHSA-2016-0701.html vendor-advisoryx_refsource_REDHAT
- http://rhn.redhat.com/errata/RHSA-2016-0702.html vendor-advisoryx_refsource_REDHAT
- http://rhn.redhat.com/errata/RHSA-2016-0708.html vendor-advisoryx_refsource_REDHAT
- http://rhn.redhat.com/errata/RHSA-2016-0716.html vendor-advisoryx_refsource_REDHAT
- http://rhn.redhat.com/errata/RHSA-2016-1039.html vendor-advisoryx_refsource_REDHAT
- http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html x_refsource_CONFIRMVendor Advisory
- http://www.oracle.com/technetwork/topics/security/cpuapr2016-2881694.html#AppendixJAVA
- http://www.securityfocus.com/bid/86482 vdb-entryx_refsource_BID
- http://www.securitytracker.com/id/1035596 vdb-entryx_refsource_SECTRACK
- http://www.zerodayinitiative.com/advisories/ZDI-16-376 x_refsource_MISC
- https://access.redhat.com/errata/RHSA-2016:1430 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2017:1216 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2016-3443 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1328618 Issue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2016-3443
- https://security.gentoo.org/glsa/201606-18 vendor-advisoryx_refsource_GENTOO
- https://security.netapp.com/advisory/ntap-20160420-0001/ x_refsource_CONFIRM
- https://www.cve.org/CVERecord?id=CVE-2016-3443
Change history (0)
No recorded changes yet.