CVE-2012-0507
critical
📛 Threat Title
CVE-2012-0507
Description
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, and 5.0 Update 33 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Concurrency. NOTE: the previous information was obtained from the February 2012 Oracle CPU. Oracle has not commented on claims from a downstream vendor and third party researchers that this issue occurs because the AtomicReferenceArray class implementation does not ensure that the array is of the Object[] type, which allows attackers to cause a denial of service (JVM crash) or bypass Java sandbox restrictions. NOTE: this issue was originally mapped to CVE-2011-3571, but that identifier was already assigned to a different issue.
Indicators of Compromise (0)
No indicators of compromise on this threat.
References (24)
- secalert_us@oracle.com NVD Recent CVEs
- secalert_us@oracle.com NVD Recent CVEs
- secalert_us@oracle.com NVD Recent CVEs
- secalert_us@oracle.com NVD Recent CVEs
- secalert_us@oracle.com NVD Recent CVEs
- secalert_us@oracle.com NVD Recent CVEs
- secalert_us@oracle.com NVD Recent CVEs
- secalert_us@oracle.com NVD Recent CVEs
- secalert_us@oracle.com NVD Recent CVEs
- secalert_us@oracle.com NVD Recent CVEs
- secalert_us@oracle.com NVD Recent CVEs
- secalert_us@oracle.com NVD Recent CVEs
- secalert_us@oracle.com NVD Recent CVEs
- secalert_us@oracle.com NVD Recent CVEs
- secalert_us@oracle.com NVD Recent CVEs
- secalert_us@oracle.com NVD Recent CVEs
- secalert_us@oracle.com NVD Recent CVEs
- secalert_us@oracle.com NVD Recent CVEs
- secalert_us@oracle.com NVD Recent CVEs
- secalert_us@oracle.com NVD Recent CVEs
- secalert_us@oracle.com NVD Recent CVEs
- secalert_us@oracle.com NVD Recent CVEs
-
NVD detail: CVE-2012-0507
NVD Recent CVEs
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, and 5.0 Update 33 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Concurrency. NOTE: the previous information was obtained from the February 2012 Oracle CPU. Oracle has not commented on claims from a downstream vendor and third party researchers that this issue occurs because the AtomicReferenceArray class implementation does not ensure that the array is of the Object[] type, which allows attackers to cause a denial of service (JVM crash) or bypass Java sandbox restrictions. NOTE: this issue was originally mapped to CVE-2011-3571, but that identifier was already assigned to a different issue.
- 134c704f-9b21-4f2e-91b3-4a467353bcc0 NVD Recent CVEs
Remediations (8)
-
web:catalog.update.microsoft.com
Welcome to the Microsoft Update Catalog site. We want your feedback! Visit our newsgroup or send us an email to provide us with your thoughts and suggestions. To get started using the site, enter in your search terms in the Search box above or visit our FAQ for search tips. |Newsgroup|Send us your feedback
-
web:learn.microsoft.com
Use the DISM tool to fix problems that prevent Windows Update from installing successfully.
-
web:msrc.microsoft.com
The Microsoft Security Response Center (MSRC) investigates all reports of security vulnerabilities affecting Microsoft products and services, and provides the information here as part of the ongoing effort to help you manage security risks and help keep your systems protected.
-
web:nvd.nist.gov
CVE-2012-0507 Detail Description Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, and 5.0 Update 33 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Concurrency.
-
web:portal.msrc.microsoft.com
The Security Update Guide provides information on the latest Microsoft security updates, helping users understand and address potential vulnerabilities effectively.
-
web:www.ninjaone.com
Microsoft reports no known issues with this update, and the patch addresses significant security concerns that warrant timely deployment. The absence of re
-
web:www.oracle.com
This Critical Patch Update contains 1449 new security patches across the product families listed below. Please note that a My Oracle Support (MOS) note summarizing the content of this Critical Patch Update and other Oracle Software Security Assurance activities is located at July 2026 Critical Patch Update: Executive Summary and Analysis.
-
web:www.threatclaw.ai
CVE-2012-0507 is a critical, remotely exploitable vulnerability in the Java Runtime Environment (JRE) affecting Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, and 5.0 Update 33 and earlier.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.