Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2012-4681
Description:Multiple vulnerabilities in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier allow remote attackers to execute arbitrary code via a crafted applet that bypasses SecurityManager restrictions by (1) using com.sun.beans.finder.ClassFinder.findClass and leveraging an exception with the forName method to access restricted classes from arbitrary packages such as sun.awt.SunToolkit, then (2) using "reflection with a trusted immediate caller" to leverage the getField method to access and modify private fields, as exploited in the wild in August 2012 using Gondzz.class and Gondvv.class.
Test IDs: 1.3.6.1.4.1.25623.1.0.864685   1.3.6.1.4.1.25623.1.1.4.2012.1231.1   1.3.6.1.4.1.25623.1.0.864794   1.3.6.1.4.1.25623.1.0.866020   1.3.6.1.4.1.25623.1.0.865375   1.3.6.1.4.1.25623.1.0.71831   1.3.6.1.4.1.25623.1.0.71859  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2012-4681
BugTraq ID: 55213
http://www.securityfocus.com/bid/55213
Cert/CC Advisory: TA12-240A
http://www.us-cert.gov/cas/techalerts/TA12-240A.html
HPdes Security Advisory: HPSBUX02824
http://marc.info/?l=bugtraq&m=135109152819176&w=2
HPdes Security Advisory: SSRT100970
http://marc.info/?l=bugtraq&m=135109152819176&w=2
http://blog.fireeye.com/research/2012/08/zero-day-season-is-not-over-yet.html
http://immunityproducts.blogspot.com/2012/08/java-0day-analysis-cve-2012-4681.html
http://labs.alienvault.com/labs/index.php/2012/new-java-0day-exploited-in-the-wild/
http://www.deependresearch.org/2012/08/java-7-vulnerability-analysis.html
https://community.rapid7.com/community/metasploit/blog/2012/08/27/lets-start-the-week-with-a-new-java-0day
RedHat Security Advisories: RHSA-2012:1225
http://rhn.redhat.com/errata/RHSA-2012-1225.html
http://secunia.com/advisories/51044
SuSE Security Announcement: SUSE-SU-2012:1231 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2012-09/msg00032.html
SuSE Security Announcement: SUSE-SU-2012:1398 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2012-10/msg00016.html




© 1998-2025 E-Soft Inc. All rights reserved.