CVE detail
CVE-2011-3544
Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7 and 6 Update 27 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality, integrity, and availability via unknown vectors related to Scripting.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 30.0 · diversity 11.0 · KEV 25.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
22 source links · newest first
- The Panda Emissary APT specialized in defence aerospace projectsSecurity Affairs
The Panda Emissary group extensively uses long-running strategic web compromises and relies on whitelists to syphon defence aerospace projects from victims. An alleged Chinese APT group dubbed Panda Emissary (also known as TG-3390) is targeting high-profile governments and organisations searching for defense aerospace projects. Researchers at Dell discovered that the Panda Emissary group used Watering hole […]
newssecurityaffairs.comAug 6, 2015, 7:42 AM - Unusual Exploit Kit Targets Chinese Users (Part 1)Malwarebytes Labs
We are very accustomed to seeing the same exploit kits over and over. Angler EK, Nuclear EK or Fiesta EK all…
newswww.malwarebytes.comMay 27, 2015, 5:00 PM Facebook has removed a scam that was redirecting users to the Nuclear exploit kit, according to researchers with Symantec. The scam relied on users getting drawn into clicking on a link promoting a work-from-home opportunity with the headline: ‘EXPOSED: Mom Makes $8,000/Month and You Won’t Believe How She Does It!’
newswww.securityweek.comJul 23, 2014, 11:47 PM- Whitehole Exploit Kit in the wildSecurity Affairs
Exploit kit, a name which has become depressingly familiar, crimaware kit that contains malicious code to exploit principal vulnerabilities in large consume product such as browsers, last news is that a new kit named Whitehole has emerged on the underground market. Generally the exploit kits are malicious Web-based applications designed to install malware on computers […]
newssecurityaffairs.comFeb 9, 2013, 7:13 AM The name BlackHole looms large over the marketplace for crimeware kits, but a new player is said to have emerged with similar code and a similar name.
newswww.securityweek.comFeb 7, 2013, 4:02 PMA new exploit kit called Whitehole has emerged on the underground market, providing cybercriminals with one more tool to infect computers with malware over the Web, security researchers from antivirus vendor Trend Micro reported Wednesday. Exploit kits are malicious Web-based applications designed to install malware on computers by exploiting vulnerabilities in outdated browser plug-ins like […]
newswww.csoonline.comFeb 7, 2013, 3:00 PMWatering hole attacks continue unabated and, according to Avast’s Director of Threat Intelligence Jindrich Kubec, the finger could be safely pointed to China once again. The latest website compromised to redirect visitors to sites serving exploits for the recently patched IE zero-day vulnerability and two Java flaws (CVE-2013-0422 and CVE-2011-3544) is the official site of Reporters Without Borders (Reporters sans Frontières), an international non-governmental organization advocating freedom of the press and freedom of information. “Such … More →
newswww.helpnetsecurity.comJan 24, 2013, 10:48 AM- Red October, RBN and too many questions still unresolvedSecurity Affairs
The recently discovered cyber espionage campaign “Red October” has shocked world wide security community, the principal questions raised are: Who is behind the attacks? How is possible that for so long time the campaign went undetected? Which is the role of AV company in these operations? To try to understand who is behind the attacks […]
newssecurityaffairs.comJan 17, 2013, 8:15 AM On Monday, Kaspersky Lab uncovered details of a complex cyber espionage campaign dubbed ‘Operation Red October’ that has been targeting specific groups throughout the world for over five years.
newswww.securityweek.comJan 15, 2013, 8:54 AMThe latest Java vulnerability has been integrated into both Black Hole and Gong Da exploit kits, making it easier for cyber-criminals to launch attacks exploiting the flaw, a security researcher said.
newswww.securityweek.comNov 22, 2012, 12:36 PMAfter a period of steady decline that started in 2009, the number of application vulnerabilities has seen a significant increase during the first half of 2012, according to the latest version of Microsoft’s Security Intelligence Report (SIR) that was released on Tuesday. Exploits for security flaws in popular applications like Java and document readers were […]
newswww.csoonline.comOct 9, 2012, 3:00 PMReports from main security firms confirm the increasing growth of cyber attacks based on malware, in particular the large diffusion of Apple products has made them desirable targets. The explosion of malicious agents designed for Apple OS X operating system as surprised Apple users that have found themselves suddenly vulnerable exactly such as users of […]
newssecurityaffairs.comSep 23, 2012, 12:37 PM- Flashback? Are you joking? There aren’t malware for MacSecurity Affairs
Yesterday I discussed with a friend and colleague Francesco on the lack of awareness of Apple’s users on malware that plague products of the house in Cupertino. This consideration is one of the reasons of the success in malware development for Apple, the users totally ignore that Apple machines are equivalent to any other kind of […]
newssecurityaffairs.comApr 22, 2012, 9:44 AM Security researchers say the Flashback malware hitting Mac OS X machines has built a powerful botnet of more than 550,000 computers.
newswww.securityweek.comApr 5, 2012, 3:06 PMDespite Apple releasing a patch for Java, the Flashback Trojan has infected 600,000 Macs, according to reports. As a result, there are 600,000 Macs being remotely controlled by the growing Mac botnet, according to Russian antivirus company Dr. Web. The majority of the botnet computers are located in the United States and Canada, according to […]
newswww.csoonline.comApr 5, 2012, 3:00 PMResearchers have discovered an extremely rare and possibly unique form of “fileless” malware that executes entirely in memory without the need to save any files to the hard drive of a victim’s PC. The latest discovery was made by Kaspersky Lab, which received reports of a malware attack hitting a common Java vulnerability (CVE-2011-3544) on […]
newswww.csoonline.comMar 21, 2012, 3:00 PMHackers are using a recent report about cyberthreats to Tibetan activists as a lure in a new attack against pro-Tibet organizations that distributes Windows and Mac malware, researchers from security vendor AlienVault said on Monday. On March 13, AlienVault published a report about email-based cyberattacks against Tibetan activist organizations including the Central Tibet Administration and […]
newswww.csoonline.comMar 21, 2012, 3:00 PMA hard-to-detect piece of malware that doesn’t create any files on the affected systems was dropped onto the computers of visitors to popular news sites in Russia in a drive-by download attack, according to security researchers from antivirus firm Kaspersky Lab. Drive-by download attacks are one of the primary methods of distributing malware over the […]
newswww.csoonline.comMar 19, 2012, 3:00 PM- Cryptome Hit by Blackhole Exploit KitSecurityWeek
Whistleblower site Cryptome has been hacked and infected by the Blackhole exploit kit. Just how the breach occurred has not been said. Cryptome co-founder John Young however told SecurityWeek that the site is in the process of cleaning everything up, and that process should be finished by the end of the day. “It appears every HTML page was infected so we are replacing all the pages to be sure,” he said.
newswww.securityweek.comFeb 13, 2012, 6:40 PM In the first quarter of 2011, enterprise users encountered an average of 274 web-based malware attacks, a 103 percent increase over 2010, according to research from Cisco ScanSafe. Why the dramatic increase? One major cause is the growing number of drive-by download attacks. Drive-by downloads are an especially pernicious method cybercriminals use to install viruses […]
newswww.csoonline.comFeb 10, 2012, 3:00 PM- Threat incidents and security wins in 2011Help Net Security
Having spent much of the year battling data breaches that led to huge information and financial loss, the security industry was likely relieved to see 2011 come to a close. In its annual threat roundup report, Trend Micro wraps 2011 as “The Year of Data Breaches,” after witnessing large, well-known companies succumb to targeted data breach attacks that not only stained reputations, but caused them significant collateral damage. This year’s report revisits past predictions, and … More →
newswww.helpnetsecurity.comJan 17, 2012, 11:49 AM The appearance of a new exploit has helped turn the spotlight this week on a common target of attackers – Java software.
newswww.securityweek.comDec 2, 2011, 9:30 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2013-4002CVSS 7.1 · High
XMLscanner.java in Apache Xerces2 Java Parser before 2.12.0, as used in the Java Runtime Environment (JRE) in IBM Java 5.0 before 5.0 SR16-FP3, 6 before 6 SR14, 6.0.1 before 6.0.1…
- CVE-2012-1717CVSS 2.1 · Low
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update 4 and earlier, 6 update 32 and earlier, 5 update 35 and earlier, and 1.4.2_37…
- CVE-2016-3427CVSS 9.8 · Critical
Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to affect confidentiality, integrity, and ava…
- CVE-2015-4902CVSS 5.3 · Medium
Unspecified vulnerability in Oracle Java SE 6u101, 7u85, and 8u60 allows remote attackers to affect integrity via unknown vectors related to Deployment.
- CVE-2013-0422CVSS 9.8 · Critical
Multiple vulnerabilities in Oracle Java 7 before Update 11 allow remote attackers to execute arbitrary code by (1) using the public getMBeanInstantiator method in the JmxMBeanServ…
- CVE-2015-8126CVSS 7.5 · High
Multiple buffer overflows in the (1) png_set_PLTE and (2) png_get_PLTE functions in libpng before 1.0.64, 1.1.x and 1.2.x before 1.2.54, 1.3.x and 1.4.x before 1.4.17, 1.5.x befor…