Skip to main content

CVE detail

CVE-2012-0507

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, and 5.0 Update 33 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Concurrency. NOTE: the previous information was obtained from the February 2012 Oracle CPU. Oracle has not commented on claims from a downstream vendor and third party researchers that this issue occurs because the AtomicReferenceArray class implementation does not ensure that the array is of the Object[] type, which allows attackers to cause a denial of service (JVM crash) or bypass Java sandbox restrictions. NOTE: this issue was originally mapped to CVE-2011-3571, but that identifier was already assigned to a different issue.

CVSS 9.8 · CriticalBuzz score 66.0KEV listed

Buzz score

Why this CVE is surfacing

Buzz score total 66.0

This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.

Buzz score components · mention 30.0 · diversity 11.0 · KEV 25.0 · OTX 0.0 · PoC 0.0
Mention score
30.0
36 evidence mentions in the snapshot
Diversity score
11.0
5 sources across 1 categories
KEV score
25.0
Known exploited vulnerability present
OTX score
0.0
0 OTX pulses
PoC score
0.0
0 repos · best confidence N/A
Best PoC traction
0
Maximum stars on a matched PoC repo

Why it matters now

Mention timeline

Total mentions
0
within the 30d window
Peak daily
0
highest bucket

Evidence

Source links by recency

Newest mentions first
36 source links · newest first
  • Old vulnerabilities are still a big problemHelp Net Security

    A recently flagged phishing campaign aimed at delivering the Agent Tesla RAT to unsuspecting users takes advantage of old vulnerabilities in Microsoft Office that allow remote code execution. “Despite fixes for CVE-2017-11882/CVE-2018-0802 being released by Microsoft in November, 2017 and January, 2018, this vulnerability remains popular amongst threat actors, suggesting there are still unpatched devices in the wild, even after over five years,” says Fortinet researcher Xiaopeng Zhang. “We are observing and mitigating 3000 attacks … More →

    newswww.helpnetsecurity.comSep 6, 2023, 1:51 PM
  • It’s a new year and while some things change, some things stay the same (or similar). There’s lots of FUD about the sophisticated cyber attacks that are multi-threaded and obfuscated. Certainly there are attacks that fall into this category, but if you look at all of the cybercrime activity from the past year, it’s clear that the majority of threats do not have the level of sophistication that is often talked about.

    newswww.securityweek.comJan 20, 2017, 4:16 PM
  • What is old may not always be new, but when it comes to hacking, it’s still effective.

    newswww.securityweek.comFeb 23, 2015, 11:26 PM
  • Earlier this morning, CSO published new information on the Magnitude Exploit Kit, a criminal project known for its ties to attacks on Yahoo and PHP.net, as well as several other websites. The story was made possible thanks to help from researchers at Trustwave. Today’s update will examine some highlights from that research, with commentary from […]

    newswww.csoonline.comAug 5, 2014, 12:33 PM
  • LAS VEGAS (Black Hat USA) – Researchers at Trustwave have provided CSO with an inside look at the Magnitude Exploit Kit’s infrastructure. Linked to attacks against PHP.net and Yahoo, this kit has gone from obscurity to a certified threat in a short amount of time, while generating more than $60,000 USD per week in income. […]

    newswww.csoonline.comAug 5, 2014, 10:00 AM
  • Malware in a JarMalwarebytes Labs

    As researchers find more security flaws in Oracle Java, the software continues to be used for exploitation and malware delivery. This…

    newswww.malwarebytes.comApr 2, 2013, 5:00 PM
  • Java exploits have become popular additions to many crimeware kits for good reason. According to Websense, close to 94 percent of endpoints running Oracle Java are vulnerable to at least one Java exploit.

    newswww.securityweek.comMar 26, 2013, 1:12 AM
  • A decade is a long time to escape detection, but that is roughly how long the TeamSpy attack may have gone on unseen.

    newswww.securityweek.comMar 21, 2013, 5:26 PM
  • New malware targeting Mac users has been discovered on a website associated with the Dalai Lama. “Acting on a tip, a member of our Threat Research team (Brod) has discovered a Dalai Lama related website is compromised and is pushing new Mac malware, called Dockster, using a Java-based exploit,” blogged Sean Sullivan, security advisor for F-Secure.

    newswww.securityweek.comDec 3, 2012, 4:16 PM
  • The latest Java vulnerability has been integrated into both Black Hole and Gong Da exploit kits, making it easier for cyber-criminals to launch attacks exploiting the flaw, a security researcher said.

    newswww.securityweek.comNov 22, 2012, 12:36 PM
  • After a period of steady decline that started in 2009, the number of application vulnerabilities has seen a significant increase during the first half of 2012, according to the latest version of Microsoft’s Security Intelligence Report (SIR) that was released on Tuesday. Exploits for security flaws in popular applications like Java and document readers were […]

    newswww.csoonline.comOct 9, 2012, 3:00 PM
  • Nepalese government websites serving backdoorHelp Net Security

    Two websites belonging to the Nepalese government have been injected with malicious code that tries to take advantage of a Java vulnerability (CVE-2012-0507) in order to download a backdoor RAT on the visitors’ machines, Websense warns. The sites in question are those of the National Information Technology Center (nitc.gov.np) and the Office of the Prime Minister and Council Minister (opmcm.gov.np), and the code injected in them has been taken from the Metasploit framework and was … More →

    newswww.helpnetsecurity.comAug 9, 2012, 5:24 AM
  • Researchers have uncovered another attack exploiting a Java vulnerability against activists and government agencies in Nepal . The attack resulted in a backdoor being installed on victims’ machines.

    newswww.securityweek.comAug 8, 2012, 10:07 PM
  • Amnesty International’s UK website was hacked to host the dangerous Gh0st RAT Trojan for two days this week, security firm Websense has revealed. Attacking browsers unpatched against the common CVE-2012-0507 Java vulnerability (also used by the Mac Flashback Trojan), between 8 and 9 May visitors would have been at risk of downloading a Windows executable […]

    newswww.csoonline.comMay 12, 2012, 3:00 PM
  • RedKit exploit kit spotted in the wildHelp Net Security

    A new exploit kit that Trustwave researchers have spotted being used in the wild is aiming to enter a market that is practically monopolized by the widely famous BlackHole and Phoenix exploit kits. This new kit has no official name, so the researchers dubbed it RedKit due to the red coloring scheme of its administration panel. RedKit’s creators decided to promote it by using banners, and potential buyers are required to share their Jabber username … More →

    newswww.helpnetsecurity.comMay 3, 2012, 12:57 PM
  • Flashback Trojan, a business opportunity for allSecurity Affairs

    Many people who do not work in our sector are asking me two questions with increasing frequency: Can a virus infect a MAC pc? Is it possible to monetize a malware development? How is it possible? Obvious my answers, we cannot think of a software system free of bugs and vulnerabilities. To those who I have […]

    newssecurityaffairs.comMay 2, 2012, 10:16 AM
  • The official website of the Israeli Institute for National Security Studies has been compromised and has been found serving a variant of the Poison Ivy remote administration tool (RAT), warns Websense. As it says on its homepage, the INSS is “an independent academic institute that studies key issues relating to Israel’s national security and Middle East affairs.” Contributing to the institute are a number of “researchers with backgrounds in academia, the military, government, and public … More →

    newswww.helpnetsecurity.comMay 2, 2012, 5:41 AM
  • Attackers have updated the Flashback Trojan targeting Macs to use Twitter as a command and control mechanism, security researchers have found.

    newswww.securityweek.comApr 30, 2012, 7:08 PM
  • Security researchers are reporting the emergence of another variant of the Flashback Trojan targeting Mac machines. According to Intego , the new variant continues to use a patched Java vulnerability to infect users. No password is required for it to install, and it places files in the victim’s home folder at the following concerns: • ~/Library/LaunchAgents/com.java.update.plist • ~/.jupdate

    newswww.securityweek.comApr 24, 2012, 6:03 PM
  • Here’s an overview of some of last week’s most interesting news, videos, reviews, podcasts, interviews and articles: SSL/TLS deployment best practices In this video recorded at RSA Conference 2012, Ivan Ristic, Director of Engineering at Qualys, talks about SSL Labs and their efforts to understand how SSL was used and to remedy the lack of easy-to-use SSL tools and documentation. New Mac malware uses Flashback Java exploit Apple’s decision to push out a Flashback malware … More →

    newswww.helpnetsecurity.comApr 23, 2012, 12:01 AM
  • Yesterday I discussed with a friend and colleague Francesco on the lack of awareness of Apple’s users on malware that plague products of the house in Cupertino. This consideration is one of the reasons of the success in malware development for Apple, the users totally ignore that Apple machines are equivalent to any other kind of […]

    newssecurityaffairs.comApr 22, 2012, 9:44 AM
  • Flashback botnet decline not as fast as expectedHelp Net Security

    Given the attention that the Flashback Mac malware has received since the discovery of the 600K strong botnet of computers infected with it and the number of tools that various security firms and Apple issued for its removal, it’s somewhat disheartening to hear that the botnet still counts around 140,000 zombies. “We had originally believed that we would have seen a greater decline in infections at this point in time, but this has proven not … More →

    newswww.helpnetsecurity.comApr 18, 2012, 5:59 AM
  • New Mac malware uses Flashback Java exploitHelp Net Security

    Apple’s decision to push out a Flashback malware removal tool for OS X Lion bundled with a new Java security update has proven to be rather fortunate, as a new Mac OS X threat has been discovered taking advantage of the vulnerability (CVE-2012-0507) exploited by the latest Flashback variants. The security update in question configures the Java web plug-in to disable the automatic execution of Java applets in browsers, a move that should prevent users … More →

    newswww.helpnetsecurity.comApr 16, 2012, 7:32 AM
  • Flashback Malware – A Detailed History of the Largest Mac OS Malware Outbreak to Date

    newswww.securityweek.comApr 13, 2012, 2:56 PM
  • Security researchers from antivirus vendor ESET have come across new Web-based malware attacks that try to evade URL security scanners by checking for the presence of mouse cursor movement. The new drive-by download attacks were spotted in the Russian Web space and don’t require user interaction to infect computers with malware. Most attacks of this […]

    newswww.csoonline.comApr 9, 2012, 3:00 PM
  • Microsoft to release four critical bulletinsHelp Net Security

    The Microsoft Security Bulletin Advance Notification for April 2012 contains six bulletins. The number of bulletins isn’t huge but the potential harm is great. Of the six bulletins, there are four critical bulletins that touch all of Microsoft’s most popular offerings. All of the critical bulletins would result in remote code execution. Bulletin 1 is a remote code execution for Microsoft Windows and Internet Explorer, indicating that users could be compromised by visiting websites with … More →

    newswww.helpnetsecurity.comApr 6, 2012, 8:00 AM
  • Security researchers say the Flashback malware hitting Mac OS X machines has built a powerful botnet of more than 550,000 computers.

    newswww.securityweek.comApr 5, 2012, 3:06 PM
  • Despite Apple releasing a patch for Java, the Flashback Trojan has infected 600,000 Macs, according to reports. As a result, there are 600,000 Macs being remotely controlled by the growing Mac botnet, according to Russian antivirus company Dr. Web. The majority of the botnet computers are located in the United States and Canada, according to […]

    newswww.csoonline.comApr 5, 2012, 3:00 PM
  • Apple yesterday released a Java update for Mac owners that fixes a dozen security flaws, including one that has been exploited by attackers for at least two weeks. The update follows a decision Monday by Mozilla to blacklist unpatched editions of the Java plug-in from running in the Windows version of Firefox. Mozilla has yet […]

    newswww.csoonline.comApr 4, 2012, 3:00 PM
  • Recently ESET security firm has reported the latest version of the Blackhole exploit kit that has been updated to include a new exploit for the Java CVE-2012-0507 vulnerability. The exploit was discovered for the first time on 7.03.2012 and it first detections were dated on March 12, 2012 and today a public module for Metasploit […]

    newssecurityaffairs.comApr 4, 2012, 9:27 AM
  • Apple patches critical Java flawHelp Net Security

    Apple released a critical update for the Java implementation on Mac OS X, for both Lion and Snow Leopard. This update comes almost two months after the release of the corresponding Java version by Oracle, and only a couple of days after evidence surfaced that malware authors have been using an included Java flaw (CVE-2012-0507) to attack Mac computers. Our recommendation: apply the update as quickly as possible. In addition, Mac users and IT admins … More →

    newswww.helpnetsecurity.comApr 4, 2012, 2:58 AM
  • Mac Trojan infects machines via unpatched Java bugHelp Net Security

    Flashback Trojan variants have been targeting Mac users since September 2011, and they have gone through a variety of changes and techniques aimed at achieving its installation and avoiding its detection. They initially posed as an Adobe Flash Player installer, then have acquired the capability to disrupt the automatic updating of XProtect, the operating system’s built-in anti-malware application. At the beginning, the user was responsible for downloading and running the malware, but lately even that … More →

    newswww.helpnetsecurity.comApr 3, 2012, 6:29 AM
  • An analysis of the Alexa top 25,000 most popular domains revealed 58 were serving malicious content during the month of February – translating to more than 10.5 million users being targeted by malware, according to research by Barracuda Networks .

    newswww.securityweek.comApr 2, 2012, 4:10 PM
  • A Java vulnerability that hasn’t yet been patched by Apple is being exploited by cybercriminals to infect Mac computers with a new variant of the Flashback malware, according to security researchers from antivirus firm F-Secure. Flashback is a computer Trojan horse for Mac OS that first appeared in September 2011. The first variant was distributed […]

    newswww.csoonline.comApr 2, 2012, 3:00 PM
  • Flashback, a Mac Trojan horse that’s been in the public eye since it was uncovered by security firm Intego last year, has a new trick up its sleeve: It can now infect your computer from little more than a visit to a website. Originally, Flashback masqueraded as an installer for Adobe’s Flash Player–hence the name–but […]

    newswww.csoonline.comApr 2, 2012, 3:00 PM
  • Organizations should move to patch a Java vulnerability being targeted by attackers in the wild, security experts say.

    newswww.securityweek.comMar 29, 2012, 7:41 PM

Exploit code

Public exploit repository references

Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.

0 repository references · best confidence N/A · max 0 stars
No public PoC repositories have been matched yet.

Related records

Similar CVEs

6 related CVEs with shared weakness or product evidence