Skip to main content

CVE detail

CVE-2012-1723

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update 4 and earlier, 6 update 32 and earlier, 5 update 35 and earlier, and 1.4.2_37 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Hotspot.

CVSS 9.8 · CriticalBuzz score 66.0KEV listed

Buzz score

Why this CVE is surfacing

Buzz score total 66.0

This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.

Buzz score components · mention 30.0 · diversity 11.0 · KEV 25.0 · OTX 0.0 · PoC 0.0
Mention score
30.0
23 evidence mentions in the snapshot
Diversity score
11.0
5 sources across 1 categories
KEV score
25.0
Known exploited vulnerability present
OTX score
0.0
0 OTX pulses
PoC score
0.0
0 repos · best confidence N/A
Best PoC traction
0
Maximum stars on a matched PoC repo

Why it matters now

Mention timeline

Total mentions
0
within the 30d window
Peak daily
0
highest bucket

Evidence

Source links by recency

Newest mentions first
23 source links · newest first
  • Old vulnerabilities are still a big problemHelp Net Security

    A recently flagged phishing campaign aimed at delivering the Agent Tesla RAT to unsuspecting users takes advantage of old vulnerabilities in Microsoft Office that allow remote code execution. “Despite fixes for CVE-2017-11882/CVE-2018-0802 being released by Microsoft in November, 2017 and January, 2018, this vulnerability remains popular amongst threat actors, suggesting there are still unpatched devices in the wild, even after over five years,” says Fortinet researcher Xiaopeng Zhang. “We are observing and mitigating 3000 attacks … More →

    newswww.helpnetsecurity.comSep 6, 2023, 1:51 PM
  • The function of cybersecurity is not to eliminate all attacks and compromises – that’s impossible – but to make the attack so expensive and time-consuming on the attacker that he simply moves on to an easier target. That is the purpose of a new product/service designed to make commodity ransomware attacks less easy for the attacker.

    newswww.securityweek.comOct 6, 2021, 6:13 PM
  • What is old may not always be new, but when it comes to hacking, it’s still effective.

    newswww.securityweek.comFeb 23, 2015, 11:26 PM
  • Turla cyber-espionage campaign puzzle solvedHelp Net Security

    Turla, also known as Snake or Uroburos is one of the most sophisticated ongoing cyber-espionage campaigns. When the first research on Turla/Snake/Uroburos was published, it didn’t answer one major question: how do victims get infected? The latest Kaspersky Lab research on this operation reveals that Epic is the initial stage of the Turla victim infection mechanism. The “Epic” project has been used since at least 2012, with the highest volume of activity observed in January-February … More →

    newswww.helpnetsecurity.comAug 7, 2014, 10:28 AM
  • Facebook has removed a scam that was redirecting users to the Nuclear exploit kit, according to researchers with Symantec. The scam relied on users getting drawn into clicking on a link promoting a work-from-home opportunity with the headline: ‘EXPOSED: Mom Makes $8,000/Month and You Won’t Believe How She Does It!’

    newswww.securityweek.comJul 23, 2014, 11:47 PM
  • Antivirus, Patch Management Failures Open Doors to Cyberattacks Patch management and antivirus are meant to prevent attackers cutting their way into the vaults protecting enterprise data.

    newswww.securityweek.comMar 27, 2014, 9:48 PM
  • Security experts uncovered an unusual cyber espionage campaign based on file infector belonging to the PE_EXPIRO family that includes information theft module Security experts at TrendMicro uncovered an unusual espionage campaign that hit United States users based on malware having file infector with stealing capabilities. The attackers acted with specific intent to steal information from organizations or […]

    newssecurityaffairs.comJul 21, 2013, 9:04 AM
  • An unusual attack has been spotted in the wild, using an unexpected combination of threats. This attack used exploit kits (in particular Java and PDF exploits) to deliver file infectors onto vulnerable systems. Interestingly, these file infectors have information theft routines, which is a behavior not usually found among file infectors. These malware are part of PE_EXPIRO family, file infectors that was first spotted spotted in 2010. In addition to standard file infection routines, the … More →

    newswww.helpnetsecurity.comJul 19, 2013, 2:11 AM
  • Researchers from Trend Micro have discovered a new attack that leverages a combination of exploits to infect systems and target FTP credentials and other information on Windows-based systems. The threat is a file infector malware that is part of the PE_EXPIRO family; malware that Trend says was first discovered in 2010.

    newswww.securityweek.comJul 16, 2013, 12:19 PM
  • A new version of a file-infecting malware program that’s being distributed through drive-by download attacks is also capable of stealing FTP (File Transfer Protocol) credentials, according to security researchers from antivirus firm Trend Micro. The newly discovered variant is part of the PE_EXPIRO family of file infectors that was identified in 2010, the Trend Micro […]

    newswww.csoonline.comJul 15, 2013, 3:00 PM
  • A new version of the Java exploit kit g01pack has added a second stage to the exploit process in order to bypass detection by antivirus tools, Trusteer’s researchers said. The kit has an infection rate estimated at about 1 out of 3,000 machines a month.

    newswww.securityweek.comMay 6, 2013, 8:17 AM
  • Most drive-by exploit kits use a minimal exploit shellcode that downloads and runs the final payload. This is akin to a two-stage ICBM (InterContinental Ballistic Missile) where the first stage, the exploit, puts the rocket in its trajectory and the second stage, the payload, inflicts the damage. In the cybercrime world, the de-coupling of the first stage from the payload is designed to make sure that an exploit kit is as generic as possible and … More →

    newswww.helpnetsecurity.comMay 3, 2013, 11:02 AM
  • Redkit Exploit Kit does the splitsMalwarebytes Labs

    Exploit Kit authors must really love Java . Not only is it ripe with vulnerabilities but its own language provides a…

    newswww.malwarebytes.comApr 4, 2013, 5:00 PM
  • Java exploits have become popular additions to many crimeware kits for good reason. According to Websense, close to 94 percent of endpoints running Oracle Java are vulnerable to at least one Java exploit.

    newswww.securityweek.comMar 26, 2013, 1:12 AM
  • Researchers at AlienVault shed some light on the evolution of the Sykipot malware attacks. The Sykipot attacks have exploited a number of zero-days during the past few years, including vulnerabilities affecting Adobe Reader, Adobe Flash Player and Microsoft Internet Explorer.

    newswww.securityweek.comMar 21, 2013, 6:54 PM
  • New Exploit Kit, Ransomware and AV evasionMalwarebytes Labs

    Ransomware is still going strong and infecting countless PCs. We happened to stumble upon an interesting sample part of the Urausy…

    newswww.malwarebytes.comMar 13, 2013, 5:00 PM
  • New exploit kit concentrates on Java flawsHelp Net Security

    Webroot’s Dancho Danchev is known for combing through the wilds of the Internet for places where cyber criminals congregate and reporting back with interesting news about tools and services offered for sale. Among those is a brand new exploit kit that, for now, concentrates only on exploiting Java flaws. The vulnerabilities in questions are CVE-2012-1723 and CVE-2013-0431, but more exploits are to be added soon, say its creators. Cyber crooks can rent the kit for … More →

    newswww.helpnetsecurity.comMar 5, 2013, 12:30 PM
  • Whitehole Exploit Kit in the wildSecurity Affairs

    Exploit kit, a name which has become depressingly familiar, crimaware kit that contains malicious code to exploit principal vulnerabilities in large consume product such as browsers, last news is that a new kit named Whitehole has emerged on the underground market. Generally the exploit kits are malicious Web-based applications designed to install malware on computers […]

    newssecurityaffairs.comFeb 9, 2013, 7:13 AM
  • The name BlackHole looms large over the marketplace for crimeware kits, but a new player is said to have emerged with similar code and a similar name.

    newswww.securityweek.comFeb 7, 2013, 4:02 PM
  • A new exploit kit called Whitehole has emerged on the underground market, providing cybercriminals with one more tool to infect computers with malware over the Web, security researchers from antivirus vendor Trend Micro reported Wednesday. Exploit kits are malicious Web-based applications designed to install malware on computers by exploiting vulnerabilities in outdated browser plug-ins like […]

    newswww.csoonline.comFeb 7, 2013, 3:00 PM
  • The latest Java vulnerability has been integrated into both Black Hole and Gong Da exploit kits, making it easier for cyber-criminals to launch attacks exploiting the flaw, a security researcher said.

    newswww.securityweek.comNov 22, 2012, 12:36 PM
  • Criminals are sending malicious emails that purport to come from payroll services firms in order to infect with malware the computers of payroll administrators from various companies, according to researchers from the SANS Internet Storm Center (ISC). “For the past couple of weeks, companies that offer outsourced payroll management services have seen their name being […]

    newswww.csoonline.comAug 6, 2012, 3:00 PM
  • The minds behind the Blackhole exploit toolkit have updated it with an exploit targeting a recently patched vulnerability in Java.

    newswww.securityweek.comJul 11, 2012, 4:50 PM

Exploit code

Public exploit repository references

Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.

0 repository references · best confidence N/A · max 0 stars
No public PoC repositories have been matched yet.

Related records

Similar CVEs

6 related CVEs with shared weakness or product evidence