CVE detail
CVE-2015-3253
The MethodClosure class in runtime/MethodClosure.java in Apache Groovy 1.7.0 through 2.4.3 allows remote attackers to execute arbitrary code or cause a denial of service via a crafted serialized object.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 13.9 · diversity 5.0 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
3 source links · newest first
Oracle on Tuesday released its July 2017 Critical Patch Update (CPU) to address a total of 308 vulnerabilities, the highest number of security fixes ever released in a quarter by the enterprise software giant.
newswww.securityweek.comJul 19, 2017, 10:25 AMOracle this week released its Critical Patch Update (CPU) for October 2016 to deliver a total of 253 new security fixes across multiple product families, nearly half of which can be exploited remotely without authentication.
newswww.securityweek.comOct 19, 2016, 11:29 AMNormal 0 false false false EN-US X-NONE X-NONE Oracle Addresses 276 Security Flaws, 19 Critical in Critical Patch Update (CPU) For July 2016 Oracle on Tuesday released its Critical Patch Update (CPU) for July 2016 to address a total of 276 vulnerabilities across multiple products, including 19 critical security flaws that have a CVSS score of 9.8. This month’s Oracle CPU contains a record number of fixes, after the January 2016 set of patches established another one, at 248 security fixes. More worrying than the sheer number of addressed vulnerabilities is that 159 can be exploited remotely without authentication. Overall, the July CPU addresses 36 security issues in applications designed specifically for the Retail, Insurance, Health, Financial, and Utility industries. However, with 4 remotely exploitable vulnerabilities without authentication in sector-specific products, the Retail industry appears to have been affected the most. A total of 121 vulnerabilities were addressed in cruc…
newswww.securityweek.comJul 20, 2016, 11:42 AM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2020-17521CVSS 5.5 · Medium
Apache Groovy provides extension methods to aid with creating temporary directories. Prior to this fix, Groovy's implementation of those extension methods was using a now supersed…
- CVE-2019-17091CVSS 6.1 · Medium
faces/context/PartialViewContextImpl.java in Eclipse Mojarra, as used in Mojarra for Eclipse EE4J before 2.3.10 and Mojarra JavaServer Faces before 2.2.20, allows Reflected XSS be…
- CVE-2019-3740CVSS 6.5 · Medium
RSA BSAFE Crypto-J versions prior to 6.2.5 are vulnerable to an Information Exposure Through Timing Discrepancy vulnerabilities during DSA key generation. A malicious remote attac…
- CVE-2019-3739CVSS 6.5 · Medium
RSA BSAFE Crypto-J versions prior to 6.2.5 are vulnerable to Information Exposure Through Timing Discrepancy vulnerabilities during ECDSA key generation. A malicious remote attack…
- CVE-2019-3738CVSS 6.5 · Medium
RSA BSAFE Crypto-J versions prior to 6.2.5 are vulnerable to a Missing Required Cryptographic Step vulnerability. A malicious remote attacker could potentially exploit this vulner…
- CVE-2026-54680CVSS 9.9 · Critical
Logging operator automates the deployment and configuration of Kubernetes logging pipelines. Prior to 6.6.0, the Fluentd configuration renderer FluentRender in pkg/sdk/logging/mod…