Critical severity9.6NVD Advisory· Published Apr 21, 2016· Updated May 6, 2026
CVE-2016-3443
CVE-2016-3443
Description
Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to 2D. NOTE: the previous information is from the April 2016 CPU. Oracle has not commented on third-party claims that this issue allows remote attackers to obtain sensitive information via crafted font data, which triggers an out-of-bounds read.
Affected products
6cpe:2.3:a:oracle:jdk:1.6.0:update113:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:oracle:jdk:1.6.0:update113:*:*:*:*:*:*
- cpe:2.3:a:oracle:jdk:1.7.0:update99:*:*:*:*:*:*
- cpe:2.3:a:oracle:jdk:1.8.0:update77:*:*:*:*:*:*
cpe:2.3:a:oracle:jre:1.6.0:update113:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:oracle:jre:1.6.0:update113:*:*:*:*:*:*
- cpe:2.3:a:oracle:jre:1.7.0:update99:*:*:*:*:*:*
- cpe:2.3:a:oracle:jre:1.8.0:update77:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
24- www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.htmlnvdVendor Advisory
- lists.opensuse.org/opensuse-security-announce/2016-05/msg00039.htmlnvd
- lists.opensuse.org/opensuse-security-announce/2016-05/msg00040.htmlnvd
- lists.opensuse.org/opensuse-security-announce/2016-05/msg00042.htmlnvd
- lists.opensuse.org/opensuse-security-announce/2016-05/msg00058.htmlnvd
- lists.opensuse.org/opensuse-security-announce/2016-05/msg00059.htmlnvd
- lists.opensuse.org/opensuse-security-announce/2016-05/msg00061.htmlnvd
- lists.opensuse.org/opensuse-security-announce/2016-05/msg00067.htmlnvd
- lists.opensuse.org/opensuse-security-announce/2016-06/msg00002.htmlnvd
- rhn.redhat.com/errata/RHSA-2016-0677.htmlnvd
- rhn.redhat.com/errata/RHSA-2016-0678.htmlnvd
- rhn.redhat.com/errata/RHSA-2016-0679.htmlnvd
- rhn.redhat.com/errata/RHSA-2016-0701.htmlnvd
- rhn.redhat.com/errata/RHSA-2016-0702.htmlnvd
- rhn.redhat.com/errata/RHSA-2016-0708.htmlnvd
- rhn.redhat.com/errata/RHSA-2016-0716.htmlnvd
- rhn.redhat.com/errata/RHSA-2016-1039.htmlnvd
- www.securityfocus.com/bid/86482nvd
- www.securitytracker.com/id/1035596nvd
- www.zerodayinitiative.com/advisories/ZDI-16-376nvd
- access.redhat.com/errata/RHSA-2016:1430nvd
- access.redhat.com/errata/RHSA-2017:1216nvd
- security.gentoo.org/glsa/201606-18nvd
- security.netapp.com/advisory/ntap-20160420-0001/nvd
News mentions
0No linked articles in our index yet.