CVE-2016-0494

critical
Published 2016-01-21 · Modified 2026-05-06
CVSS v3
CVSS v2
10.0
VIR risk
10.0

Description

Unspecified vulnerability in the Java SE and Java SE Embedded components in Oracle Java SE 6u105, 7u91, and 8u66 and Java SE Embedded 8u65 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2016-0494

vendor Authored 2026-05-27

Vendor advisory: secalert_us@oracle.com — http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html

vendor Authored 2026-05-27

Vendor advisory: suse — https://www.suse.com/security/cve/CVE-2016-0494.html

OS impact

OSVersionStatusFixed in
suse slesaffected
debian debianbookwormfixed57.1-4
debian debianbullseyefixed57.1-4
debian debianforkyfixed57.1-4
debian debiansidfixed57.1-4
debian debiantrixiefixed57.1-4
ubuntu ubuntu12.04affected
ubuntu ubuntu14.04affected
ubuntu ubuntu15.04affected
ubuntu ubuntu15.10affected

Application impact

VendorProductVersionsFixed
oraclejdk1.6.0
oraclejdk1.7.0
oraclejdk1.8.0
oraclejre1.6.0
oraclejre1.7.0
oraclejre1.8.0

References

Verify integrity in audit chain (admin only). AS-IS.