Vulnerability Details CVE-2012-5373
Oracle Java SE 7 and earlier, and OpenJDK 7 and earlier, computes hash values without properly restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table, as demonstrated by a universal multicollision attack against the MurmurHash3 algorithm, a different vulnerability than CVE-2012-2739.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.005
EPSS Ranking 65.3%
CVSS Severity
CVSS v2 Score 5.0
Products affected by CVE-2012-5373
-
cpe:2.3:a:oracle:jdk:1.4.2_37
-
cpe:2.3:a:oracle:jdk:1.4.2_38
-
cpe:2.3:a:oracle:jdk:1.4.2_40
-
cpe:2.3:a:oracle:jdk:1.5.0
-
-
cpe:2.3:a:oracle:jdk:1.6.0
-
-
cpe:2.3:a:oracle:jdk:1.7.0
-
-
cpe:2.3:a:oracle:jre:1.1.6_009
-
cpe:2.3:a:oracle:jre:1.1.7b_007
-
cpe:2.3:a:oracle:jre:1.1.8_005
-
cpe:2.3:a:oracle:jre:1.1.8_006
-
cpe:2.3:a:oracle:jre:1.1.8_007
-
cpe:2.3:a:oracle:jre:1.1.8_008
-
cpe:2.3:a:oracle:jre:1.1.8_009
-
cpe:2.3:a:oracle:jre:1.1.8_010
-
cpe:2.3:a:oracle:jre:1.1.8_015
-
cpe:2.3:a:oracle:jre:1.1.8_16
-
cpe:2.3:a:oracle:jre:1.4.0
-
cpe:2.3:a:oracle:jre:1.4.0_01
-
cpe:2.3:a:oracle:jre:1.4.0_02
-
cpe:2.3:a:oracle:jre:1.4.0_03
-
cpe:2.3:a:oracle:jre:1.4.0_04
-
cpe:2.3:a:oracle:jre:1.4.1
-
cpe:2.3:a:oracle:jre:1.4.1_02
-
cpe:2.3:a:oracle:jre:1.4.1_03
-
cpe:2.3:a:oracle:jre:1.4.1_04
-
cpe:2.3:a:oracle:jre:1.4.1_05
-
cpe:2.3:a:oracle:jre:1.4.1_06
-
cpe:2.3:a:oracle:jre:1.4.1_07
-
cpe:2.3:a:oracle:jre:1.4.2
-
cpe:2.3:a:oracle:jre:1.4.2_01
-
cpe:2.3:a:oracle:jre:1.4.2_02
-
cpe:2.3:a:oracle:jre:1.4.2_03
-
cpe:2.3:a:oracle:jre:1.4.2_04
-
cpe:2.3:a:oracle:jre:1.4.2_05
-
cpe:2.3:a:oracle:jre:1.4.2_06
-
cpe:2.3:a:oracle:jre:1.4.2_07
-
cpe:2.3:a:oracle:jre:1.4.2_08
-
cpe:2.3:a:oracle:jre:1.4.2_09
-
cpe:2.3:a:oracle:jre:1.4.2_10
-
cpe:2.3:a:oracle:jre:1.4.2_11
-
cpe:2.3:a:oracle:jre:1.4.2_12
-
cpe:2.3:a:oracle:jre:1.4.2_13
-
cpe:2.3:a:oracle:jre:1.4.2_14
-
cpe:2.3:a:oracle:jre:1.4.2_15
-
cpe:2.3:a:oracle:jre:1.4.2_16
-
cpe:2.3:a:oracle:jre:1.4.2_17
-
cpe:2.3:a:oracle:jre:1.4.2_18
-
cpe:2.3:a:oracle:jre:1.4.2_19
-
cpe:2.3:a:oracle:jre:1.4.2_25
-
cpe:2.3:a:oracle:jre:1.4.2_37
-
cpe:2.3:a:oracle:jre:1.4.2_38
-
cpe:2.3:a:oracle:jre:1.4.2_40
-
cpe:2.3:a:oracle:jre:1.5.0
-
-
cpe:2.3:a:oracle:jre:1.6.0
-
-
cpe:2.3:a:oracle:jre:1.7.0
-
cpe:2.3:a:oracle:openjdk:-
-
cpe:2.3:a:oracle:openjdk:1.6.0
-
cpe:2.3:a:oracle:openjdk:1.7.0