CVE-2015-0491

Unspecified vulnerability in Oracle Java SE 5.0u81, 6u91, 7u76, and 8u40, and Java FX 2.2.76, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D, a different vulnerability than CVE-2015-0459.

Published: 2015-04-16 Last update: 2026-06-16 Assigner: [email protected] Source: [email protected]

Conclusion & alert: CVE-2015-0491 is rated High Risk (70.3/100): CVSS Critical severity, with high exploitation likelihood (EPSS 6.28%, 93th percentile). Core evidence: EPSS ranks this CVE among the most likely to be exploited in the near term. Mandatory action: High exploitation likelihood—assess exposure and prioritize remediation.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

Exploit prediction scoring system (EPSS) score for CVE-2015-0491

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2026-06-15 8.40% 6.28% -2.11%
2 2026-05-13 7.85% 8.40% +0.54%
3 2025-12-28 7.85%

Full EPSS history (20 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2015-0491

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
10.0 2.0 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C Click to expand
Access vector (AV:N)
Can be exploited remotely over network reachability.
Access complexity (AC:L)
Exploitation conditions are straightforward and predictable.
Authentication (AU:N)
No authentication is required.
Confidentiality impact (C:C)
Complete confidentiality impact.
Integrity impact (I:C)
Complete integrity impact.
Availability impact (A:C)
Complete availability impact.
10.0 10.0 [email protected]

Weakness enumeration for CVE-2015-0491

OS Trackers for CVE-2015-0491

vendor priority summary link
debian unimportant CVE-2015-0491 unimportant priority: Debian including 1 source packages (openjdk-8), 1 status rows across 1 suites (sid): resolved 1. https://security-tracker.debian.org/tracker/CVE-2015-0491
gentoo normal CVE-2015-0491: 1 GLSA(s) (201603-11), 2 atom(s) (dev-java/oracle-jdk-bin, dev-java/oracle-jre-bin); latest impact normal. https://bugs.gentoo.org/buglist.cgi?quicksearch=CVE-2015-0491
redhat critical https://access.redhat.com/security/cve/CVE-2015-0491
suse critical https://www.suse.com/security/cve/CVE-2015-0491/
ubuntu medium CVE-2015-0491 medium priority: Ubuntu including 3 source packages (openjdk-6, openjdk-7, openjdk-8), 15 status rows across 5 suites (lucid, precise, trusty, upstream, utopic): not-affected 9, DNE 6. https://ubuntu.com/security/CVE-2015-0491

NVD evaluator notes for CVE-2015-0491

Comment: Per Oracle: Applies to client deployment of Java only. This vulnerability can be exploited only through sandboxed Java Web Start applications and sandboxed Java applets. (http://www.oracle.com/technetwork/topics/security/cpuapr2015-2365600.html)

Affected software / configurations for CVE-2015-0491

Vendor Product Version Raw CPE
oracle jdk 1.5.0 cpe:2.3:a:oracle:jdk:1.5.0:update8:*:*:*:*:*:*
oracle jdk 1.6.0 cpe:2.3:a:oracle:jdk:1.6.0:update91:*:*:*:*:*:*
oracle jdk 1.7.0 cpe:2.3:a:oracle:jdk:1.7.0:update76:*:*:*:*:*:*
oracle jdk 1.8.0 cpe:2.3:a:oracle:jdk:1.8.0:update40:*:*:*:*:*:*
oracle jre 1.5.0 cpe:2.3:a:oracle:jre:1.5.0:update81:*:*:*:*:*:*
oracle jre 1.6.0 cpe:2.3:a:oracle:jre:1.6.0:update91:*:*:*:*:*:*
oracle jre 1.7.0 cpe:2.3:a:oracle:jre:1.7.0:update76:*:*:*:*:*:*
oracle jre 1.8.0 cpe:2.3:a:oracle:jre:1.8.0:update40:*:*:*:*:*:*
oracle javafx 2.2.76 cpe:2.3:a:oracle:javafx:2.2.76:*:*:*:*:*:*:*
suse suse_linux_enterprise_desktop 11.0 cpe:2.3:o:suse:suse_linux_enterprise_desktop:11.0:sp3:*:*:*:*:*:*
opensuse opensuse 13.2 cpe:2.3:o:opensuse:opensuse:13.2:*:*:*:*:*:*:*

References for CVE-2015-0491

URL Tags
http://lists.opensuse.org/opensuse-security-announce/2015-04/msg00017.html
http://lists.opensuse.org/opensuse-security-announce/2015-04/msg00018.html
http://lists.opensuse.org/opensuse-security-announce/2015-05/msg00002.html
http://lists.opensuse.org/opensuse-security-announce/2015-06/msg00014.html
http://lists.opensuse.org/opensuse-security-announce/2015-06/msg00015.html
http://lists.opensuse.org/opensuse-security-announce/2015-06/msg00022.html
http://lists.opensuse.org/opensuse-security-announce/2015-06/msg00031.html
http://lists.opensuse.org/opensuse-security-announce/2015-12/msg00000.html
http://lists.opensuse.org/opensuse-security-announce/2015-12/msg00001.html
http://lists.opensuse.org/opensuse-security-announce/2015-12/msg00003.html
http://lists.opensuse.org/opensuse-security-announce/2015-12/msg00004.html
http://lists.opensuse.org/opensuse-security-announce/2015-12/msg00006.html
http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00005.html
http://rhn.redhat.com/errata/RHSA-2015-0854.html
http://rhn.redhat.com/errata/RHSA-2015-0857.html
http://rhn.redhat.com/errata/RHSA-2015-0858.html
http://rhn.redhat.com/errata/RHSA-2015-1006.html
http://rhn.redhat.com/errata/RHSA-2015-1007.html
http://rhn.redhat.com/errata/RHSA-2015-1020.html
http://rhn.redhat.com/errata/RHSA-2015-1021.html
http://rhn.redhat.com/errata/RHSA-2015-1091.html
http://www-01.ibm.com/support/docview.wss?uid=swg21883640
http://www.oracle.com/technetwork/topics/security/cpuapr2015-2365600.html Vendor Advisory
http://www.securityfocus.com/bid/74094
http://www.securitytracker.com/id/1032120
https://security.gentoo.org/glsa/201603-11
cvelogic Threat Intelligence