CVE-2016-3500: Unspecified vulnerability in Oracle Java SE 6u115, 7u101, and 8u92; Java SE Embedded 8u91; and JRockit R28.3.10 allows r
infovulnerability
security
Summary
A vulnerability (CVE-2016-3500) exists in several versions of Oracle Java SE and related products that allows remote attackers to disrupt service through a flaw in JAXP (Java API for XML Processing, a tool for handling XML data). The vulnerability affects Java SE versions 6u115, 7u101, 8u92, Java SE Embedded 8u91, and JRockit R28.3.10.
Vulnerability Details
CVSS Score
5
EPSS (30-day exploit probability)
EPSS: 11.6%
Classification
Attack SophisticationModerate
Impact (CIA+S)
availability
Original source: https://nvd.nist.gov/vuln/detail/CVE-2016-3500
First tracked: February 15, 2026 at 08:43 PM
Classified by LLM (prompt v3) · confidence: 95%