Vulnerabilities > Oracle > JDK > Critical

DATE CVE VULNERABILITY TITLE RISK
2017-05-23 CVE-2016-9841 inffast.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic.
network
low complexity
zlib opensuse debian canonical oracle redhat apple netapp nodejs
critical
9.8
2017-05-23 CVE-2016-9843 The crc32_big function in crc32.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact via vectors involving big-endian CRC calculation.
network
low complexity
zlib opensuse debian canonical oracle redhat apple netapp mariadb nodejs
critical
9.8
2016-10-25 CVE-2016-5556 Improper Access Control vulnerability in Oracle JDK and JRE
Unspecified vulnerability in Oracle Java SE 6u121, 7u111, and 8u102 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to 2D.
network
low complexity
oracle CWE-284
critical
9.6
2016-10-25 CVE-2016-5568 Improper Access Control vulnerability in Oracle JDK and JRE
Unspecified vulnerability in Oracle Java SE 6u121, 7u111, and 8u102 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to AWT.
network
low complexity
oracle CWE-284
critical
9.6
2016-10-25 CVE-2016-5582 Improper Access Control vulnerability in Oracle JDK and JRE
Unspecified vulnerability in Oracle Java SE 6u121, 7u111, 8u102; and Java SE Embedded 8u101 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Hotspot, a different vulnerability than CVE-2016-5573.
network
low complexity
oracle CWE-284
critical
9.6
2016-07-21 CVE-2016-3587 Unspecified vulnerability in Oracle Jdk, JRE and Linux
Unspecified vulnerability in Oracle Java SE 8u92 and Java SE Embedded 8u91 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Hotspot.
network
oracle
critical
9.3
2016-07-21 CVE-2016-3598 Unspecified vulnerability in Oracle Jdk, JRE and Linux
Unspecified vulnerability in Oracle Java SE 8u92 and Java SE Embedded 8u91 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Libraries, a different vulnerability than CVE-2016-3610.
network
oracle
critical
9.3
2016-07-21 CVE-2016-3610 Unspecified vulnerability in Oracle Jdk, JRE and Linux
Unspecified vulnerability in Oracle Java SE 8u92 and Java SE Embedded 8u91 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Libraries, a different vulnerability than CVE-2016-3598.
network
oracle
critical
9.3
2016-04-21 CVE-2016-3427 Unspecified vulnerability in Oracle Jdk, JRE and Jrockit
Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to JMX.
network
high complexity
oracle
critical
9.0
2016-04-21 CVE-2016-3443 Unspecified vulnerability in Oracle JDK and JRE
Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to 2D.
network
low complexity
oracle
critical
10.0