Vulnerabilities > Oracle > Openjdk

DATE CVE VULNERABILITY TITLE RISK
2014-07-17 CVE-2014-2483 Unspecified vulnerability in the Java SE component in Oracle Java SE Java SE 7u60 and OpenJDK 7 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries, a different vulnerability than CVE-2014-4223.
network
redhat debian oracle
critical
9.3
2014-05-14 CVE-2014-2405 Remote Security vulnerability in Oracle Openjdk 1.6.0
Unspecified vulnerability in OpenJDK 6 before 6b31 on Debian GNU/Linux and Ubuntu 12.04 LTS and 10.04 LTS has unknown impact and attack vectors, a different vulnerability than CVE-2014-0462.
network
low complexity
oracle canonical debian
critical
10.0
2014-05-14 CVE-2014-0462 Remote Security vulnerability in Oracle Openjdk 1.6.0
Unspecified vulnerability in OpenJDK 6 before 6b31 on Debian GNU/Linux and Ubuntu 12.04 LTS and 10.04 LTS has unknown impact and attack vectors, a different vulnerability than CVE-2014-2405.
network
low complexity
oracle canonical debian
critical
10.0
2014-02-10 CVE-2014-1876 Link Following vulnerability in Oracle Openjdk 1.6.0/1.7.0/1.8.0
The unpacker::redirect_stdio function in unpack.cpp in unpack200 in OpenJDK 6, 7, and 8; Oracle Java SE 5.0u61, 6u71, 7u51, and 8; JRockit R27.8.1 and R28.3.1; and Java SE Embedded 7u51 does not securely create temporary files when a log file cannot be opened, which allows local users to overwrite arbitrary files via a symlink attack on /tmp/unpack.log.
local
oracle CWE-59
4.4
2013-06-18 CVE-2013-2461 Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier and 6 Update 45 and earlier; the Oracle JRockit component in Oracle Fusion Middleware R27.7.5 and earlier and R28.2.7 and earlier; and OpenJDK 7 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries.
network
low complexity
sun oracle
7.5
2012-11-28 CVE-2012-5373 Cryptographic Issues vulnerability in Oracle Jdk, JRE and Openjdk
Oracle Java SE 7 and earlier, and OpenJDK 7 and earlier, computes hash values without properly restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table, as demonstrated by a universal multicollision attack against the MurmurHash3 algorithm, a different vulnerability than CVE-2012-2739.
network
low complexity
oracle CWE-310
5.0
2012-11-28 CVE-2012-2739 Cryptographic Issues vulnerability in Oracle Jdk, JRE and Openjdk
Oracle Java SE before 7 Update 6, and OpenJDK 7 before 7u6 build 12 and 8 before build 39, computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table.
network
low complexity
oracle CWE-310
5.0