CVE-2014-0449
published 2014-04-16CVE-2014-0449: Unspecified vulnerability in Oracle Java SE 6u71, 7u51, and 8, and Java SE Embedded 7u51, allows remote attackers to affect confidentiality via unknown vectors…
medium5CVSS 3.1
AVNACLAuNCPINAN
Unspecified vulnerability in Oracle Java SE 6u71, 7u51, and 8, and Java SE Embedded 7u51, allows remote attackers to affect confidentiality via unknown vectors related to Deployment.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | jdk | — | — |
| oracle | jdk | — | — |
| oracle | jdk | — | — |
| oracle | jre | — | — |
| oracle | jre | — | — |
| oracle | jre | — | — |
Red Hat
JDK: unspecified vulnerability fixed in 6u75, 7u55 and 8u5 (Deployment)
vendor_redhat·2014-04-15·CVSS 5.0
CVE-2014-0449 [MEDIUM] JDK: unspecified vulnerability fixed in 6u75, 7u55 and 8u5 (Deployment)
JDK: unspecified vulnerability fixed in 6u75, 7u55 and 8u5 (Deployment)
Unspecified vulnerability in Oracle Java SE 6u71, 7u51, and 8, and Java SE Embedded 7u51, allows remote attackers to affect confidentiality via unknown vectors related to Deployment.
Package: java-1.5.0-ibm (Red Hat Enterprise Linux 5) - Not affected
Package: java-1.5.0-ibm (Red Hat Enterprise Linux 6) - Not affected
Package: java-1.6.0-sun (Red Hat Enterprise Linux 7) - Not affected
Package: java-1.7.0-oracle (Red Hat Enterprise Linux 7) - Not affected
VulDB
Oracle Java SE/Java SE Embedded 6u71/7u51/8 Deployment information disclosure (Nessus ID 73570 / ID 185086)
vuldb·2026-05-10·CVSS 5.0
CVE-2014-0449 [MEDIUM] Oracle Java SE/Java SE Embedded 6u71/7u51/8 Deployment information disclosure (Nessus ID 73570 / ID 185086)
A vulnerability classified as problematic was found in Oracle Java SE and Java SE Embedded 6u71/7u51/8. This vulnerability affects unknown code of the component Deployment Handler. Such manipulation leads to information disclosure.
This vulnerability is referenced as CVE-2014-0449. It is possible to launch the attack remotely. No exploit is available.
Upgrading the affected component is advised.
GHSA
GHSA-83jm-4m95-wg4p: Unspecified vulnerability in Oracle Java SE 6u71, 7u51, and 8, and Java SE Embedded 7u51, allows remote attackers to affect confidentiality via unknow
ghsa_unreviewed·2022-05-10
CVE-2014-0449 [MEDIUM] GHSA-83jm-4m95-wg4p: Unspecified vulnerability in Oracle Java SE 6u71, 7u51, and 8, and Java SE Embedded 7u51, allows remote attackers to affect confidentiality via unknow
Unspecified vulnerability in Oracle Java SE 6u71, 7u51, and 8, and Java SE Embedded 7u51, allows remote attackers to affect confidentiality via unknown vectors related to Deployment.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-1523 Mozilla: Out of bounds read while decoding JPG images (MFSA-2014-37)
bugzilla·2014-04-29·CVSS 6.5
CVE-2014-1523 [MEDIUM] CVE-2014-1523 Mozilla: Out of bounds read while decoding JPG images (MFSA-2014-37)
CVE-2014-1523 Mozilla: Out of bounds read while decoding JPG images (MFSA-2014-37)
Security researcher Abhishek Arya (Inferno) of the Google Chrome Security Team used the Address Sanitizer tool to discover a fixed offset out of bounds read issue while decoding specifically formatted JPG format images. This causes a non-exploitable crash.
External Reference:
http://www.mozilla.org/security/announce/2014/mfsa2014-37.html
Acknowledgements:
Red Hat would like to thank the Mozilla project for reporting this issue. Upstream acknowledges Abhishek Arya as the original reporter.
Discussion:
This issue has been addressed in following products:
Red Hat Enterprise Linux 5
Red Hat Enterprise Linux 6
Via RHSA-2014:0449 https://rhn.redhat.com/errata/RHSA-2014-0449.html
---
This issue has bee
Bugzilla
CVE-2014-0449 Oracle JDK: unspecified vulnerability fixed in 6u75, 7u55 and 8u5 (Deployment)
bugzilla·2014-04-15·CVSS 5.0
CVE-2014-0449 [MEDIUM] CVE-2014-0449 Oracle JDK: unspecified vulnerability fixed in 6u75, 7u55 and 8u5 (Deployment)
CVE-2014-0449 Oracle JDK: unspecified vulnerability fixed in 6u75, 7u55 and 8u5 (Deployment)
Oracle Java SE 6u75, 7u55 and 8u5 fixes an unspecified vulnerability in the Deployment component (CVE-2014-0449). Upstream has CVSSv2 scored this issue as: 5.0/AV:N/AC:L/Au:N/C:P/I:N/A:N
External Reference:
http://www.oracle.com/technetwork/topics/security/cpuapr2014-1972952.html#AppendixJAVA
Discussion:
This issue has been addressed in following products:
Oracle Java for Red Hat Enterprise Linux 6
Oracle Java for Red Hat Enterprise Linux 5
Via RHSA-2014:0413 https://rhn.redhat.com/errata/RHSA-2014-0413.html
---
This issue has been addressed in following products:
Supplementary for Red Hat Enterprise Linux 6
Supplementary for Red Hat Enterprise Linux 5
Via RHSA-2014:0412 https://rhn.redh
http://marc.info/?l=bugtraq&m=140852886808946&w=2http://marc.info/?l=bugtraq&m=140852974709252&w=2http://security.gentoo.org/glsa/glsa-201502-12.xmlhttp://www-01.ibm.com/support/docview.wss?uid=swg21672080http://www.oracle.com/technetwork/topics/security/cpuapr2014-1972952.htmlhttp://www.securityfocus.com/bid/66907https://access.redhat.com/errata/RHSA-2014:0413https://access.redhat.com/errata/RHSA-2014:0414http://marc.info/?l=bugtraq&m=140852886808946&w=2http://marc.info/?l=bugtraq&m=140852974709252&w=2http://security.gentoo.org/glsa/glsa-201502-12.xmlhttp://www-01.ibm.com/support/docview.wss?uid=swg21672080http://www.oracle.com/technetwork/topics/security/cpuapr2014-1972952.htmlhttp://www.securityfocus.com/bid/66907https://access.redhat.com/errata/RHSA-2014:0413https://access.redhat.com/errata/RHSA-2014:0414
2014-04-16
Published