CVE-2014-4208Improper Update of Reference Count in Oracle JDK

Severity
5.0MEDIUMNVD
NVD2.6CNA2.6
EPSS
2.5%
top 14.49%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJul 17
Latest updateMay 13

Description

Unspecified vulnerability in the Java SE component in Oracle Java SE 7u60 and 8u5 allows remote attackers to affect integrity via unknown vectors related to Deployment, a different vulnerability than CVE-2014-4220.

CVSS vector

AV:N/AC:H/C:N/I:P/A:NExploitability: 4.9 | Impact: 2.9

Affected Packages2 packages

NVDoracle/jdk1.7.0, 1.8.0+1
NVDoracle/jre1.7.0, 1.8.0+1

🔴Vulnerability Details

4
GHSA
GHSA-rgv6-rg5r-4v8m: Unspecified vulnerability in Oracle Java SE 7u60 and 8u5 allows remote attackers to affect integrity via unknown vectors related to Deployment, a diff2022-05-13
GHSA
GHSA-xc8x-qr4j-5rjx: Unspecified vulnerability in the Java SE component in Oracle Java SE 7u60 and 8u5 allows remote attackers to affect integrity via unknown vectors rela2022-05-13
CVEList
CVE-2014-4208: Unspecified vulnerability in the Java SE component in Oracle Java SE 7u60 and 8u5 allows remote attackers to affect integrity via unknown vectors rela2014-07-17
CVEList
CVE-2014-4220: Unspecified vulnerability in Oracle Java SE 7u60 and 8u5 allows remote attackers to affect integrity via unknown vectors related to Deployment, a diff2014-07-17

📋Vendor Advisories

2
Red Hat
JDK: unspecified vulnerability fixed in 7u65 and 8u11 (Deployment)2014-07-15
Red Hat
JDK: unspecified vulnerability fixed in 7u65 and 8u11 (Deployment)2014-07-15

💬Community

1
Bugzilla
CVE-2014-4208 Oracle JDK: unspecified vulnerability fixed in 7u65 and 8u11 (Deployment)2014-07-15
CVE-2014-4208 — Improper Update of Reference Count | cvebase