CVE-2014-4219
published 2014-07-17CVE-2014-4219: Unspecified vulnerability in Oracle Java SE 6u75, 7u60, and 8u5 allows remote attackers to affect confidentiality, integrity, and availability via unknown…
critical9.3CVSS 3.1
AVNACMAuNCCICAC
Unspecified vulnerability in Oracle Java SE 6u75, 7u60, and 8u5 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Hotspot.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | jdk | — | — |
| oracle | jdk | — | — |
| oracle | jdk | — | — |
| oracle | jre | — | — |
| oracle | jre | — | — |
| oracle | jre | — | — |
CVSS provenance
nvd9.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv9.3CRITICAL
GHSA
GHSA-2xqm-8vg5-2563: Unspecified vulnerability in Oracle Java SE 6u75, 7u60, and 8u5 allows remote attackers to affect confidentiality, integrity, and availability via unk
ghsa_unreviewed·2022-05-13
CVE-2014-4219 [HIGH] GHSA-2xqm-8vg5-2563: Unspecified vulnerability in Oracle Java SE 6u75, 7u60, and 8u5 allows remote attackers to affect confidentiality, integrity, and availability via unk
Unspecified vulnerability in Oracle Java SE 6u75, 7u60, and 8u5 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Hotspot.
OSV
openjdk-7 update
osv·2014-09-17·CVSS 9.3
CVE-2014-2483 [CRITICAL] openjdk-7 update
openjdk-7 update
USN-2319-1 fixed vulnerabilities in OpenJDK 7. This update provides
stability fixes for the arm64 and ppc64el architectures.
Original advisory details:
Several vulnerabilities were discovered in the OpenJDK JRE related to
information disclosure, data integrity and availability. An attacker could
exploit these to cause a denial of service or expose sensitive data over
the network. (CVE-2014-2483, CVE-2014-2490, CVE-2014-4216, CVE-2014-4219,
CVE-2014-4223, CVE-2014-4262)
Several vulnerabilities were discovered in the OpenJDK JRE related to
information disclosure and data integrity. An attacker could exploit these
to expose sensitive data over the network. (CVE-2014-4209, CVE-2014-4244,
CVE-2014-4263)
Two vulnerabilities were discovered in the OpenJDK JRE related to data
OSV
openjdk-7 regression
osv·2014-08-26·CVSS 9.3
[CRITICAL] openjdk-7 regression
openjdk-7 regression
USN-2319-1 fixed vulnerabilities in OpenJDK 7. Due to an upstream
regression, verifying of the init method call would fail when it was done
from inside a branch when stack frames are activated. This update fixes the
problem.
We apologize for the inconvenience.
Original advisory details:
Several vulnerabilities were discovered in the OpenJDK JRE related to
information disclosure, data integrity and availability. An attacker could
exploit these to cause a denial of service or expose sensitive data over
the network. (CVE-2014-2483, CVE-2014-2490, CVE-2014-4216, CVE-2014-4219,
CVE-2014-4223, CVE-2014-4262)
Several vulnerabilities were discovered in the OpenJDK JRE related to
information disclosure and data integrity. An attacker could exploit these
to expose sensitive
OSV
openjdk-7 vulnerabilities
osv·2014-08-20·CVSS 9.3
CVE-2014-2483 [CRITICAL] openjdk-7 vulnerabilities
openjdk-7 vulnerabilities
Several vulnerabilities were discovered in the OpenJDK JRE related to
information disclosure, data integrity and availability. An attacker could
exploit these to cause a denial of service or expose sensitive data over
the network. (CVE-2014-2483, CVE-2014-2490, CVE-2014-4216, CVE-2014-4219,
CVE-2014-4223, CVE-2014-4262)
Several vulnerabilities were discovered in the OpenJDK JRE related to
information disclosure and data integrity. An attacker could exploit these
to expose sensitive data over the network. (CVE-2014-4209, CVE-2014-4244,
CVE-2014-4263)
Two vulnerabilities were discovered in the OpenJDK JRE related to data
integrity. (CVE-2014-4218, CVE-2014-4266)
A vulnerability was discovered in the OpenJDK JRE related to availability.
An attacker could exploit
OSV
CVE-2014-4219: Unspecified vulnerability in Oracle Java SE 6u75, 7u60, and 8u5 allows remote attackers to affect confidentiality, integrity, and availability via unk
osv·2014-07-17·CVSS 9.3
CVE-2014-4219 [CRITICAL] CVE-2014-4219: Unspecified vulnerability in Oracle Java SE 6u75, 7u60, and 8u5 allows remote attackers to affect confidentiality, integrity, and availability via unk
Unspecified vulnerability in Oracle Java SE 6u75, 7u60, and 8u5 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Hotspot.
Ubuntu
OpenJDK 7 update
vendor_ubuntu·2014-09-17·CVSS 9.3
CVE-2014-2483 [CRITICAL] OpenJDK 7 update
Title: OpenJDK 7 update
Summary: This update provides stability updates for OpenJDK 7.
USN-2319-1 fixed vulnerabilities in OpenJDK 7. This update provides
stability fixes for the arm64 and ppc64el architectures.
Original advisory details:
Several vulnerabilities were discovered in the OpenJDK JRE related to
information disclosure, data integrity and availability. An attacker could
exploit these to cause a denial of service or expose sensitive data over
the network. (CVE-2014-2483, CVE-2014-2490, CVE-2014-4216, CVE-2014-4219,
CVE-2014-4223, CVE-2014-4262)
Several vulnerabilities were discovered in the OpenJDK JRE related to
information disclosure and data integrity. An attacker could exploit these
to expose sensitive data over the network. (CVE-2014-4209, CVE-2014-4244,
CVE-2014-4263)
Ubuntu
OpenJDK 7 regression
vendor_ubuntu·2014-08-26·CVSS 9.3
[CRITICAL] OpenJDK 7 regression
Title: OpenJDK 7 regression
Summary: USN-2319-1 introduced a regression in OpenJDK 7.
USN-2319-1 fixed vulnerabilities in OpenJDK 7. Due to an upstream
regression, verifying of the init method call would fail when it was done
from inside a branch when stack frames are activated. This update fixes the
problem.
We apologize for the inconvenience.
Original advisory details:
Several vulnerabilities were discovered in the OpenJDK JRE related to
information disclosure, data integrity and availability. An attacker could
exploit these to cause a denial of service or expose sensitive data over
the network. (CVE-2014-2483, CVE-2014-2490, CVE-2014-4216, CVE-2014-4219,
CVE-2014-4223, CVE-2014-4262)
Several vulnerabilities were discovered in the OpenJDK JRE related to
information disclosure and d
Ubuntu
OpenJDK 7 vulnerabilities
vendor_ubuntu·2014-08-20·CVSS 9.3
CVE-2014-2483 [CRITICAL] OpenJDK 7 vulnerabilities
Title: OpenJDK 7 vulnerabilities
Summary: Several security issues were fixed in OpenJDK 7.
Several vulnerabilities were discovered in the OpenJDK JRE related to
information disclosure, data integrity and availability. An attacker could
exploit these to cause a denial of service or expose sensitive data over
the network. (CVE-2014-2483, CVE-2014-2490, CVE-2014-4216, CVE-2014-4219,
CVE-2014-4223, CVE-2014-4262)
Several vulnerabilities were discovered in the OpenJDK JRE related to
information disclosure and data integrity. An attacker could exploit these
to expose sensitive data over the network. (CVE-2014-4209, CVE-2014-4244,
CVE-2014-4263)
Two vulnerabilities were discovered in the OpenJDK JRE related to data
integrity. (CVE-2014-4218, CVE-2014-4266)
A vulnerability was discovered in t
Ubuntu
OpenJDK 6 vulnerabilities
vendor_ubuntu·2014-08-12·CVSS 9.3
CVE-2014-2490 [CRITICAL] OpenJDK 6 vulnerabilities
Title: OpenJDK 6 vulnerabilities
Summary: Several security issues were fixed in OpenJDK 6.
Several vulnerabilities were discovered in the OpenJDK JRE related to
information disclosure, data integrity and availability. An attacker could
exploit these to cause a denial of service or expose sensitive data over
the network. (CVE-2014-2490, CVE-2014-4216, CVE-2014-4219, CVE-2014-4262)
Several vulnerabilities were discovered in the OpenJDK JRE related to
information disclosure and data integrity. An attacker could exploit these
to expose sensitive data over the network. (CVE-2014-4209, CVE-2014-4244,
CVE-2014-4263)
Two vulnerabilities were discovered in the OpenJDK JRE related to data
integrity. (CVE-2014-4218, CVE-2014-4266)
Two vulnerabilities were discovered in the OpenJDK JRE related to
Red Hat
OpenJDK: Bytecode verification does not prevent ctor calls to this() and super() (Hotspot, 8035119)
vendor_redhat·2014-07-15·CVSS 9.3
CVE-2014-4219 [CRITICAL] OpenJDK: Bytecode verification does not prevent ctor calls to this() and super() (Hotspot, 8035119)
OpenJDK: Bytecode verification does not prevent ctor calls to this() and super() (Hotspot, 8035119)
Unspecified vulnerability in Oracle Java SE 6u75, 7u60, and 8u5 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Hotspot.
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-security-announce/2015-02/msg00026.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-02/msg00033.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-02/msg00036.htmlhttp://marc.info/?l=bugtraq&m=140852974709252&w=2http://rhn.redhat.com/errata/RHSA-2015-0264.htmlhttp://seclists.org/fulldisclosure/2014/Dec/23http://secunia.com/advisories/59404http://secunia.com/advisories/59680http://secunia.com/advisories/59924http://secunia.com/advisories/59985http://secunia.com/advisories/59986http://secunia.com/advisories/59987http://secunia.com/advisories/60081http://secunia.com/advisories/60129http://secunia.com/advisories/60245http://secunia.com/advisories/60317http://secunia.com/advisories/60485http://secunia.com/advisories/60622http://secunia.com/advisories/60812http://secunia.com/advisories/60817http://secunia.com/advisories/61577http://secunia.com/advisories/61640http://security.gentoo.org/glsa/glsa-201502-12.xmlhttp://www-01.ibm.com/support/docview.wss?uid=swg21680334http://www-01.ibm.com/support/docview.wss?uid=swg21686383http://www-01.ibm.com/support/docview.wss?uid=swg21686824http://www.debian.org/security/2014/dsa-2980http://www.debian.org/security/2014/dsa-2987http://www.oracle.com/technetwork/topics/security/cpujul2014-1972956.htmlhttp://www.securityfocus.com/archive/1/534161/100/0/threadedhttp://www.securityfocus.com/bid/68620http://www.securitytracker.com/id/1030577http://www.vmware.com/security/advisories/VMSA-2014-0012.htmlhttps://access.redhat.com/errata/RHSA-2014:0902https://access.redhat.com/errata/RHSA-2014:0908https://exchange.xforce.ibmcloud.com/vulnerabilities/94589http://lists.opensuse.org/opensuse-security-announce/2015-02/msg00026.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-02/msg00033.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-02/msg00036.htmlhttp://marc.info/?l=bugtraq&m=140852974709252&w=2http://rhn.redhat.com/errata/RHSA-2015-0264.htmlhttp://seclists.org/fulldisclosure/2014/Dec/23http://secunia.com/advisories/59404http://secunia.com/advisories/59680http://secunia.com/advisories/59924http://secunia.com/advisories/59985http://secunia.com/advisories/59986http://secunia.com/advisories/59987http://secunia.com/advisories/60081http://secunia.com/advisories/60129http://secunia.com/advisories/60245http://secunia.com/advisories/60317http://secunia.com/advisories/60485http://secunia.com/advisories/60622http://secunia.com/advisories/60812http://secunia.com/advisories/60817http://secunia.com/advisories/61577http://secunia.com/advisories/61640http://security.gentoo.org/glsa/glsa-201502-12.xmlhttp://www-01.ibm.com/support/docview.wss?uid=swg21680334http://www-01.ibm.com/support/docview.wss?uid=swg21686383http://www-01.ibm.com/support/docview.wss?uid=swg21686824http://www.debian.org/security/2014/dsa-2980http://www.debian.org/security/2014/dsa-2987http://www.oracle.com/technetwork/topics/security/cpujul2014-1972956.htmlhttp://www.securityfocus.com/archive/1/534161/100/0/threadedhttp://www.securityfocus.com/bid/68620http://www.securitytracker.com/id/1030577http://www.vmware.com/security/advisories/VMSA-2014-0012.htmlhttps://access.redhat.com/errata/RHSA-2014:0902https://access.redhat.com/errata/RHSA-2014:0908https://exchange.xforce.ibmcloud.com/vulnerabilities/94589
2014-07-17
Published