CVE-2014-4223
published 2014-07-17CVE-2014-4223: Unspecified vulnerability in Oracle Java SE 7u60 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to…
critical9.3CVSS 3.1
AVNACMAuNCCICAC
Unspecified vulnerability in Oracle Java SE 7u60 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries, a different vulnerability than CVE-2014-2483.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| oracle | jdk | — | — |
| oracle | jre | — | — |
| oracle | openjdk | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
CVSS provenance
nvd9.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv9.3CRITICAL
Ubuntu
OpenJDK 7 update
vendor_ubuntu·2014-09-17·CVSS 9.3
CVE-2014-2483 [CRITICAL] OpenJDK 7 update
Title: OpenJDK 7 update
Summary: This update provides stability updates for OpenJDK 7.
USN-2319-1 fixed vulnerabilities in OpenJDK 7. This update provides
stability fixes for the arm64 and ppc64el architectures.
Original advisory details:
Several vulnerabilities were discovered in the OpenJDK JRE related to
information disclosure, data integrity and availability. An attacker could
exploit these to cause a denial of service or expose sensitive data over
the network. (CVE-2014-2483, CVE-2014-2490, CVE-2014-4216, CVE-2014-4219,
CVE-2014-4223, CVE-2014-4262)
Several vulnerabilities were discovered in the OpenJDK JRE related to
information disclosure and data integrity. An attacker could exploit these
to expose sensitive data over the network. (CVE-2014-4209, CVE-2014-4244,
CVE-2014-4263)
Ubuntu
OpenJDK 7 regression
vendor_ubuntu·2014-08-26·CVSS 9.3
[CRITICAL] OpenJDK 7 regression
Title: OpenJDK 7 regression
Summary: USN-2319-1 introduced a regression in OpenJDK 7.
USN-2319-1 fixed vulnerabilities in OpenJDK 7. Due to an upstream
regression, verifying of the init method call would fail when it was done
from inside a branch when stack frames are activated. This update fixes the
problem.
We apologize for the inconvenience.
Original advisory details:
Several vulnerabilities were discovered in the OpenJDK JRE related to
information disclosure, data integrity and availability. An attacker could
exploit these to cause a denial of service or expose sensitive data over
the network. (CVE-2014-2483, CVE-2014-2490, CVE-2014-4216, CVE-2014-4219,
CVE-2014-4223, CVE-2014-4262)
Several vulnerabilities were discovered in the OpenJDK JRE related to
information disclosure and d
Ubuntu
OpenJDK 7 vulnerabilities
vendor_ubuntu·2014-08-20·CVSS 9.3
CVE-2014-2483 [CRITICAL] OpenJDK 7 vulnerabilities
Title: OpenJDK 7 vulnerabilities
Summary: Several security issues were fixed in OpenJDK 7.
Several vulnerabilities were discovered in the OpenJDK JRE related to
information disclosure, data integrity and availability. An attacker could
exploit these to cause a denial of service or expose sensitive data over
the network. (CVE-2014-2483, CVE-2014-2490, CVE-2014-4216, CVE-2014-4219,
CVE-2014-4223, CVE-2014-4262)
Several vulnerabilities were discovered in the OpenJDK JRE related to
information disclosure and data integrity. An attacker could exploit these
to expose sensitive data over the network. (CVE-2014-4209, CVE-2014-4244,
CVE-2014-4263)
Two vulnerabilities were discovered in the OpenJDK JRE related to data
integrity. (CVE-2014-4218, CVE-2014-4266)
A vulnerability was discovered in t
Red Hat
OpenJDK: Restrict use of privileged annotations (Libraries, 8034985)
vendor_redhat·2014-07-15·CVSS 9.3
CVE-2014-2483 [CRITICAL] OpenJDK: Restrict use of privileged annotations (Libraries, 8034985)
OpenJDK: Restrict use of privileged annotations (Libraries, 8034985)
Unspecified vulnerability in the Java SE component in Oracle Java SE Java SE 7u60 and OpenJDK 7 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries, a different vulnerability than CVE-2014-4223. NOTE: the previous information is from the July 2014 CPU. Oracle has not commented on another vendor's claim that the issue is related to improper restriction of the "use of privileged annotations."
Package: java-1.6.0-openjdk (Red Hat Enterprise Linux 5) - Not affected
Package: java-1.6.0-sun (Red Hat Enterprise Linux 5) - Not affected
Package: java-1.6.0-openjdk (Red Hat Enterprise Linux 6) - Not affected
Package: java-1.6.0-sun (Red Hat Enterprise Linux 6)
Red Hat
OpenJDK: Incorrect handling of invocations with exhausted ranks (Libraries, 8035793)
vendor_redhat·2014-07-15·CVSS 9.3
CVE-2014-4223 [CRITICAL] OpenJDK: Incorrect handling of invocations with exhausted ranks (Libraries, 8035793)
OpenJDK: Incorrect handling of invocations with exhausted ranks (Libraries, 8035793)
Unspecified vulnerability in Oracle Java SE 7u60 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries, a different vulnerability than CVE-2014-2483.
Package: java-1.6.0-openjdk (Red Hat Enterprise Linux 5) - Not affected
Package: java-1.6.0-sun (Red Hat Enterprise Linux 5) - Not affected
Package: java-1.6.0-openjdk (Red Hat Enterprise Linux 6) - Not affected
Package: java-1.6.0-sun (Red Hat Enterprise Linux 6) - Not affected
Package: java-1.6.0-openjdk (Red Hat Enterprise Linux 7) - Not affected
Package: java-1.6.0-sun (Red Hat Enterprise Linux 7) - Not affected
GHSA
GHSA-9pmr-9fpq-fq64: Unspecified vulnerability in the Java SE component in Oracle Java SE Java SE 7u60 and OpenJDK 7 allows remote attackers to affect confidentiality, int
ghsa_unreviewed·2022-05-13·CVSS 9.3
CVE-2014-2483 [CRITICAL] GHSA-9pmr-9fpq-fq64: Unspecified vulnerability in the Java SE component in Oracle Java SE Java SE 7u60 and OpenJDK 7 allows remote attackers to affect confidentiality, int
Unspecified vulnerability in the Java SE component in Oracle Java SE Java SE 7u60 and OpenJDK 7 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries, a different vulnerability than CVE-2014-4223. NOTE: the previous information is from the July 2014 CPU. Oracle has not commented on another vendor's claim that the issue is related to improper restriction of the "use of privileged annotations."
GHSA
GHSA-x77f-3hr5-3569: Unspecified vulnerability in Oracle Java SE 7u60 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors re
ghsa_unreviewed·2022-05-13·CVSS 9.3
CVE-2014-4223 [CRITICAL] GHSA-x77f-3hr5-3569: Unspecified vulnerability in Oracle Java SE 7u60 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors re
Unspecified vulnerability in Oracle Java SE 7u60 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries, a different vulnerability than CVE-2014-2483.
OSV
openjdk-7 update
osv·2014-09-17·CVSS 9.3
CVE-2014-2483 [CRITICAL] openjdk-7 update
openjdk-7 update
USN-2319-1 fixed vulnerabilities in OpenJDK 7. This update provides
stability fixes for the arm64 and ppc64el architectures.
Original advisory details:
Several vulnerabilities were discovered in the OpenJDK JRE related to
information disclosure, data integrity and availability. An attacker could
exploit these to cause a denial of service or expose sensitive data over
the network. (CVE-2014-2483, CVE-2014-2490, CVE-2014-4216, CVE-2014-4219,
CVE-2014-4223, CVE-2014-4262)
Several vulnerabilities were discovered in the OpenJDK JRE related to
information disclosure and data integrity. An attacker could exploit these
to expose sensitive data over the network. (CVE-2014-4209, CVE-2014-4244,
CVE-2014-4263)
Two vulnerabilities were discovered in the OpenJDK JRE related to data
OSV
openjdk-7 regression
osv·2014-08-26·CVSS 9.3
[CRITICAL] openjdk-7 regression
openjdk-7 regression
USN-2319-1 fixed vulnerabilities in OpenJDK 7. Due to an upstream
regression, verifying of the init method call would fail when it was done
from inside a branch when stack frames are activated. This update fixes the
problem.
We apologize for the inconvenience.
Original advisory details:
Several vulnerabilities were discovered in the OpenJDK JRE related to
information disclosure, data integrity and availability. An attacker could
exploit these to cause a denial of service or expose sensitive data over
the network. (CVE-2014-2483, CVE-2014-2490, CVE-2014-4216, CVE-2014-4219,
CVE-2014-4223, CVE-2014-4262)
Several vulnerabilities were discovered in the OpenJDK JRE related to
information disclosure and data integrity. An attacker could exploit these
to expose sensitive
OSV
openjdk-7 vulnerabilities
osv·2014-08-20·CVSS 9.3
CVE-2014-2483 [CRITICAL] openjdk-7 vulnerabilities
openjdk-7 vulnerabilities
Several vulnerabilities were discovered in the OpenJDK JRE related to
information disclosure, data integrity and availability. An attacker could
exploit these to cause a denial of service or expose sensitive data over
the network. (CVE-2014-2483, CVE-2014-2490, CVE-2014-4216, CVE-2014-4219,
CVE-2014-4223, CVE-2014-4262)
Several vulnerabilities were discovered in the OpenJDK JRE related to
information disclosure and data integrity. An attacker could exploit these
to expose sensitive data over the network. (CVE-2014-4209, CVE-2014-4244,
CVE-2014-4263)
Two vulnerabilities were discovered in the OpenJDK JRE related to data
integrity. (CVE-2014-4218, CVE-2014-4266)
A vulnerability was discovered in the OpenJDK JRE related to availability.
An attacker could exploit
No detection rules found.
No public exploits indexed.
http://marc.info/?l=bugtraq&m=140852886808946&w=2http://seclists.org/fulldisclosure/2014/Dec/23http://secunia.com/advisories/60485http://secunia.com/advisories/60812http://security.gentoo.org/glsa/glsa-201502-12.xmlhttp://www.debian.org/security/2014/dsa-2987http://www.oracle.com/technetwork/topics/security/cpujul2014-1972956.htmlhttp://www.securityfocus.com/archive/1/534161/100/0/threadedhttp://www.securityfocus.com/bid/68590http://www.securitytracker.com/id/1030577http://www.vmware.com/security/advisories/VMSA-2014-0012.htmlhttps://access.redhat.com/errata/RHSA-2014:0902https://exchange.xforce.ibmcloud.com/vulnerabilities/94594http://marc.info/?l=bugtraq&m=140852886808946&w=2http://seclists.org/fulldisclosure/2014/Dec/23http://secunia.com/advisories/60485http://secunia.com/advisories/60812http://security.gentoo.org/glsa/glsa-201502-12.xmlhttp://www.debian.org/security/2014/dsa-2987http://www.oracle.com/technetwork/topics/security/cpujul2014-1972956.htmlhttp://www.securityfocus.com/archive/1/534161/100/0/threadedhttp://www.securityfocus.com/bid/68590http://www.securitytracker.com/id/1030577http://www.vmware.com/security/advisories/VMSA-2014-0012.htmlhttps://access.redhat.com/errata/RHSA-2014:0902https://exchange.xforce.ibmcloud.com/vulnerabilities/94594
2014-07-17
Published