CVE-2014-4268
published 2014-07-17CVE-2014-4268: Unspecified vulnerability in Oracle Java SE 5.0u65, 6u75, 7u60, and 8u5 allows remote attackers to affect confidentiality via unknown vectors related to Swing.
medium5CVSS 3.1
AVNACLAuNCPINAN
Unspecified vulnerability in Oracle Java SE 5.0u65, 6u75, 7u60, and 8u5 allows remote attackers to affect confidentiality via unknown vectors related to Swing.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | jdk | — | — |
| oracle | jdk | — | — |
| oracle | jdk | — | — |
| oracle | jdk | — | — |
| oracle | jre | — | — |
| oracle | jre | — | — |
| oracle | jre | — | — |
| oracle | jre | — | — |
CVSS provenance
nvd5.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv9.3CRITICAL
Ubuntu
OpenJDK 7 update
vendor_ubuntu·2014-09-17·CVSS 9.3
CVE-2014-2483 [CRITICAL] OpenJDK 7 update
Title: OpenJDK 7 update
Summary: This update provides stability updates for OpenJDK 7.
USN-2319-1 fixed vulnerabilities in OpenJDK 7. This update provides
stability fixes for the arm64 and ppc64el architectures.
Original advisory details:
Several vulnerabilities were discovered in the OpenJDK JRE related to
information disclosure, data integrity and availability. An attacker could
exploit these to cause a denial of service or expose sensitive data over
the network. (CVE-2014-2483, CVE-2014-2490, CVE-2014-4216, CVE-2014-4219,
CVE-2014-4223, CVE-2014-4262)
Several vulnerabilities were discovered in the OpenJDK JRE related to
information disclosure and data integrity. An attacker could exploit these
to expose sensitive data over the network. (CVE-2014-4209, CVE-2014-4244,
CVE-2014-4263)
Ubuntu
OpenJDK 7 regression
vendor_ubuntu·2014-08-26·CVSS 9.3
[CRITICAL] OpenJDK 7 regression
Title: OpenJDK 7 regression
Summary: USN-2319-1 introduced a regression in OpenJDK 7.
USN-2319-1 fixed vulnerabilities in OpenJDK 7. Due to an upstream
regression, verifying of the init method call would fail when it was done
from inside a branch when stack frames are activated. This update fixes the
problem.
We apologize for the inconvenience.
Original advisory details:
Several vulnerabilities were discovered in the OpenJDK JRE related to
information disclosure, data integrity and availability. An attacker could
exploit these to cause a denial of service or expose sensitive data over
the network. (CVE-2014-2483, CVE-2014-2490, CVE-2014-4216, CVE-2014-4219,
CVE-2014-4223, CVE-2014-4262)
Several vulnerabilities were discovered in the OpenJDK JRE related to
information disclosure and d
Ubuntu
OpenJDK 7 vulnerabilities
vendor_ubuntu·2014-08-20·CVSS 9.3
CVE-2014-2483 [CRITICAL] OpenJDK 7 vulnerabilities
Title: OpenJDK 7 vulnerabilities
Summary: Several security issues were fixed in OpenJDK 7.
Several vulnerabilities were discovered in the OpenJDK JRE related to
information disclosure, data integrity and availability. An attacker could
exploit these to cause a denial of service or expose sensitive data over
the network. (CVE-2014-2483, CVE-2014-2490, CVE-2014-4216, CVE-2014-4219,
CVE-2014-4223, CVE-2014-4262)
Several vulnerabilities were discovered in the OpenJDK JRE related to
information disclosure and data integrity. An attacker could exploit these
to expose sensitive data over the network. (CVE-2014-4209, CVE-2014-4244,
CVE-2014-4263)
Two vulnerabilities were discovered in the OpenJDK JRE related to data
integrity. (CVE-2014-4218, CVE-2014-4266)
A vulnerability was discovered in t
Ubuntu
OpenJDK 6 vulnerabilities
vendor_ubuntu·2014-08-12·CVSS 9.3
CVE-2014-2490 [CRITICAL] OpenJDK 6 vulnerabilities
Title: OpenJDK 6 vulnerabilities
Summary: Several security issues were fixed in OpenJDK 6.
Several vulnerabilities were discovered in the OpenJDK JRE related to
information disclosure, data integrity and availability. An attacker could
exploit these to cause a denial of service or expose sensitive data over
the network. (CVE-2014-2490, CVE-2014-4216, CVE-2014-4219, CVE-2014-4262)
Several vulnerabilities were discovered in the OpenJDK JRE related to
information disclosure and data integrity. An attacker could exploit these
to expose sensitive data over the network. (CVE-2014-4209, CVE-2014-4244,
CVE-2014-4263)
Two vulnerabilities were discovered in the OpenJDK JRE related to data
integrity. (CVE-2014-4218, CVE-2014-4266)
Two vulnerabilities were discovered in the OpenJDK JRE related to
Red Hat
OpenJDK: Missing file choser access restrictions (Swing, 8035699)
vendor_redhat·2014-07-15·CVSS 5.0
CVE-2014-4268 [MEDIUM] OpenJDK: Missing file choser access restrictions (Swing, 8035699)
OpenJDK: Missing file choser access restrictions (Swing, 8035699)
Unspecified vulnerability in Oracle Java SE 5.0u65, 6u75, 7u60, and 8u5 allows remote attackers to affect confidentiality via unknown vectors related to Swing.
Package: java-1.5.0-ibm (Red Hat Enterprise Linux 5) - Not affected
Package: java-1.6.0-ibm (Red Hat Enterprise Linux 5) - Not affected
Package: java-1.6.0-openjdk (Red Hat Enterprise Linux 5) - Not affected
Package: java-1.6.0-sun (Red Hat Enterprise Linux 5) - Not affected
Package: java-1.7.0-ibm (Red Hat Enterprise Linux 5) - Not affected
Package: java-1.7.0-openjdk (Red Hat Enterprise Linux 5) - Not affected
Package: java-1.7.0-oracle (Red Hat Enterprise Linux 5) - Not affected
Package: java-1.5.0-ibm (Red Hat Enterprise Linux 6) - Not affected
Package:
GHSA
GHSA-p388-pw52-w2mq: Unspecified vulnerability in Oracle Java SE 5
ghsa_unreviewed·2022-05-13
CVE-2014-4268 [MEDIUM] GHSA-p388-pw52-w2mq: Unspecified vulnerability in Oracle Java SE 5
Unspecified vulnerability in Oracle Java SE 5.0u65, 6u75, 7u60, and 8u5 allows remote attackers to affect confidentiality via unknown vectors related to Swing.
OSV
openjdk-7 update
osv·2014-09-17·CVSS 9.3
CVE-2014-2483 [CRITICAL] openjdk-7 update
openjdk-7 update
USN-2319-1 fixed vulnerabilities in OpenJDK 7. This update provides
stability fixes for the arm64 and ppc64el architectures.
Original advisory details:
Several vulnerabilities were discovered in the OpenJDK JRE related to
information disclosure, data integrity and availability. An attacker could
exploit these to cause a denial of service or expose sensitive data over
the network. (CVE-2014-2483, CVE-2014-2490, CVE-2014-4216, CVE-2014-4219,
CVE-2014-4223, CVE-2014-4262)
Several vulnerabilities were discovered in the OpenJDK JRE related to
information disclosure and data integrity. An attacker could exploit these
to expose sensitive data over the network. (CVE-2014-4209, CVE-2014-4244,
CVE-2014-4263)
Two vulnerabilities were discovered in the OpenJDK JRE related to data
OSV
openjdk-7 regression
osv·2014-08-26·CVSS 9.3
[CRITICAL] openjdk-7 regression
openjdk-7 regression
USN-2319-1 fixed vulnerabilities in OpenJDK 7. Due to an upstream
regression, verifying of the init method call would fail when it was done
from inside a branch when stack frames are activated. This update fixes the
problem.
We apologize for the inconvenience.
Original advisory details:
Several vulnerabilities were discovered in the OpenJDK JRE related to
information disclosure, data integrity and availability. An attacker could
exploit these to cause a denial of service or expose sensitive data over
the network. (CVE-2014-2483, CVE-2014-2490, CVE-2014-4216, CVE-2014-4219,
CVE-2014-4223, CVE-2014-4262)
Several vulnerabilities were discovered in the OpenJDK JRE related to
information disclosure and data integrity. An attacker could exploit these
to expose sensitive
OSV
openjdk-7 vulnerabilities
osv·2014-08-20·CVSS 9.3
CVE-2014-2483 [CRITICAL] openjdk-7 vulnerabilities
openjdk-7 vulnerabilities
Several vulnerabilities were discovered in the OpenJDK JRE related to
information disclosure, data integrity and availability. An attacker could
exploit these to cause a denial of service or expose sensitive data over
the network. (CVE-2014-2483, CVE-2014-2490, CVE-2014-4216, CVE-2014-4219,
CVE-2014-4223, CVE-2014-4262)
Several vulnerabilities were discovered in the OpenJDK JRE related to
information disclosure and data integrity. An attacker could exploit these
to expose sensitive data over the network. (CVE-2014-4209, CVE-2014-4244,
CVE-2014-4263)
Two vulnerabilities were discovered in the OpenJDK JRE related to data
integrity. (CVE-2014-4218, CVE-2014-4266)
A vulnerability was discovered in the OpenJDK JRE related to availability.
An attacker could exploit
OSV
CVE-2014-4268: Unspecified vulnerability in Oracle Java SE 5
osv·2014-07-17·CVSS 5.0
CVE-2014-4268 [MEDIUM] CVE-2014-4268: Unspecified vulnerability in Oracle Java SE 5
Unspecified vulnerability in Oracle Java SE 5.0u65, 6u75, 7u60, and 8u5 allows remote attackers to affect confidentiality via unknown vectors related to Swing.
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-security-announce/2015-02/msg00026.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-02/msg00033.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-02/msg00036.htmlhttp://marc.info/?l=bugtraq&m=140852886808946&w=2http://marc.info/?l=bugtraq&m=140852974709252&w=2http://seclists.org/fulldisclosure/2014/Dec/23http://secunia.com/advisories/59404http://secunia.com/advisories/59680http://secunia.com/advisories/60081http://secunia.com/advisories/60129http://secunia.com/advisories/60317http://secunia.com/advisories/60485http://secunia.com/advisories/60622http://secunia.com/advisories/60812http://secunia.com/advisories/60817http://secunia.com/advisories/61577http://secunia.com/advisories/61640http://security.gentoo.org/glsa/glsa-201502-12.xmlhttp://www-01.ibm.com/support/docview.wss?uid=swg21680334http://www-01.ibm.com/support/docview.wss?uid=swg21686383http://www-01.ibm.com/support/docview.wss?uid=swg21686824http://www.debian.org/security/2014/dsa-2980http://www.debian.org/security/2014/dsa-2987http://www.oracle.com/technetwork/topics/security/cpujul2014-1972956.htmlhttp://www.securityfocus.com/archive/1/534161/100/0/threadedhttp://www.securityfocus.com/bid/68615http://www.securitytracker.com/id/1030577http://www.vmware.com/security/advisories/VMSA-2014-0012.htmlhttps://exchange.xforce.ibmcloud.com/vulnerabilities/94602http://lists.opensuse.org/opensuse-security-announce/2015-02/msg00026.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-02/msg00033.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-02/msg00036.htmlhttp://marc.info/?l=bugtraq&m=140852886808946&w=2http://marc.info/?l=bugtraq&m=140852974709252&w=2http://seclists.org/fulldisclosure/2014/Dec/23http://secunia.com/advisories/59404http://secunia.com/advisories/59680http://secunia.com/advisories/60081http://secunia.com/advisories/60129http://secunia.com/advisories/60317http://secunia.com/advisories/60485http://secunia.com/advisories/60622http://secunia.com/advisories/60812http://secunia.com/advisories/60817http://secunia.com/advisories/61577http://secunia.com/advisories/61640http://security.gentoo.org/glsa/glsa-201502-12.xmlhttp://www-01.ibm.com/support/docview.wss?uid=swg21680334http://www-01.ibm.com/support/docview.wss?uid=swg21686383http://www-01.ibm.com/support/docview.wss?uid=swg21686824http://www.debian.org/security/2014/dsa-2980http://www.debian.org/security/2014/dsa-2987http://www.oracle.com/technetwork/topics/security/cpujul2014-1972956.htmlhttp://www.securityfocus.com/archive/1/534161/100/0/threadedhttp://www.securityfocus.com/bid/68615http://www.securitytracker.com/id/1030577http://www.vmware.com/security/advisories/VMSA-2014-0012.htmlhttps://exchange.xforce.ibmcloud.com/vulnerabilities/94602
2014-07-17
Published