cbcvebase.

Debian Openjdk-8 vulnerabilities

333 known vulnerabilities affecting debian/openjdk-8.

Total CVEs
333
CISA KEV
2
actively exploited
Public exploits
7
Exploited in wild
3
Severity breakdown
CRITICAL46HIGH45MEDIUM166LOW76

Vulnerabilities

Page 1 of 17
CVE-2016-3427P1CRITICALCVSS 9.8KEVPoCfixed in openjdk-8 8u91-b14-1 (sid)2016
CVE-2016-3427 [CRITICAL] CVE-2016-3427: openjdk-8 - Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embed... Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to JMX. Scope: local sid: resolved (fixed in 8u91-b14-1)
debian
CVE-2015-2590P1CRITICALCVSS 9.8KEVfixed in openjdk-8 8u66-b01-1 (sid)2015
CVE-2015-2590 [CRITICAL] CVE-2015-2590: openjdk-8 - Unspecified vulnerability in Oracle Java SE 6u95, 7u80, and 8u45, and Java SE Em... Unspecified vulnerability in Oracle Java SE 6u95, 7u80, and 8u45, and Java SE Embedded 7u75 and 8u33 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries, a different vulnerability than CVE-2015-4732. Scope: local sid: resolved (fixed in 8u66-b01-1)
debian
CVE-2017-3241P2CRITICALCVSS 9.0PoCfixed in openjdk-8 8u121-b13-1 (sid)2017
CVE-2017-3241 [CRITICAL] CVE-2017-3241: openjdk-8 - Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java... Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: RMI). Supported versions that are affected are Java SE: 6u131, 7u121 and 8u112; Java SE Embedded: 8u111; JRockit: R28.3.12. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE
debian
CVE-2019-2698P2LOWCVSS 8.1PoCfixed in openjdk-11 11.0.3+7-1 (bullseye)2019
CVE-2019-2698 [HIGH] CVE-2019-2698: openjdk-11 - Vulnerability in the Java SE component of Oracle Java SE (subcomponent: 2D). Sup... Vulnerability in the Java SE component of Oracle Java SE (subcomponent: 2D). Supported versions that are affected are Java SE: 7u211 and 8u202. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks of this vulnerability can result in takeover of Java SE. Note: This vul
debian
CVE-2017-10176P3HIGHCVSS 7.5Exploitedfixed in openjdk-8 8u141-b15-1 (sid)2017
CVE-2017-10176 [HIGH] CVE-2017-10176: openjdk-8 - Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java... Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Security). Supported versions that are affected are Java SE: 7u141 and 8u131; Java SE Embedded: 8u131; JRockit: R28.3.14. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedd
debian
CVE-2015-4000P3LOWCVSS 3.7PoCfixed in nss 2:3.19.1-1 (bookworm)2015
CVE-2015-4000 [LOW] CVE-2015-4000: nss - The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a ... The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a server but not on a client, does not properly convey a DHE_EXPORT choice, which allows man-in-the-middle attackers to conduct cipher-downgrade attacks by rewriting a ClientHello with DHE replaced by DHE_EXPORT and then rewriting a ServerHello with DHE_EXPORT replaced by DHE, aka the "Logjam" is
debian
CVE-2014-6593P3MEDIUMCVSS 4.0PoCfixed in openjdk-8 8u40~b22-1 (sid)2014
CVE-2014-6593 [MEDIUM] CVE-2014-6593: openjdk-8 - Unspecified vulnerability in Oracle Java SE 5.0u75, 6u85, 7u72, and 8u25; Java S... Unspecified vulnerability in Oracle Java SE 5.0u75, 6u85, 7u72, and 8u25; Java SE Embedded 7u71 and 8u6; and JRockit 27.8.4 and 28.3.4 allows remote attackers to affect confidentiality and integrity via vectors related to JSSE. Scope: local sid: resolved (fixed in 8u40~b22-1)
debian
CVE-2014-3566P3LOWCVSS 3.4PoCfixed in erlang 1:17.3-dfsg-3 (bookworm)2014
CVE-2014-3566 [LOW] CVE-2014-3566: bouncycastle - The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other products, uses... The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other products, uses nondeterministic CBC padding, which makes it easier for man-in-the-middle attackers to obtain cleartext data via a padding-oracle attack, aka the "POODLE" issue. Scope: local bookworm: resolved bullseye: resolved forky: resolved sid: resolved trixie: resolved
debian
CVE-2022-34169P2HIGHCVSS 7.5fixed in bcel 6.5.0-2 (bookworm)2022
CVE-2022-34169 [HIGH] CVE-2022-34169: bcel - The Apache Xalan Java XSLT library is vulnerable to an integer truncation issue ... The Apache Xalan Java XSLT library is vulnerable to an integer truncation issue when processing malicious XSLT stylesheets. This can be used to corrupt Java class files generated by the internal XSLTC compiler and execute arbitrary Java bytecode. Users are recommended to update to version 2.7.3 or later. Note: Java runtimes (such as OpenJDK) include repackaged copies o
debian
CVE-2015-4748P2HIGHCVSS 7.6fixed in openjdk-8 8u66-b01-1 (sid)2015
CVE-2015-4748 [HIGH] CVE-2015-4748: openjdk-8 - Unspecified vulnerability in Oracle Java SE 6u95, 7u80, and 8u45; JRockit R28.3.... Unspecified vulnerability in Oracle Java SE 6u95, 7u80, and 8u45; JRockit R28.3.6; and Java SE Embedded 7u75 and Embedded 8u33 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Security. Scope: local sid: resolved (fixed in 8u66-b01-1)
debian
CVE-2017-10355P3MEDIUMCVSS 5.3PoCfixed in openjdk-8 8u151-b12-1 (sid)2017
CVE-2017-10355 [MEDIUM] CVE-2017-10355: openjdk-8 - Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java... Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Networking). Supported versions that are affected are Java SE: 6u161, 7u151, 8u144 and 9; Java SE Embedded: 8u144; JRockit: R28.3.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE,
debian
CVE-2016-0483P3CRITICALCVSS 10.0fixed in openjdk-8 8u72-b15-1 (sid)2016
CVE-2016-0483 [CRITICAL] CVE-2016-0483: openjdk-8 - Unspecified vulnerability in Oracle Java SE 6u105, 7u91, and 8u66; Java SE Embed... Unspecified vulnerability in Oracle Java SE 6u105, 7u91, and 8u66; Java SE Embedded 8u65; and JRockit R28.3.8 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to AWT. NOTE: the previous information is from the January 2016 CPU. Oracle has not commented on third-party claims that this is a heap-based buffer overfl
debian
CVE-2015-4843P3CRITICALCVSS 10.0fixed in openjdk-8 8u66-b17-1 (sid)2015
CVE-2015-4843 [CRITICAL] CVE-2015-4843: openjdk-8 - Unspecified vulnerability in Oracle Java SE 6u101, 7u85, and 8u60, and Java SE E... Unspecified vulnerability in Oracle Java SE 6u101, 7u85, and 8u60, and Java SE Embedded 8u51, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries. Scope: local sid: resolved (fixed in 8u66-b17-1)
debian
CVE-2015-4844P3CRITICALCVSS 10.0fixed in icu 57.1-1.1 (bookworm)2015
CVE-2015-4844 [CRITICAL] CVE-2015-4844: icu - Unspecified vulnerability in Oracle Java SE 6u101, 7u85, and 8u60, and Java SE E... Unspecified vulnerability in Oracle Java SE 6u101, 7u85, and 8u60, and Java SE Embedded 8u51, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D. Scope: local bookworm: resolved (fixed in 57.1-1.1) bullseye: resolved (fixed in 57.1-1.1) forky: resolved (fixed in 57.1-1.1) sid: resolved (fixed in 57.1-1.1) t
debian
CVE-2015-4805P3CRITICALCVSS 10.0fixed in openjdk-8 8u66-b17-1 (sid)2015
CVE-2015-4805 [CRITICAL] CVE-2015-4805: openjdk-8 - Unspecified vulnerability in Oracle Java SE 6u101, 7u85, and 8u60, and Java SE E... Unspecified vulnerability in Oracle Java SE 6u101, 7u85, and 8u60, and Java SE Embedded 8u51, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Serialization. Scope: local sid: resolved (fixed in 8u66-b17-1)
debian
CVE-2016-3598P3CRITICALCVSS 9.6fixed in openjdk-8 8u102-b14-1 (sid)2016
CVE-2016-3598 [CRITICAL] CVE-2016-3598: openjdk-8 - Unspecified vulnerability in Oracle Java SE 8u92 and Java SE Embedded 8u91 allow... Unspecified vulnerability in Oracle Java SE 8u92 and Java SE Embedded 8u91 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Libraries, a different vulnerability than CVE-2016-3610. Scope: local sid: resolved (fixed in 8u102-b14-1)
debian
CVE-2015-0408P3CRITICALCVSS 10.0fixed in openjdk-8 8u40~b22-1 (sid)2015
CVE-2015-0408 [CRITICAL] CVE-2015-0408: openjdk-8 - Unspecified vulnerability in Oracle Java SE 5.0u75, 6u85, 7u72, and 8u25 allows ... Unspecified vulnerability in Oracle Java SE 5.0u75, 6u85, 7u72, and 8u25 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to RMI. Scope: local sid: resolved (fixed in 8u40~b22-1)
debian
CVE-2016-0687P3CRITICALCVSS 9.6fixed in openjdk-8 8u91-b14-1 (sid)2016
CVE-2016-0687 [CRITICAL] CVE-2016-0687: openjdk-8 - Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77 and Java SE Em... Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77 and Java SE Embedded 8u77 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to the Hotspot sub-component. Scope: local sid: resolved (fixed in 8u91-b14-1)
debian
CVE-2016-0686P3CRITICALCVSS 9.6fixed in openjdk-8 8u91-b14-1 (sid)2016
CVE-2016-0686 [CRITICAL] CVE-2016-0686: openjdk-8 - Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77 and Java SE Em... Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77 and Java SE Embedded 8u77 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Serialization. Scope: local sid: resolved (fixed in 8u91-b14-1)
debian
CVE-2015-4835P3CRITICALCVSS 10.0fixed in openjdk-8 8u66-b17-1 (sid)2015
CVE-2015-4835 [CRITICAL] CVE-2015-4835: openjdk-8 - Unspecified vulnerability in Oracle Java SE 6u101, 7u85, and 8u60, and Java SE E... Unspecified vulnerability in Oracle Java SE 6u101, 7u85, and 8u60, and Java SE Embedded 8u51, allows remote attackers to affect confidentiality, integrity, and availability via vectors related to CORBA, a different vulnerability than CVE-2015-4881. Scope: local sid: resolved (fixed in 8u66-b17-1)
debian
1 / 17Next →
Debian Openjdk-8 vulnerabilities | cvebase