Debian Openjdk-8 vulnerabilities
333 known vulnerabilities affecting debian/openjdk-8.
Total CVEs
333
CISA KEV
2
actively exploited
Public exploits
7
Exploited in wild
3
Severity breakdown
CRITICAL46HIGH45MEDIUM166LOW76
Vulnerabilities
Page 9 of 17
CVE-2022-21305P4MEDIUMCVSS 5.3fixed in openjdk-11 11.0.14+9-1~deb11u1 (bullseye)2022
CVE-2022-21305 [MEDIUM] CVE-2022-21305: openjdk-11 - Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product o...
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 7u321, 8u311, 11.0.13, 17.0.1; Oracle GraalVM Enterprise Edition: 20.3.4 and 21.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple prot
debian
CVE-2026-21933P4MEDIUMCVSS 6.1fixed in openjdk-11 11.0.30+7-1~deb11u1 (bullseye)2026
CVE-2026-21933 [MEDIUM] CVE-2026-21933: openjdk-11 - Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Ente...
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Networking). Supported versions that are affected are Oracle Java SE: 8u471, 8u471-b50, 8u471-perf, 11.0.29, 17.0.17, 21.0.9, 25.0.1; Oracle GraalVM for JDK: 17.0.17 and 21.0.9; Oracle GraalVM Enterprise Edition: 21.3.16. Easily e
debian
CVE-2014-6468P4MEDIUMCVSS 6.8fixed in openjdk-8 8u40~b09-1 (sid)2014
CVE-2014-6468 [MEDIUM] CVE-2014-6468: openjdk-8 - Unspecified vulnerability in Oracle Java SE 8u20 allows local users to affect co...
Unspecified vulnerability in Oracle Java SE 8u20 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Hotspot.
Scope: local
sid: resolved (fixed in 8u40~b09-1)
debian
CVE-2018-2815P4MEDIUMCVSS 5.3fixed in openjdk-8 8u171-b11-1 (sid)2018
CVE-2018-2815 [MEDIUM] CVE-2018-2815: openjdk-8 - Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java...
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Serialization). Supported versions that are affected are Java SE: 6u181, 7u171, 8u162 and 10; Java SE Embedded: 8u161; JRockit: R28.3.17. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE
debian
CVE-2015-7575P4MEDIUMCVSS 5.9fixed in gnutls28 3.3.15-1 (bookworm)2015
CVE-2015-7575 [MEDIUM] CVE-2015-7575: gnutls28 - Mozilla Network Security Services (NSS) before 3.20.2, as used in Mozilla Firefo...
Mozilla Network Security Services (NSS) before 3.20.2, as used in Mozilla Firefox before 43.0.2 and Firefox ESR 38.x before 38.5.2, does not reject MD5 signatures in Server Key Exchange messages in TLS 1.2 Handshake Protocol traffic, which makes it easier for man-in-the-middle attackers to spoof servers by triggering a collision.
Scope: local
bookworm: resolved (fi
debian
CVE-2022-21360P4MEDIUMCVSS 5.3fixed in openjdk-11 11.0.14+9-1~deb11u1 (bullseye)2022
CVE-2022-21360 [MEDIUM] CVE-2022-21360: openjdk-11 - Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product o...
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: ImageIO). Supported versions that are affected are Oracle Java SE: 7u321, 8u311, 11.0.13, 17.0.1; Oracle GraalVM Enterprise Edition: 20.3.4 and 21.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple prot
debian
CVE-2022-21365P4MEDIUMCVSS 5.3fixed in openjdk-11 11.0.14+9-1~deb11u1 (bullseye)2022
CVE-2022-21365 [MEDIUM] CVE-2022-21365: openjdk-11 - Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product o...
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: ImageIO). Supported versions that are affected are Oracle Java SE: 7u321, 8u311, 11.0.13, 17.0.1; Oracle GraalVM Enterprise Edition: 20.3.4 and 21.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple prot
debian
CVE-2022-21299P4MEDIUMCVSS 5.3fixed in openjdk-11 11.0.14+9-1~deb11u1 (bullseye)2022
CVE-2022-21299 [MEDIUM] CVE-2022-21299: openjdk-11 - Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product o...
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JAXP). Supported versions that are affected are Oracle Java SE: 7u321, 8u311, 11.0.13, 17.0.1; Oracle GraalVM Enterprise Edition: 20.3.4 and 21.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protoco
debian
CVE-2022-21294P4MEDIUMCVSS 5.3fixed in openjdk-11 11.0.14+9-1~deb11u1 (bullseye)2022
CVE-2022-21294 [MEDIUM] CVE-2022-21294: openjdk-11 - Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product o...
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Oracle Java SE: 7u321, 8u311, 11.0.13, 17.0.1; Oracle GraalVM Enterprise Edition: 20.3.4 and 21.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple pr
debian
CVE-2022-21426P4MEDIUMCVSS 5.3fixed in openjdk-11 11.0.15+10-1~deb11u1 (bullseye)2022
CVE-2022-21426 [MEDIUM] CVE-2022-21426: openjdk-11 - Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product o...
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JAXP). Supported versions that are affected are Oracle Java SE: 7u331, 8u321, 11.0.14, 17.0.2, 18; Oracle GraalVM Enterprise Edition: 20.3.5, 21.3.1 and 22.0.0.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via mu
debian
CVE-2017-3252P4MEDIUMCVSS 5.8fixed in openjdk-8 8u121-b13-1 (sid)2017
CVE-2017-3252 [MEDIUM] CVE-2017-3252: openjdk-8 - Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java...
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: JAAS). Supported versions that are affected are Java SE: 6u131, 7u121 and 8u112; Java SE Embedded: 8u111; JRockit: R28.3.12. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise Java SE, Java SE Em
debian
CVE-2020-14803P4MEDIUMCVSS 5.3fixed in openjdk-11 11.0.9+11-1 (bullseye)2020
CVE-2020-14803 [MEDIUM] CVE-2020-14803: openjdk-11 - Vulnerability in the Java SE product of Oracle Java SE (component: Libraries). S...
Vulnerability in the Java SE product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 11.0.8 and 15. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks of this vulnerability can result in unauthorized read access to a sub
debian
CVE-2023-21967P4MEDIUMCVSS 5.9fixed in openjdk-11 11.0.20+8-1~deb11u1 (bullseye)2023
CVE-2023-21967 [MEDIUM] CVE-2023-21967: openjdk-11 - Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product o...
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JSSE). Supported versions that are affected are Oracle Java SE: 8u361, 8u361-perf, 11.0.18, 17.0.6, 20; Oracle GraalVM Enterprise Edition: 20.3.9, 21.3.5 and 22.3.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access v
debian
CVE-2022-21496P4MEDIUMCVSS 5.3fixed in openjdk-11 11.0.15+10-1~deb11u1 (bullseye)2022
CVE-2022-21496 [MEDIUM] CVE-2022-21496: openjdk-11 - Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product o...
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JNDI). Supported versions that are affected are Oracle Java SE: 7u331, 8u321, 11.0.14, 17.0.2, 18; Oracle GraalVM Enterprise Edition: 20.3.5, 21.3.1 and 22.0.0.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via mu
debian
CVE-2016-5552P4MEDIUMCVSS 5.3fixed in openjdk-8 8u121-b13-1 (sid)2016
CVE-2016-5552 [MEDIUM] CVE-2016-5552: openjdk-8 - Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java...
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Networking). Supported versions that are affected are Java SE: 6u131, 7u121 and 8u112; Java SE Embedded: 8u111; JRockit: R28.3.12. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java
debian
CVE-2022-21434P4MEDIUMCVSS 5.3fixed in openjdk-11 11.0.15+10-1~deb11u1 (bullseye)2022
CVE-2022-21434 [MEDIUM] CVE-2022-21434: openjdk-11 - Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product o...
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Oracle Java SE: 7u331, 8u321, 11.0.14, 17.0.2, 18; Oracle GraalVM Enterprise Edition: 20.3.5, 21.3.1 and 22.0.0.2. Easily exploitable vulnerability allows unauthenticated attacker with network access v
debian
CVE-2023-21939P4MEDIUMCVSS 5.3fixed in openjdk-11 11.0.20+8-1~deb11u1 (bullseye)2023
CVE-2023-21939 [MEDIUM] CVE-2023-21939: openjdk-11 - Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product o...
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Swing). Supported versions that are affected are Oracle Java SE: 8u361, 8u361-perf, 11.0.18, 17.0.6, 20; Oracle GraalVM Enterprise Edition: 20.3.9, 21.3.5 and 22.3.1. Easily exploitable vulnerability allows unauthenticated attacker with network access vi
debian
CVE-2016-0466P4MEDIUMCVSS 5.0fixed in openjdk-8 8u72-b15-1 (sid)2016
CVE-2016-0466 [MEDIUM] CVE-2016-0466: openjdk-8 - Unspecified vulnerability in the Java SE, Java SE Embedded, and JRockit componen...
Unspecified vulnerability in the Java SE, Java SE Embedded, and JRockit components in Oracle Java SE 6u105, 7u91, and 8u66; Java SE Embedded 8u65; and JRockit R28.3.8 allows remote attackers to affect availability via vectors related to JAXP.
Scope: local
sid: resolved (fixed in 8u72-b15-1)
debian
CVE-2019-2762P4MEDIUMCVSS 5.3fixed in openjdk-11 11.0.4+11-1 (bullseye)2019
CVE-2019-2762 [MEDIUM] CVE-2019-2762: openjdk-11 - Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subc...
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Utilities). Supported versions that are affected are Java SE: 7u221, 8u212, 11.0.3 and 12.0.1; Java SE Embedded: 8u211. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Succes
debian
CVE-2019-2769P4MEDIUMCVSS 5.3fixed in openjdk-11 11.0.4+11-1 (bullseye)2019
CVE-2019-2769 [MEDIUM] CVE-2019-2769: openjdk-11 - Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subc...
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Utilities). Supported versions that are affected are Java SE: 7u221, 8u212, 11.0.3 and 12.0.1; Java SE Embedded: 8u211. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Succes
debian