cbcvebase.

Ibm Java vulnerabilities

28 known vulnerabilities affecting ibm/java.

Total CVEs
28
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL16HIGH4MEDIUM7LOW1

Vulnerabilities

Page 2 of 2
CVE-2013-0485P4CRITICALCVSS 10.0v1.4.2v5.0.0.0+2 more2014-01-21
CVE-2013-0485 [CRITICAL] CVE-2013-0485: Unspecified vulnerability in IBM Java SDK 7 before SR4-FP1, 6 before SR13-FP1, 5.0 before SR16-FP1, Unspecified vulnerability in IBM Java SDK 7 before SR4-FP1, 6 before SR13-FP1, 5.0 before SR16-FP1, and 1.4.2 before SR13-FP16 has unknown impact and attack vectors related to Class Libraries.
nvd
CVE-2013-4041P4MEDIUMCVSS 6.8v5.0.0.0v6.0.0.0+2 more2013-11-24
CVE-2013-4041 [MEDIUM] CVE-2013-4041: Unspecified vulnerability in IBM Java SDK 5.0.0 before SR16 FP4, 7.0.0 before SR6, 6.0.1 before SR7, Unspecified vulnerability in IBM Java SDK 5.0.0 before SR16 FP4, 7.0.0 before SR6, 6.0.1 before SR7, and 6.0.0 before SR15 allows remote attackers to access restricted classes via unspecified vectors.
nvd
CVE-2014-3068P4MEDIUMCVSS 6.4v5.0.0.0v5.0.11.0+44 more2014-12-02
CVE-2014-3068 [MEDIUM] CWE-255 CVE-2014-3068: IBM Java Runtime Environment (JRE) 7 R1 before SR1 FP1 (7.1.1.1), 7 before SR7 FP1 (7.0.7.1), 6 R1 b IBM Java Runtime Environment (JRE) 7 R1 before SR1 FP1 (7.1.1.1), 7 before SR7 FP1 (7.0.7.1), 6 R1 before SR8 FP1 (6.1.8.1), 6 before SR16 FP1 (6.0.16.1), and before 5.0 SR16 FP7 (5.0.16.7) allows attackers to obtain the private key from a Certificate Management System (CMS) keystore via a brute force attack.
nvd
CVE-2019-4732P4MEDIUMCVSS 6.5v7.0.0.0v7.1.0.0+4 more2020-02-03
CVE-2019-4732 [MEDIUM] CWE-426 CVE-2019-4732: IBM SDK, Java Technology Edition Version 7.0.0.0 through 7.0.10.55, 7.1.0.0 through 7.1.4.55, and 8. IBM SDK, Java Technology Edition Version 7.0.0.0 through 7.0.10.55, 7.1.0.0 through 7.1.4.55, and 8.0.0.0 through 8.0.6.0 could allow a local authenticated attacker to execute arbitrary code on the system, caused by DLL search order hijacking vulnerability in Microsoft Windows client. By placing a specially-crafted file in a compromised folder, an att
nvd
CVE-2015-1914P4MEDIUMCVSS 5.0≥ 5.0.0.0, < 5.0.16.10≥ 6.0.0.0, < 6.0.16.4+3 more2015-07-02
CVE-2015-1914 [MEDIUM] CWE-200 CVE-2015-1914: IBM Java 7 R1 before SR3, 7 before SR9, 6 R1 before SR8 FP4, 6 before SR16 FP4, and 5.0 before SR16 IBM Java 7 R1 before SR3, 7 before SR9, 6 R1 before SR8 FP4, 6 before SR16 FP4, and 5.0 before SR16 FP10 allows remote attackers to bypass "permission checks" and obtain sensitive information via vectors related to the Java Virtual Machine.
nvd
CVE-2014-3065P4MEDIUMCVSS 6.9v5.0.0.0v5.0.11.0+44 more2014-12-02
CVE-2014-3065 [MEDIUM] CWE-94 CVE-2014-3065: Unspecified vulnerability in IBM Java Runtime Environment (JRE) 7 R1 before SR2 (7.1.2.0), 7 before Unspecified vulnerability in IBM Java Runtime Environment (JRE) 7 R1 before SR2 (7.1.2.0), 7 before SR8 (7.0.8.0), 6 R1 before SR8 FP2 (6.1.8.2), 6 before SR16 FP2 (6.0.16.2), and before SR16 FP8 (5.0.16.8) allows local users to execute arbitrary code via vectors related to the shared classes cache.
nvd
CVE-2011-3387P4MEDIUMCVSS 4.0v1.4.2.13.92011-09-02
CVE-2011-3387 [MEDIUM] CVE-2011-3387: The class file parser in IBM Java 1.4.2 SR13 FP9 allows remote authenticated users to cause a denial The class file parser in IBM Java 1.4.2 SR13 FP9 allows remote authenticated users to cause a denial of service (memory consumption or an infinite loop) via a crafted attribute length field in a class file, related to validation of a length field at the wrong time, a different vulnerability than CVE-2011-0311.
nvd
CVE-2011-0311P4LOWCVSS 3.5≤ 1.4.2.13.8v1.4.2+8 more2011-09-02
CVE-2011-0311 [LOW] CWE-119 CVE-2011-0311: The class file parser in IBM Java before 1.4.2 SR13 FP9, as used in IBM Runtimes for Java Technology The class file parser in IBM Java before 1.4.2 SR13 FP9, as used in IBM Runtimes for Java Technology 5.0.0 before SR13 and 6.0.0 before SR10, allows remote authenticated users to cause a denial of service (JVM segmentation fault, and possibly memory consumption or an infinite loop) via a crafted attribute length field in a class file, which triggers a bu
nvd
Ibm Java vulnerabilities | cvebase