Oracle Jdk vulnerabilities
787 known vulnerabilities affecting oracle/jdk.
Total CVEs
787
CISA KEV
8
actively exploited
Public exploits
26
Exploited in wild
18
Severity breakdown
CRITICAL196HIGH121MEDIUM346LOW122
Vulnerabilities
Page 10 of 40
CVE-2013-5805P3CRITICALCVSS 9.3≤ 1.7.0v1.7.02013-10-16
CVE-2013-5805 [CRITICAL] CVE-2013-5805: Unspecified vulnerability in Oracle Java SE 7u40 and earlier and Java SE Embedded 7u40 and earlier a
Unspecified vulnerability in Oracle Java SE 7u40 and earlier and Java SE Embedded 7u40 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Swing, a different vulnerability than CVE-2013-5806.
nvd
CVE-2017-10107P3CRITICALCVSS 9.6v1.6.0v1.7.0+1 more2017-08-08
CVE-2017-10107 [CRITICAL] CVE-2017-10107: Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: RMI). Supp
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: RMI). Supported versions that are affected are Java SE: 6u151, 7u141 and 8u131; Java SE Embedded: 8u131. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful at
nvd
CVE-2017-10087P3CRITICALCVSS 9.6v1.6.0v1.7.0+1 more2017-08-08
CVE-2017-10087 [CRITICAL] CVE-2017-10087: Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Libraries)
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Libraries). Supported versions that are affected are Java SE: 6u151, 7u141 and 8u131; Java SE Embedded: 8u131. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Success
nvd
CVE-2017-10090P3CRITICALCVSS 9.6v1.7.0v1.8.02017-08-08
CVE-2017-10090 [CRITICAL] CVE-2017-10090: Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Libraries)
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Libraries). Supported versions that are affected are Java SE: 7u141 and 8u131; Java SE Embedded: 8u131. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful att
nvd
CVE-2017-10096P3CRITICALCVSS 9.6v1.6.0v1.7.0+1 more2017-08-08
CVE-2017-10096 [CRITICAL] CVE-2017-10096: Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: JAXP). Sup
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: JAXP). Supported versions that are affected are Java SE: 6u151, 7u141 and 8u131; Java SE Embedded: 8u131. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful a
nvd
CVE-2017-10101P3CRITICALCVSS 9.6v1.6.0v1.7.0+1 more2017-08-08
CVE-2017-10101 [CRITICAL] CVE-2017-10101: Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: JAXP). Sup
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: JAXP). Supported versions that are affected are Java SE: 6u151, 7u141 and 8u131; Java SE Embedded: 8u131. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful a
nvd
CVE-2017-3289P3CRITICALCVSS 9.6v1.7v1.82017-01-27
CVE-2017-3289 [CRITICAL] CVE-2017-3289: Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Hotspot).
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Hotspot). Supported versions that are affected are Java SE: 7u121 and 8u112; Java SE Embedded: 8u111. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks
nvd
CVE-2017-10110P3CRITICALCVSS 9.6v1.6.0v1.7.0+1 more2017-08-08
CVE-2017-10110 [CRITICAL] CVE-2017-10110: Vulnerability in the Java SE component of Oracle Java SE (subcomponent: AWT). Supported versions tha
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: AWT). Supported versions that are affected are Java SE: 6u151, 7u141 and 8u131. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks require human interaction from a person other than the
nvd
CVE-2017-10089P3CRITICALCVSS 9.6v1.6.0v1.7.0+1 more2017-08-08
CVE-2017-10089 [CRITICAL] CVE-2017-10089: Vulnerability in the Java SE component of Oracle Java SE (subcomponent: ImageIO). Supported versions
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: ImageIO). Supported versions that are affected are Java SE: 6u151, 7u141 and 8u131. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks require human interaction from a person other than
nvd
CVE-2016-0494P3CRITICALCVSS 10.0v1.6.0v1.7.0+1 more2016-01-21
CVE-2016-0494 [CRITICAL] CVE-2016-0494: Unspecified vulnerability in the Java SE and Java SE Embedded components in Oracle Java SE 6u105, 7u
Unspecified vulnerability in the Java SE and Java SE Embedded components in Oracle Java SE 6u105, 7u91, and 8u66 and Java SE Embedded 8u65 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D.
nvd
CVE-2014-0415P3CRITICALCVSS 10.0v1.6.02014-01-15
CVE-2014-0415 [CRITICAL] CVE-2014-0415: Unspecified vulnerability in Oracle Java SE 6u65 and 7u45 allows remote attackers to affect confiden
Unspecified vulnerability in Oracle Java SE 6u65 and 7u45 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment, a different vulnerability than CVE-2013-5889, CVE-2013-5902, CVE-2014-0410, CVE-2014-0418, and CVE-2014-0424.
nvd
CVE-2014-0410P3CRITICALCVSS 10.0v1.6.02014-01-15
CVE-2014-0410 [CRITICAL] CVE-2014-0410: Unspecified vulnerability in Oracle Java SE 6u65 and 7u45 allows remote attackers to affect confiden
Unspecified vulnerability in Oracle Java SE 6u65 and 7u45 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment, a different vulnerability than CVE-2013-5889, CVE-2013-5902, CVE-2014-0415, CVE-2014-0418, and CVE-2014-0424.
nvd
CVE-2015-4731P3CRITICALCVSS 10.0v1.6.0v1.7.0+1 more2015-07-16
CVE-2015-4731 [CRITICAL] CVE-2015-4731: Unspecified vulnerability in Oracle Java SE 6u95, 7u80, and 8u45; Java SE Embedded 7u75; and Java SE
Unspecified vulnerability in Oracle Java SE 6u95, 7u80, and 8u45; Java SE Embedded 7u75; and Java SE Embedded 8u33 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to JMX.
nvd
CVE-2014-6549P3CRITICALCVSS 10.0v1.8.02015-01-21
CVE-2014-6549 [CRITICAL] CVE-2014-6549: Unspecified vulnerability in Oracle Java SE 8u25 allows remote attackers to affect confidentiality,
Unspecified vulnerability in Oracle Java SE 8u25 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries.
nvd
CVE-2013-2421P3CRITICALCVSS 9.3≤ 1.7.0v1.7.02013-04-17
CVE-2013-2421 [CRITICAL] CVE-2013-2421: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, and OpenJDK 6 and 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to HotSpot. NOTE: the previous information is from the April 2013 CPU. Oracle has not commented on claims from ano
nvd
CVE-2013-5893P3CRITICALCVSS 9.3v1.7.02014-01-15
CVE-2013-5893 [CRITICAL] CVE-2013-5893: Unspecified vulnerability in Oracle Java SE 7u45 and Java SE Embedded 7u45, and OpenJDK 7, allows re
Unspecified vulnerability in Oracle Java SE 7u45 and Java SE Embedded 7u45, and OpenJDK 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries. NOTE: the previous information is from the January 2014 CPU. Oracle has not commented on third-party claims that the issue is related to improper h
nvd
CVE-2014-6456P3CRITICALCVSS 9.3v1.7.0v1.8.02014-10-15
CVE-2014-6456 [CRITICAL] CVE-2014-6456: Unspecified vulnerability in Oracle Java SE 7u67 and 8u20 allows remote attackers to affect confiden
Unspecified vulnerability in Oracle Java SE 7u67 and 8u20 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.
nvd
CVE-2015-0492P3CRITICALCVSS 9.3v1.5.0v1.6.0+2 more2015-04-16
CVE-2015-0492 [CRITICAL] CVE-2015-0492: Unspecified vulnerability in Oracle Java SE 7u76 and 8u40, and JavaFX 2.2.76, allows remote attacker
Unspecified vulnerability in Oracle Java SE 7u76 and 8u40, and JavaFX 2.2.76, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors, a different vulnerability than CVE-2015-0484.
nvd
CVE-2020-2803P3HIGHCVSS 8.3v1.7.0v1.8.0+2 more2020-04-15
CVE-2020-2803 [HIGH] CVE-2020-2803: Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Libraries). Sup
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 7u251, 8u241, 11.0.6 and 14; Java SE Embedded: 8u241. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful
nvd
CVE-2013-1478P3CRITICALCVSS 10.0v1.7.0v1.6.0+3 more2013-02-02
CVE-2013-1478 [CRITICAL] CVE-2013-1478: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 throug
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, 5.0 through Update 38, and 1.4.2_40 and earlier, and OpenJDK 6 and 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D. NOTE: the previous information is from th
nvd