Oracle Jdk vulnerabilities

778 known vulnerabilities affecting oracle/jdk.

Total CVEs
778
CISA KEV
8
actively exploited
Public exploits
25
Exploited in wild
10
Severity breakdown
CRITICAL196HIGH119MEDIUM343LOW118

Vulnerabilities

Page 36 of 39
CVE-2013-1479CRITICALCVSS 10.0v1.7.0v1.6.02013-02-02
CVE-2013-1479 [CRITICAL] CVE-2013-1479: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 throug Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, and JavaFX 2.2.4 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.
nvd
CVE-2013-0423HIGHCVSS 7.6v1.7.0v1.6.02013-02-02
CVE-2013-0423 [HIGH] CVE-2013-0423: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 throug Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11 and 6 through Update 38 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment, a different vulnerability than other CVEs listed in the February 2013 CPU.
nvd
CVE-2013-0419HIGHCVSS 7.6v1.7.0v1.6.02013-02-02
CVE-2013-0419 [HIGH] CVE-2013-0419: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 throug Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11 and 6 through Update 38 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment, a different vulnerability than other CVEs listed in the February 2013 CPU.
nvd
CVE-2013-0351HIGHCVSS 7.5v1.7.0v1.6.02013-02-02
CVE-2013-0351 [HIGH] CVE-2013-0351: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 throug Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11 and 6 through Update 38 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment, a different vulnerability than other CVEs listed in the February 2013 CPU.
nvd
CVE-2013-0429HIGHCVSS 7.6v1.7.0v1.6.0+1 more2013-02-02
CVE-2013-0429 [HIGH] CVE-2013-0429: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 throug Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, and 5.0 through Update 38, and OpenJDK 6 and 7, allows remote attackers to affect confidentiality, integrity, and availability via vectors related to CORBA. NOTE: the previous information is from the February 2013 CPU. Oracle has
nvd
CVE-2013-0444HIGHCVSS 7.6v1.7.02013-02-02
CVE-2013-0444 [HIGH] CVE-2013-0444: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 throug Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, and OpenJDK 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Beans. NOTE: the previous information is from the February 2013 CPU. Oracle has not commented on claims from another vendor t
nvd
CVE-2013-0432MEDIUMCVSS 6.4v1.7.0v1.6.0+3 more2013-02-02
CVE-2013-0432 [MEDIUM] CVE-2013-0432: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 throug Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, 5.0 through Update 38, and 1.4.2_40 and earlier, and OpenJDK 6 and 7, allows remote attackers to affect confidentiality and integrity via vectors related to AWT. NOTE: the previous information is from the February 2013 CPU. Ora
nvd
CVE-2013-0434MEDIUMCVSS 5.0v1.7.0v1.6.0+3 more2013-02-02
CVE-2013-0434 [MEDIUM] CVE-2013-0434: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 throug Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, 5.0 through Update 38, and 1.4.2_40 and earlier, and OpenJDK 6 and 7, allows remote attackers to affect confidentiality via vectors related to JAXP. NOTE: the previous information is from the February 2013 CPU. Oracle has not c
nvd
CVE-2013-1473MEDIUMCVSS 5.0v1.7.0v1.6.02013-02-02
CVE-2013-1473 [MEDIUM] CVE-2013-1473: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 throug Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11 and 6 through Update 38 allows remote attackers to affect integrity via unknown vectors related to Deployment.
nvd
CVE-2013-0440MEDIUMCVSS 5.0v1.7.0v1.6.0+3 more2013-02-02
CVE-2013-0440 [MEDIUM] CVE-2013-0440: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 throug Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, 5.0 through Update 38, and 1.4.2_40 and earlier, and OpenJDK 7, allows remote attackers to affect availability via vectors related to JSSE. NOTE: the previous information is from the February 2013 CPU. Oracle has not commented
nvd
CVE-2013-0430MEDIUMCVSS 6.9v1.7.0v1.6.02013-02-02
CVE-2013-0430 [MEDIUM] CVE-2013-0430: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 throug Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11 and 6 through Update 38, allows local users to affect confidentiality, integrity, and availability via unknown vectors related to the installation process of the client.
nvd
CVE-2013-0435MEDIUMCVSS 5.0v1.7.0v1.6.02013-02-02
CVE-2013-0435 [MEDIUM] CVE-2013-0435: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 throug Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11 and 6 through Update 38, and OpenJDK 6 and 7, allows remote attackers to affect confidentiality via vectors related to JAX-WS. NOTE: the previous information is from the February 2013 CPU. Oracle has not commented on claims from another vendor that
nvd
CVE-2013-0433MEDIUMCVSS 5.0v1.7.0v1.6.0+1 more2013-02-02
CVE-2013-0433 [MEDIUM] CVE-2013-0433: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 throug Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, and 5.0 through Update 38, and OpenJDK 6 and 7, allows remote attackers to affect integrity via unknown vectors related to Networking. NOTE: the previous information is from the February 2013 CPU. Oracle has not commented on cl
nvd
CVE-2013-0409MEDIUMCVSS 5.0v1.7.0v1.6.0+1 more2013-02-02
CVE-2013-0409 [MEDIUM] CVE-2013-0409: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 throug Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, and 5.0 through Update 38 allows remote attackers to affect confidentiality via vectors related to JMX.
nvd
CVE-2013-0427MEDIUMCVSS 5.0v1.7.0v1.6.0+1 more2013-02-02
CVE-2013-0427 [MEDIUM] CVE-2013-0427: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 throug Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, and 5.0 through Update 38, and OpenJDK 6 and 7, allows remote attackers to affect integrity via unknown vectors related to Libraries. NOTE: the previous information is from the February 2013 CPU. Oracle has not commented on cla
nvd
CVE-2013-0449MEDIUMCVSS 5.0v1.7.02013-02-02
CVE-2013-0449 [MEDIUM] CVE-2013-0449: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 throug Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11 allows remote attackers to affect confidentiality via unknown vectors related to Deployment.
nvd
CVE-2013-0443MEDIUMCVSS 4.0v1.7.0v1.6.0+3 more2013-02-02
CVE-2013-0443 [MEDIUM] CVE-2013-0443: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 throug Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, 5.0 through Update 38, and 1.4.2_40 and earlier, and OpenJDK 6 and 7, allows remote attackers to affect confidentiality and integrity via vectors related to JSSE. NOTE: the previous information is from the February 2013 CPU. Or
nvd
CVE-2013-0438MEDIUMCVSS 4.3v1.7.0v1.6.02013-02-02
CVE-2013-0438 [MEDIUM] CVE-2013-0438: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 throug Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11 and 6 through Update 38 allows remote attackers to affect confidentiality via unknown vectors related to Deployment.
nvd
CVE-2013-0424MEDIUMCVSS 5.0v1.7.0v1.6.0+3 more2013-02-02
CVE-2013-0424 [MEDIUM] CVE-2013-0424: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 throug Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, 5.0 through Update 38, and 1.4.2_40 and earlier, and OpenJDK 7, allows remote attackers to affect integrity via vectors related to RMI. NOTE: the previous information is from the February 2013 CPU. Oracle has not commented on c
nvd
CVE-2013-0448MEDIUMCVSS 5.0v1.7.02013-02-02
CVE-2013-0448 [MEDIUM] CVE-2013-0448: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 throug Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11 allows remote attackers to affect integrity via unknown vectors related to Libraries.
nvd
Oracle Jdk vulnerabilities | cvebase