Oracle Jdk vulnerabilities

778 known vulnerabilities affecting oracle/jdk.

Total CVEs
778
CISA KEV
8
actively exploited
Public exploits
25
Exploited in wild
10
Severity breakdown
CRITICAL196HIGH119MEDIUM343LOW118

Vulnerabilities

Page 39 of 39
CVE-2012-1713CRITICALCVSS 10.0≤ 1.7.0≤ 1.6.02012-06-16
CVE-2012-1713 [CRITICAL] CVE-2012-1713: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update 4 and earlier, 6 update 32 and earlier, 5 update 35 and earlier, 1.4.2_37 and earlier, and JavaFX 2.1 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D.
nvd
CVE-2012-1716CRITICALCVSS 10.0≤ 1.7.0v1.7.0+2 more2012-06-16
CVE-2012-1716 [CRITICAL] CVE-2012-1716: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update 4 and earlier, 6 update 32 and earlier, and 5 update 35 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Swing.
nvd
CVE-2012-1711HIGHCVSS 7.5≤ 1.7.0≤ 1.6.02012-06-16
CVE-2012-1711 [HIGH] CVE-2012-1711: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update 4 and earlier, 6 update 32 and earlier, 5 update 35 and earlier, and 1.4.2_37 and earlier allows remote attackers to affect confidentiality, integrity, and availability, related to CORBA.
nvd
CVE-2012-1718MEDIUMCVSS 5.0≤ 1.7.0≤ 1.6.02012-06-16
CVE-2012-1718 [MEDIUM] CVE-2012-1718: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update 4 and earlier, 6 update 32 and earlier, 5 update 35 and earlier, and 1.4.2_37 and earlier allows remote attackers to affect availability via unknown vectors related to Security.
nvd
CVE-2012-1719MEDIUMCVSS 5.0≤ 1.7.0v1.7.0+2 more2012-06-16
CVE-2012-1719 [MEDIUM] CVE-2012-1719: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update 4 and earlier, 6 update 32 and earlier, 5 update 35 and earlier, and 1.4.2_37 and earlier allows remote attackers to affect integrity, related to CORBA.
nvd
CVE-2012-1726MEDIUMCVSS 6.4≤ 1.7.0v1.7.02012-06-16
CVE-2012-1726 [MEDIUM] CVE-2012-1726: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update 4 and earlier allows remote attackers to affect confidentiality and integrity via unknown vectors related to Libraries.
nvd
CVE-2012-1724MEDIUMCVSS 5.0≤ 1.7.0v1.7.0+2 more2012-06-16
CVE-2012-1724 [MEDIUM] CVE-2012-1724: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update 4 and earlier, and 6 update 32 and earlier, allows remote attackers to affect availability, related to JAXP.
nvd
CVE-2012-1720LOWCVSS 3.7≤ 1.7.0≤ 1.6.02012-06-16
CVE-2012-1720 [LOW] CVE-2012-1720: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update 4 and earlier, 6 update 32 and earlier, 5 update 35 and earlier, and 1.4.2_37 and earlier, when running on Solaris, allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Networking.
nvd
CVE-2012-1717LOWCVSS 2.1≥ 1.4.2, ≤ 1.4.2_37v1.5.0+2 more2012-06-16
CVE-2012-1717 [LOW] CVE-2012-1717: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update 4 and earlier, 6 update 32 and earlier, 5 update 35 and earlier, and 1.4.2_37 and earlier allows local users to affect confidentiality via unknown vectors related to printing on Solaris or Linux.
nvd
CVE-2012-0551MEDIUMCVSS 5.8PoC≤ 1.6.0v1.6.0+2 more2012-05-03
CVE-2012-0551 [MEDIUM] CVE-2012-0551: Unspecified vulnerability in the Java Runtime Environment (JRE) in Oracle Java SE 7 update 4 and ear Unspecified vulnerability in the Java Runtime Environment (JRE) in Oracle Java SE 7 update 4 and earlier and 6 update 32 and earlier, and the GlassFish Enterprise Server component in Oracle Sun Products Suite GlassFish Enterprise Server 3.1.1, allows remote attackers to affect confidentiality and integrity via unknown vectors related to Web Container or Deplo
nvd
CVE-2012-0504CRITICALCVSS 9.3≤ 1.7.0v1.7.0+2 more2012-02-15
CVE-2012-0504 [CRITICAL] CVE-2012-0504: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, and 6 Update 30 and earlier, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Install and the Java Update mechanism.
nvd
CVE-2011-3544CRITICALCVSS 9.8KEVPoCfixed in 1.6.0v1.6.0+1 more2011-10-19
CVE-2011-3544 [CRITICAL] CWE-284 CVE-2011-3544: Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7 Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7 and 6 Update 27 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality, integrity, and availability via unknown vectors related to Scripting.
nvd
CVE-2011-3547MEDIUMCVSS 5.0≤ 1.6.0v1.6.0+1 more2011-10-19
CVE-2011-3547 [MEDIUM] CVE-2011-3547: Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7, Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7, 6 Update 27 and earlier, 5.0 Update 31 and earlier, and 1.4.2_33 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality via unknown vectors related to Networking.
nvd
CVE-2011-3546MEDIUMCVSS 5.8v1.7.0≤ 1.6.0+1 more2011-10-19
CVE-2011-3546 [MEDIUM] CVE-2011-3546: Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7, Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7, 6 Update 27 and earlier, and JavaFX 2.0 allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality and integrity via unknown vectors related to Deployment.
nvd
CVE-2011-3561LOWCVSS 1.8≤ 1.6.0v1.6.02011-10-19
CVE-2011-3561 [LOW] CVE-2011-3561: Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7, Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7, 6 Update 27 and earlier, and JavaFX 2.0 allows remote attackers to affect confidentiality via unknown vectors related to Deployment.
nvd
CVE-2010-1423CRITICALCVSS 9.3PoC≤ 1.6.0v1.6.02010-04-15
CVE-2010-1423 [CRITICAL] CWE-78 CVE-2010-1423: Argument injection vulnerability in the URI handler in (a) Java NPAPI plugin and (b) Java Deployment Argument injection vulnerability in the URI handler in (a) Java NPAPI plugin and (b) Java Deployment Toolkit in Java 6 Update 10, 19, and other versions, when running on Windows and possibly on Linux, allows remote attackers to execute arbitrary code via the (1) -J or (2) -XXaltjvm argument to javaws.exe, which is processed by the launch method. NOTE
nvd
CVE-2009-2625MEDIUMCVSS 5.0v1.5.0v1.6.02009-08-06
CVE-2009-2625 [MEDIUM] CVE-2009-2625: XMLScanner.java in Apache Xerces2 Java, as used in Sun Java Runtime Environment (JRE) in JDK and JRE XMLScanner.java in Apache Xerces2 Java, as used in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15 and JDK and JRE 5.0 before Update 20, and in other products, allows remote attackers to cause a denial of service (infinite loop and application hang) via malformed XML input, as demonstrated by the Codenomicon XML fuzzing framework.
nvd
CVE-2007-3503MEDIUMCVSS 4.3v1.5.0v1.6.02007-06-30
CVE-2007-3503 [MEDIUM] CWE-79 CVE-2007-3503: The Javadoc tool in Sun JDK 6 and JDK 5.0 Update 11 can generate HTML documentation pages that conta The Javadoc tool in Sun JDK 6 and JDK 5.0 Update 11 can generate HTML documentation pages that contain cross-site scripting (XSS) vulnerabilities, which allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
nvd