Oracle Jdk vulnerabilities
787 known vulnerabilities affecting oracle/jdk.
Total CVEs
787
CISA KEV
8
actively exploited
Public exploits
26
Exploited in wild
18
Severity breakdown
CRITICAL196HIGH121MEDIUM346LOW122
Vulnerabilities
Page 4 of 40
CVE-2015-4805P3CRITICALCVSS 10.0v1.6.0v1.7.0+1 more2015-10-21
CVE-2015-4805 [CRITICAL] CVE-2015-4805: Unspecified vulnerability in Oracle Java SE 6u101, 7u85, and 8u60, and Java SE Embedded 8u51, allows
Unspecified vulnerability in Oracle Java SE 6u101, 7u85, and 8u60, and Java SE Embedded 8u51, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Serialization.
nvd
CVE-2013-5843P3CRITICALCVSS 10.0v1.5.0v1.6.0+1 more2013-10-16
CVE-2013-5843 [CRITICAL] CVE-2013-5843: Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u
Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, JavaFX 2.2.40 and earlier, and Java SE Embedded 7u40 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D.
nvd
CVE-2012-5086P3CRITICALCVSS 10.0≤ 1.7.0v1.7.0+2 more2012-10-16
CVE-2012-5086 [CRITICAL] CVE-2012-5086: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier, and 6 Update 35 and earlier, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Beans.
nvd
CVE-2016-3598P3CRITICALCVSS 9.6v1.8.02016-07-21
CVE-2016-3598 [CRITICAL] CVE-2016-3598: Unspecified vulnerability in Oracle Java SE 8u92 and Java SE Embedded 8u91 allows remote attackers t
Unspecified vulnerability in Oracle Java SE 8u92 and Java SE Embedded 8u91 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Libraries, a different vulnerability than CVE-2016-3610.
nvd
CVE-2013-5787P3CRITICALCVSS 10.0≤ 1.6.0v1.6.0+2 more2013-10-16
CVE-2013-5787 [CRITICAL] CVE-2013-5787: Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, and Java SE
Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, and Java SE Embedded 7u40 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment, a different vulnerability than CVE-2013-5789, CVE-2013-5824, CVE-2013-5832, and CVE-2013-5852.
nvd
CVE-2013-5824P3CRITICALCVSS 10.0≤ 1.7.0v1.7.0+2 more2013-10-16
CVE-2013-5824 [CRITICAL] CVE-2013-5824: Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, and Java SE
Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, and Java SE Embedded 7u40 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment, a different vulnerability than CVE-2013-5787, CVE-2013-5789, CVE-2013-5832, and CVE-2013-5852.
nvd
CVE-2013-5789P3CRITICALCVSS 10.0≤ 1.6.0v1.6.0+2 more2013-10-16
CVE-2013-5789 [CRITICAL] CVE-2013-5789: Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, and Java SE
Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, and Java SE Embedded 7u40 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment, a different vulnerability than CVE-2013-5787, CVE-2013-5824, CVE-2013-5832, and CVE-2013-5852.
nvd
CVE-2012-1532P3CRITICALCVSS 10.0≤ 1.7.0v1.7.0+2 more2012-10-16
CVE-2012-1532 [CRITICAL] CVE-2012-1532: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier and 6 Update 35 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment.
nvd
CVE-2012-5087P3CRITICALCVSS 10.0≤ 1.7.0v1.7.02012-10-16
CVE-2012-5087 [CRITICAL] CVE-2012-5087: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Beans.
nvd
CVE-2012-3143P3CRITICALCVSS 10.0≤ 1.7.0v1.7.0+3 more2012-10-16
CVE-2012-3143 [CRITICAL] CVE-2012-3143: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier, 6 Update 35 and earlier, and 5.0 Update 36 and earlier allows remote attackers to affect confidentiality, integrity, and availability, related to JMX, a different vulnerability than CVE-2012-5089.
nvd
CVE-2019-11068P3CRITICALCVSS 9.8v8.02019-04-10
CVE-2019-11068 [CRITICAL] CVE-2019-11068: libxslt through 1.1.33 allows bypass of a protection mechanism because callers of xsltCheckRead and
libxslt through 1.1.33 allows bypass of a protection mechanism because callers of xsltCheckRead and xsltCheckWrite permit access even upon receiving a -1 error code. xsltCheckRead can return -1 for a crafted URL that is not actually invalid and is subsequently loaded.
nvd
CVE-2013-0425P3CRITICALCVSS 10.0v1.7.0v1.6.0+3 more2013-02-02
CVE-2013-0425 [CRITICAL] CVE-2013-0425: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 throug
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, 5.0 through Update 38, and 1.4.2_40 and earlier, and OpenJDK 6 and 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries, a different vulnerability than CVE
nvd
CVE-2013-0426P3CRITICALCVSS 10.0v1.7.0v1.6.0+3 more2013-02-02
CVE-2013-0426 [CRITICAL] CVE-2013-0426: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 throug
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, 5.0 through Update 38, and 1.4.2_40 and earlier, and OpenJDK 6 and 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries, a different vulnerability than CVE
nvd
CVE-2013-0441P3CRITICALCVSS 10.0v1.7.0v1.6.0+3 more2013-02-02
CVE-2013-0441 [CRITICAL] CVE-2013-0441: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 throug
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, 5.0 through Update 38, and 1.4.2_40 and earlier, and OpenJDK 6 and 7, allows remote attackers to affect confidentiality, integrity, and availability via vectors related to CORBA, a different vulnerability than CVE-2013-1476 a
nvd
CVE-2013-0445P3CRITICALCVSS 10.0v1.7.0v1.6.0+1 more2013-02-02
CVE-2013-0445 [CRITICAL] CVE-2013-0445: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 throug
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, and 5.0 through Update 38, and OpenJDK 6 and 7, allows remote attackers to affect confidentiality, integrity, and availability via vectors related to AWT. NOTE: the previous information is from the February 2013 CPU. Oracle h
nvd
CVE-2013-1475P3CRITICALCVSS 10.0v1.7.0v1.6.0+3 more2013-02-02
CVE-2013-1475 [CRITICAL] CVE-2013-1475: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 throug
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, 5.0 through Update 38, and 1.4.2_40 and earlier, and OpenJDK 6 and 7, allows remote attackers to affect confidentiality, integrity, and availability via vectors related to CORBA. NOTE: the previous information is from the Feb
nvd
CVE-2013-1558P3CRITICALCVSS 10.0≤ 1.7.0v1.7.0+2 more2013-04-17
CVE-2013-1558 [CRITICAL] CVE-2013-1558: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier and 6 Update 43 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Beans.
nvd
CVE-2013-2435P3CRITICALCVSS 10.0≤ 1.7.0v1.7.0+2 more2013-04-17
CVE-2013-2435 [CRITICAL] CVE-2013-2435: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier and 6 Update 43 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment, a different vulnerability than CVE-2013-2440.
nvd
CVE-2013-2440P3CRITICALCVSS 10.0≤ 1.7.0v1.7.0+2 more2013-04-17
CVE-2013-2440 [CRITICAL] CVE-2013-2440: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier and 6 Update 43 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment, a different vulnerability than CVE-2013-2435.
nvd
CVE-2013-2420P3CRITICALCVSS 10.0≤ 1.7.0v1.7.0+4 more2013-04-17
CVE-2013-2420 [CRITICAL] CVE-2013-2420: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, 6 Update 43 and earlier, and 5.0 Update 41 and earlier; and OpenJDK 6 and 7; allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D. NOTE: the previous information is from the April 20
nvd