cbcvebase.

Oracle Openjdk vulnerabilities

98 known vulnerabilities affecting oracle/openjdk.

Total CVEs
98
CISA KEV
1
actively exploited
Public exploits
1
Exploited in wild
2
Severity breakdown
CRITICAL4HIGH15MEDIUM51LOW28

Vulnerabilities

Page 1 of 5
CVE-2013-0431P1MEDIUMCVSS 5.3KEVPoCRansomwarev72013-01-31
CVE-2013-0431 [MEDIUM] CWE-693 CVE-2013-0431: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 throug Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, and OpenJDK 7, allows user-assisted remote attackers to bypass the Java security sandbox via unspecified vectors related to JMX, aka "Issue 52," a different vulnerability than CVE-2013-1490.
nvd
CVE-2013-2461P2HIGHCVSS 7.5Exploitedv1.7.02013-06-18
CVE-2013-2461 [HIGH] CVE-2013-2461: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier and 6 Update 45 and earlier; the Oracle JRockit component in Oracle Fusion Middleware R27.7.5 and earlier and R28.2.7 and earlier; and OpenJDK 7 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors rel
nvd
CVE-2022-34169P2HIGHCVSS 7.5≥ 11, ≤ 11.0.15≥ 13, ≤ 13.0.11+5 more2022-07-19
CVE-2022-34169 [HIGH] CWE-681 CVE-2022-34169: The Apache Xalan Java XSLT library is vulnerable to an integer truncation issue when processing mali The Apache Xalan Java XSLT library is vulnerable to an integer truncation issue when processing malicious XSLT stylesheets. This can be used to corrupt Java class files generated by the internal XSLTC compiler and execute arbitrary Java bytecode. Users are recommended to update to version 2.7.3 or later. Note: Java runtimes (such as OpenJDK) include r
nvd
CVE-2021-3517P3HIGHCVSS 8.6v82021-05-19
CVE-2021-3517 [HIGH] CWE-787 CVE-2021-3517: There is a flaw in the xml entity encoding functionality of libxml2 in versions before 2.9.11. An at There is a flaw in the xml entity encoding functionality of libxml2 in versions before 2.9.11. An attacker who is able to supply a crafted file to be processed by an application linked with the affected functionality of libxml2 could trigger an out-of-bounds read. The most likely impact of this flaw is to application availability, with some potential im
nvd
CVE-2014-8873P3CRITICALCVSS 10.0v1.7.02015-11-09
CVE-2014-8873 [CRITICAL] CWE-20 CVE-2014-8873: A .desktop file in the Debian openjdk-7 package 7u79-2.5.5-1~deb8u1 includes a MIME type registratio A .desktop file in the Debian openjdk-7 package 7u79-2.5.5-1~deb8u1 includes a MIME type registration that is added to /etc/mailcap by mime-support, which allows remote attackers to execute arbitrary code via a JAR file.
nvd
CVE-2020-2604P3HIGHCVSS 8.1≥ 11, ≤ 11.0.5≥ 13, ≤ 13.0.1+2 more2020-01-15
CVE-2020-2604 [HIGH] CWE-502 CVE-2020-2604: Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Serialization). Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Serialization). Supported versions that are affected are Java SE: 7u241, 8u231, 11.0.5 and 13.0.1; Java SE Embedded: 8u231. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embed
nvd
CVE-2020-2803P3HIGHCVSS 8.3≥ 11, ≤ 11.0.6≥ 13, ≤ 13.0.2+3 more2020-04-15
CVE-2020-2803 [HIGH] CVE-2020-2803: Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Libraries). Sup Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 7u251, 8u241, 11.0.6 and 14; Java SE Embedded: 8u241. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful
nvd
CVE-2022-21476P3HIGHCVSS 7.5≥ 11, ≤ 11.0.14≥ 13, ≤ 13.0.10+5 more2022-04-19
CVE-2022-21476 [HIGH] CWE-284 CVE-2022-21476: Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (co Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Oracle Java SE: 7u331, 8u321, 11.0.14, 17.0.2, 18; Oracle GraalVM Enterprise Edition: 20.3.5, 21.3.1 and 22.0.0.2. Easily exploitable vulnerability allows unauthenticated attacker with networ
nvd
CVE-2014-2483P3CRITICALCVSS 9.3v1.7.02014-07-17
CVE-2014-2483 [CRITICAL] CVE-2014-2483: Unspecified vulnerability in the Java SE component in Oracle Java SE Java SE 7u60 and OpenJDK 7 allo Unspecified vulnerability in the Java SE component in Oracle Java SE Java SE 7u60 and OpenJDK 7 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries, a different vulnerability than CVE-2014-4223. NOTE: the previous information is from the July 2014 CPU. Oracle has not commented on another ve
nvd
CVE-2020-2805P3HIGHCVSS 8.3≥ 11, ≤ 11.0.6≥ 13, ≤ 13.0.2+3 more2020-04-15
CVE-2020-2805 [HIGH] CVE-2020-2805: Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Libraries). Sup Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 7u251, 8u241, 11.0.6 and 14; Java SE Embedded: 8u241. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful
nvd
CVE-2020-14583P3HIGHCVSS 8.3v7v8+13 more2020-07-15
CVE-2020-14583 [HIGH] CVE-2020-14583: Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Libraries). Sup Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 7u261, 8u251, 11.0.7 and 14.0.1; Java SE Embedded: 8u251. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Succe
nvd
CVE-2021-35560P3HIGHCVSS 7.5v82021-10-20
CVE-2021-35560 [HIGH] CVE-2021-35560: Vulnerability in the Java SE product of Oracle Java SE (component: Deployment). The supported versio Vulnerability in the Java SE product of Oracle Java SE (component: Deployment). The supported version that is affected is Java SE: 8u301. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks require human interaction from a person other than the attacker. Succes
nvd
CVE-2021-2388P3HIGHCVSS 7.5v8v11+25 more2021-07-21
CVE-2021-2388 [HIGH] CVE-2021-2388: Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Java SE: 8u291, 11.0.11, 16.0.1; Oracle GraalVM Enterprise Edition: 20.3.2 and 21.1.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise
nvd
CVE-2023-21930P3HIGHCVSS 7.4fixed in 8≥ 11, ≤ 11.0.18+3 more2023-04-18
CVE-2023-21930 [HIGH] CVE-2023-21930: Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (co Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JSSE). Supported versions that are affected are Oracle Java SE: 8u361, 8u361-perf, 11.0.18, 17.0.6, 20; Oracle GraalVM Enterprise Edition: 20.3.9, 21.3.5 and 22.3.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access
nvd
CVE-2020-2816P3HIGHCVSS 7.5≥ 11, ≤ 11.0.6≥ 13, ≤ 13.0.2+3 more2020-04-15
CVE-2020-2816 [HIGH] CVE-2020-2816: Vulnerability in the Java SE product of Oracle Java SE (component: JSSE). Supported versions that ar Vulnerability in the Java SE product of Oracle Java SE (component: JSSE). Supported versions that are affected are Java SE: 11.0.6 and 14. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Java SE. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification acc
nvd
CVE-2024-20952P3HIGHCVSS 7.4≥ 11, < 11.0.24≥ 17, < 17.0.10+2 more2024-01-16
CVE-2024-20952 [HIGH] CWE-284 CVE-2024-20952: Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition produ Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Security). Supported versions that are affected are Oracle Java SE: 8u391, 8u391-perf, 11.0.21, 17.0.9, 21.0.1; Oracle GraalVM for JDK: 17.0.9, 21.0.1; Oracle GraalVM Enterprise Edition: 20.3.12, 21.3.8 and 22.3.4. Diffi
nvd
CVE-2020-14593P3HIGHCVSS 7.4v7v8+13 more2020-07-15
CVE-2020-14593 [HIGH] CVE-2020-14593: Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: 2D). Supported Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: 2D). Supported versions that are affected are Java SE: 7u261, 8u251, 11.0.7 and 14.0.1; Java SE Embedded: 8u251. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful atta
nvd
CVE-2021-20264P3HIGHCVSS 7.8v1.8.0v112021-10-06
CVE-2021-20264 [HIGH] CWE-266 CVE-2021-20264: An insecure modification flaw in the /etc/passwd file was found in the openjdk-1.8 and openjdk-11 co An insecure modification flaw in the /etc/passwd file was found in the openjdk-1.8 and openjdk-11 containers. This flaw allows an attacker with access to the container to modify the /etc/passwd and escalate their privileges. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
nvd
CVE-2014-2405P3CRITICALCVSS 10.0v1.6.02014-05-14
CVE-2014-2405 [CRITICAL] CVE-2014-2405: Unspecified vulnerability in OpenJDK 6 before 6b31 on Debian GNU/Linux and Ubuntu 12.04 LTS and 10.0 Unspecified vulnerability in OpenJDK 6 before 6b31 on Debian GNU/Linux and Ubuntu 12.04 LTS and 10.04 LTS has unknown impact and attack vectors, a different vulnerability than CVE-2014-0462.
nvd
CVE-2014-0462P3CRITICALCVSS 10.0v1.6.02014-05-14
CVE-2014-0462 [CRITICAL] CVE-2014-0462: Unspecified vulnerability in OpenJDK 6 before 6b31 on Debian GNU/Linux and Ubuntu 12.04 LTS and 10.0 Unspecified vulnerability in OpenJDK 6 before 6b31 on Debian GNU/Linux and Ubuntu 12.04 LTS and 10.04 LTS has unknown impact and attack vectors, a different vulnerability than CVE-2014-2405.
nvd
Oracle Openjdk vulnerabilities | cvebase