<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – OpenJDK builds from Oracle (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/openjdk-builds-from-oracle.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/openjdk-builds-from-oracle-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – OpenJDK builds from Oracle (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:27:06 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2025-4447 – In Eclipse OpenJ9 versions up to 0.51, when used with OpenJDK version 8 a stack ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-4447</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-4447</guid>
    <pubDate>Fri, 09 May 2025 21:15:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-4447</strong></p>
  <p>In Eclipse OpenJ9 versions up to 0.51, when used with OpenJDK version 8 a stack based buffer overflow can be caused by modifying a file on disk that is read when the JVM starts.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-121</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-4447">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-39913 – Deserialization of Untrusted Data, Improper Input Validation vulnerability in Ap...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-39913</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-39913</guid>
    <pubDate>Wed, 08 Nov 2023 08:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-39913</strong></p>
  <p>Deserialization of Untrusted Data, Improper Input Validation vulnerability in Apache UIMA Java SDK, Apache UIMA Java SDK, Apache UIMA Java SDK, Apache UIMA Java SDK.This issue affects Apache UIMA Java SDK: before 3.5.0.  Users are recommended to upgrade to version 3.5.0, which fixes the issue.  There are several locations in the code where serialized Java objects are deserialized without verifyin…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-39913">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-34169 – The Apache Xalan Java XSLT library is vulnerable to an integer truncation issue ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-34169</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-34169</guid>
    <pubDate>Tue, 19 Jul 2022 18:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-34169</strong></p>
  <p>The Apache Xalan Java XSLT library is vulnerable to an integer truncation issue when processing malicious XSLT stylesheets. This can be used to corrupt Java class files generated by the internal XSLTC compiler and execute arbitrary Java bytecode. Users are recommended to update to version 2.7.3 or later. Note: Java runtimes (such as OpenJDK) include repackaged copies of Xalan.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-681</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-34169">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-20264 – An insecure modification flaw in the /etc/passwd file was found in the openjdk-1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-20264</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-20264</guid>
    <pubDate>Wed, 06 Oct 2021 16:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-20264</strong></p>
  <p>An insecure modification flaw in the /etc/passwd file was found in the openjdk-1.8 and openjdk-11 containers. This flaw allows an attacker with access to the container to modify the /etc/passwd and escalate their privileges. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-266</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-20264">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-32553 – It was discovered that read_file() in apport/hookutils.py would follow symbolic ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-32553</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-32553</guid>
    <pubDate>Sat, 12 Jun 2021 04:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-32553</strong></p>
  <p>It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function is used by the openjdk-17 package apport hooks, it could expose private data to other local users.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-59</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-32553">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-32552 – It was discovered that read_file() in apport/hookutils.py would follow symbolic ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-32552</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-32552</guid>
    <pubDate>Sat, 12 Jun 2021 04:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-32552</strong></p>
  <p>It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function is used by the openjdk-16 package apport hooks, it could expose private data to other local users.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-59</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-32552">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-32551 – It was discovered that read_file() in apport/hookutils.py would follow symbolic ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-32551</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-32551</guid>
    <pubDate>Sat, 12 Jun 2021 04:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-32551</strong></p>
  <p>It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function is used by the openjdk-15 package apport hooks, it could expose private data to other local users.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-59</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-32551">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-32550 – It was discovered that read_file() in apport/hookutils.py would follow symbolic ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-32550</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-32550</guid>
    <pubDate>Sat, 12 Jun 2021 04:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-32550</strong></p>
  <p>It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function is used by the openjdk-14 package apport hooks, it could expose private data to other local users.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-59</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-32550">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-32549 – It was discovered that read_file() in apport/hookutils.py would follow symbolic ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-32549</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-32549</guid>
    <pubDate>Sat, 12 Jun 2021 04:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-32549</strong></p>
  <p>It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function is used by the openjdk-13 package apport hooks, it could expose private data to other local users.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-59</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-32549">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-32548 – It was discovered that read_file() in apport/hookutils.py would follow symbolic ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-32548</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-32548</guid>
    <pubDate>Sat, 12 Jun 2021 04:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-32548</strong></p>
  <p>It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function is used by the openjdk-8 package apport hooks, it could expose private data to other local users.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-59</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-32548">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-32547 – It was discovered that read_file() in apport/hookutils.py would follow symbolic ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-32547</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-32547</guid>
    <pubDate>Sat, 12 Jun 2021 04:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-32547</strong></p>
  <p>It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function is used by the openjdk-lts package apport hooks, it could expose private data to other local users.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-59</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-32547">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2012-4420 – An information disclosure flaw was found in the way the Java Virtual Machine (JV...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2012-4420</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2012-4420</guid>
    <pubDate>Thu, 26 Dec 2019 21:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2012-4420</strong></p>
  <p>An information disclosure flaw was found in the way the Java Virtual Machine (JVM) implementation of Java SE 7 as provided by OpenJDK 7 incorrectly initialized integer arrays after memory allocation (in certain circumstances they had nonzero elements right after the allocation). A remote attacker could use this flaw to obtain potentially sensitive information.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2012-4420">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2018-12548 – In OpenJDK + Eclipse OpenJ9 version 0.11.0 builds, the public jdk.crypto.jniprov...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-12548</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-12548</guid>
    <pubDate>Thu, 31 Jan 2019 20:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2018-12548</strong></p>
  <p>In OpenJDK + Eclipse OpenJ9 version 0.11.0 builds, the public jdk.crypto.jniprovider.NativeCrypto class contains public static natives which accept pointer values that are dereferenced in the native code.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-822</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-12548">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-1000357 – Denial of Service attack when the switch rejects to receive packets from the con...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-1000357</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-1000357</guid>
    <pubDate>Mon, 24 Apr 2017 16:59:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-1000357</strong></p>
  <p>Denial of Service attack when the switch rejects to receive packets from the controller. Component: This vulnerability affects OpenDaylight odl-l2switch-switch, which is the feature responsible for the OpenFlow communication. Version: OpenDaylight versions 3.3 (Lithium-SR3), 3.4 (Lithium-SR4), 4.0 (Beryllium), 4.1 (Beryllium-SR1), 4.2 (Beryllium-SR2), and 4.4 (Beryllium-SR4) are affected by this…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-1000357">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2014-8873 – A .desktop file in the Debian openjdk-7 package 7u79-2.5.5-1~deb8u1 includes a M...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-8873</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-8873</guid>
    <pubDate>Mon, 09 Nov 2015 16:59:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2014-8873</strong></p>
  <p>A .desktop file in the Debian openjdk-7 package 7u79-2.5.5-1~deb8u1 includes a MIME type registration that is added to /etc/mailcap by mime-support, which allows remote attackers to execute arbitrary code via a JAR file.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-8873">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2014-2483 – Unspecified vulnerability in the Java SE component in Oracle Java SE Java SE 7u6...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-2483</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-2483</guid>
    <pubDate>Thu, 17 Jul 2014 05:10:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2014-2483</strong></p>
  <p>Unspecified vulnerability in the Java SE component in Oracle Java SE Java SE 7u60 and OpenJDK 7 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries, a different vulnerability than CVE-2014-4223. NOTE: the previous information is from the July 2014 CPU. Oracle has not commented on another vendor's claim that the issue is related t…</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-2483">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2014-2405 – Unspecified vulnerability in OpenJDK 6 before 6b31 on Debian GNU/Linux and Ubunt...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-2405</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-2405</guid>
    <pubDate>Wed, 14 May 2014 00:55:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2014-2405</strong></p>
  <p>Unspecified vulnerability in OpenJDK 6 before 6b31 on Debian GNU/Linux and Ubuntu 12.04 LTS and 10.04 LTS has unknown impact and attack vectors, a different vulnerability than CVE-2014-0462.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-2405">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2014-0462 – Unspecified vulnerability in OpenJDK 6 before 6b31 on Debian GNU/Linux and Ubunt...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-0462</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-0462</guid>
    <pubDate>Wed, 14 May 2014 00:55:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2014-0462</strong></p>
  <p>Unspecified vulnerability in OpenJDK 6 before 6b31 on Debian GNU/Linux and Ubuntu 12.04 LTS and 10.04 LTS has unknown impact and attack vectors, a different vulnerability than CVE-2014-2405.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-0462">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2013-5878 – Unspecified vulnerability in Oracle Java SE 6u65 and 7u45, Java SE Embedded 7u45...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-5878</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-5878</guid>
    <pubDate>Wed, 15 Jan 2014 16:11:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2013-5878</strong></p>
  <p>Unspecified vulnerability in Oracle Java SE 6u65 and 7u45, Java SE Embedded 7u45, and OpenJDK 7 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Security.  NOTE: the previous information is from the January 2014 CPU.  Oracle has not commented on third-party claims that the Security component does not properly handle null XML namespace (…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-5878">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2014-0428 – Unspecified vulnerability in Oracle Java SE 5.0u55, 6u65, and 7u45; Java SE Embe...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-0428</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-0428</guid>
    <pubDate>Wed, 15 Jan 2014 16:08:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2014-0428</strong></p>
  <p>Unspecified vulnerability in Oracle Java SE 5.0u55, 6u65, and 7u45; Java SE Embedded 7u45; and OpenJDK 7 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to CORBA.  NOTE: the previous information is from the January 2014 CPU. Oracle has not commented on third-party claims that the issue is related to "insufficient security checks in IIOP streams,"…</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-0428">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2014-0422 – Unspecified vulnerability in Oracle Java SE 5.0u55, 6u65, and 7u45; Java SE Embe...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-0422</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-0422</guid>
    <pubDate>Wed, 15 Jan 2014 16:08:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2014-0422</strong></p>
  <p>Unspecified vulnerability in Oracle Java SE 5.0u55, 6u65, and 7u45; Java SE Embedded 7u45; and OpenJDK 7 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to JNDI.  NOTE: the previous information is from the January 2014 CPU. Oracle has not commented on third-party claims that the issue is related to missing package access checks in the Naming / JN…</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-0422">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2014-0373 – Unspecified vulnerability in Oracle Java SE 5.0u55, 6u65, and 7u45, and OpenJDK ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-0373</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-0373</guid>
    <pubDate>Wed, 15 Jan 2014 16:08:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2014-0373</strong></p>
  <p>Unspecified vulnerability in Oracle Java SE 5.0u55, 6u65, and 7u45, and OpenJDK 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Serviceability.  NOTE: the previous information is from the January 2014 CPU. Oracle has not commented on third-party claims that the issue is related to throwing of an incorrect exception when SnmpStatusEx…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-0373">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2013-5907 – Unspecified vulnerability in Oracle Java SE 5.0u55, 6u65, and 7u45; JRockit R27...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-5907</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-5907</guid>
    <pubDate>Wed, 15 Jan 2014 16:08:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2013-5907</strong></p>
  <p>Unspecified vulnerability in Oracle Java SE 5.0u55, 6u65, and 7u45; JRockit R27.7.7 and R28.2.9; Java SE Embedded 7u45; and OpenJDK 7 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D.  NOTE: the previous information is from the January 2014 CPU. Oracle has not commented on third-party claims that the issue is due to incorrect input v…</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-5907">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2013-5893 – Unspecified vulnerability in Oracle Java SE 7u45 and Java SE Embedded 7u45, and ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-5893</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-5893</guid>
    <pubDate>Wed, 15 Jan 2014 16:08:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2013-5893</strong></p>
  <p>Unspecified vulnerability in Oracle Java SE 7u45 and Java SE Embedded 7u45, and OpenJDK 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries.  NOTE: the previous information is from the January 2014 CPU. Oracle has not commented on third-party claims that the issue is related to improper handling of methods in MethodHandles in…</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-5893">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2013-2473 – Unspecified vulnerability in the Java Runtime Environment (JRE) component in Ora...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-2473</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-2473</guid>
    <pubDate>Tue, 18 Jun 2013 22:55:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2013-2473</strong></p>
  <p>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier, and OpenJDK 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D.  NOTE: the previous information is from the June 2013 CPU. Oracle has not commented on claims fro…</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-2473">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2013-2472 – Unspecified vulnerability in the Java Runtime Environment (JRE) component in Ora...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-2472</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-2472</guid>
    <pubDate>Tue, 18 Jun 2013 22:55:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2013-2472</strong></p>
  <p>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier, and OpenJDK 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D.  NOTE: the previous information is from the June 2013 CPU. Oracle has not commented on claims fro…</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-2472">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2013-2471 – Unspecified vulnerability in the Java Runtime Environment (JRE) component in Ora...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-2471</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-2471</guid>
    <pubDate>Tue, 18 Jun 2013 22:55:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2013-2471</strong></p>
  <p>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier, and OpenJDK 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D.  NOTE: the previous information is from the June 2013 CPU. Oracle has not commented on claims fro…</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-2471">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2013-2470 – Unspecified vulnerability in the Java Runtime Environment (JRE) component in Ora...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-2470</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-2470</guid>
    <pubDate>Tue, 18 Jun 2013 22:55:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2013-2470</strong></p>
  <p>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier, and OpenJDK 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D.  NOTE: the previous information is from the June 2013 CPU. Oracle has not commented on claims fro…</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-2470">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2013-2469 – Unspecified vulnerability in the Java Runtime Environment (JRE) component in Ora...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-2469</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-2469</guid>
    <pubDate>Tue, 18 Jun 2013 22:55:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2013-2469</strong></p>
  <p>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier, and OpenJDK 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D.  NOTE: the previous information is from the June 2013 CPU. Oracle has not commented on claims fro…</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-2469">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2013-2465 – Unspecified vulnerability in the Java Runtime Environment (JRE) component in Ora...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-2465</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-2465</guid>
    <pubDate>Tue, 18 Jun 2013 22:55:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2013-2465</strong></p>
  <p>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier, and OpenJDK 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D.  NOTE: the previous information is from the June 2013 CPU. Oracle has not commented on claims fro…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-693</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-2465">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2013-2463 – Unspecified vulnerability in the Java Runtime Environment (JRE) component in Ora...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-2463</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-2463</guid>
    <pubDate>Tue, 18 Jun 2013 22:55:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2013-2463</strong></p>
  <p>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier, and OpenJDK 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D.  NOTE: the previous information is from the June 2013 CPU. Oracle has not commented on claims fro…</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-2463">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2013-2461 – Unspecified vulnerability in the Java Runtime Environment (JRE) component in Ora...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-2461</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-2461</guid>
    <pubDate>Tue, 18 Jun 2013 22:55:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2013-2461</strong></p>
  <p>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier and 6 Update 45 and earlier; the Oracle JRockit component in Oracle Fusion Middleware R27.7.5 and earlier and R28.2.7 and earlier; and OpenJDK 7 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries.  NOTE: the previo…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-2461">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2013-2460 – Unspecified vulnerability in the Java Runtime Environment (JRE) component in Ora...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-2460</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-2460</guid>
    <pubDate>Tue, 18 Jun 2013 22:55:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2013-2460</strong></p>
  <p>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, and OpenJDK 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Serviceability.  NOTE: the previous information is from the June 2013 CPU. Oracle has not commented on claims from another vendor that this issue allows remo…</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-2460">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2013-2459 – Unspecified vulnerability in the Java Runtime Environment (JRE) component in Ora...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-2459</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-2459</guid>
    <pubDate>Tue, 18 Jun 2013 22:55:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2013-2459</strong></p>
  <p>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier, and OpenJDK 7, allows remote attackers to affect confidentiality, integrity, and availability via vectors related to AWT.  NOTE: the previous information is from the June 2013 CPU. Oracle has not commented on claims from anoth…</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-2459">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2013-2448 – Unspecified vulnerability in the Java Runtime Environment (JRE) component in Ora...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-2448</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-2448</guid>
    <pubDate>Tue, 18 Jun 2013 22:55:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2013-2448</strong></p>
  <p>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier, and OpenJDK 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Sound.  NOTE: the previous information is from the June 2013 CPU. Oracle has not commented on claims…</p>
  <p><strong>CVSS:</strong> 7.6 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-2448">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2013-2445 – Unspecified vulnerability in the Java Runtime Environment (JRE) component in Ora...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-2445</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-2445</guid>
    <pubDate>Tue, 18 Jun 2013 22:55:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2013-2445</strong></p>
  <p>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier, and OpenJDK 7, allows remote attackers to affect availability via unknown vectors related to Hotspot.  NOTE: the previous information is from the June 2013 CPU. Oracle has not commented on claims from another vendor that this…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-2445">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2013-2436 – Unspecified vulnerability in the Java Runtime Environment (JRE) component in Ora...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-2436</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-2436</guid>
    <pubDate>Wed, 17 Apr 2013 18:55:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2013-2436</strong></p>
  <p>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, and OpenJDK 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries, a different vulnerability than CVE-2013-1488 and CVE-2013-2426.  NOTE: the previous information is from the April 2013 CPU. Oracle has not comment…</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-2436">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2013-2431 – Unspecified vulnerability in the Java Runtime Environment (JRE) component in Ora...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-2431</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-2431</guid>
    <pubDate>Wed, 17 Apr 2013 18:55:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2013-2431</strong></p>
  <p>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, and OpenJDK 6 and 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to HotSpot.  NOTE: the previous information is from the April 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related…</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-2431">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2013-2430 – Unspecified vulnerability in the Java Runtime Environment (JRE) component in Ora...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-2430</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-2430</guid>
    <pubDate>Wed, 17 Apr 2013 18:55:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2013-2430</strong></p>
  <p>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, 6 Update 43 and earlier, and 5.0 Update 41 and earlier; JavaFX 2.2.7 and earlier; and OpenJDK 6 and 7 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to ImageIO. NOTE: the previous information is from the April 2013 CPU. Or…</p>
  <p><strong>CVSS:</strong> 7.6 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-2430">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2013-2429 – Unspecified vulnerability in the Java Runtime Environment (JRE) component in Ora...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-2429</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-2429</guid>
    <pubDate>Wed, 17 Apr 2013 18:55:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2013-2429</strong></p>
  <p>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, 6 Update 43 and earlier, and 5.0 Update 41 and earlier; and OpenJDK 6 and 7; allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to ImageIO.  NOTE: the previous information is from the April 2013 CPU. Oracle has not commented o…</p>
  <p><strong>CVSS:</strong> 7.6 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-2429">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2013-2426 – Unspecified vulnerability in the Java Runtime Environment (JRE) component in Ora...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-2426</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-2426</guid>
    <pubDate>Wed, 17 Apr 2013 18:55:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2013-2426</strong></p>
  <p>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, and OpenJDK 6 and 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries.  NOTE: the previous information is from the April 2013 CPU. Oracle has not commented on claims from another vendor that this issue is relate…</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-2426">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2013-2422 – Unspecified vulnerability in the Java Runtime Environment (JRE) component in Ora...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-2422</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-2422</guid>
    <pubDate>Wed, 17 Apr 2013 18:55:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2013-2422</strong></p>
  <p>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier and 6 Update 43 and earlier; and OpenJDK 6 and 7; allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries.  NOTE: the previous information is from the April 2013 CPU. Oracle has not commented on claims from another vend…</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-2422">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2013-2421 – Unspecified vulnerability in the Java Runtime Environment (JRE) component in Ora...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-2421</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-2421</guid>
    <pubDate>Wed, 17 Apr 2013 18:55:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2013-2421</strong></p>
  <p>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, and OpenJDK 6 and 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to HotSpot.  NOTE: the previous information is from the April 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related…</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-2421">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2013-2420 – Unspecified vulnerability in the Java Runtime Environment (JRE) component in Ora...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-2420</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-2420</guid>
    <pubDate>Wed, 17 Apr 2013 18:55:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2013-2420</strong></p>
  <p>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, 6 Update 43 and earlier, and 5.0 Update 41 and earlier; and OpenJDK 6 and 7; allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D.  NOTE: the previous information is from the April 2013 CPU. Oracle has not commented on cla…</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-2420">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2013-2384 – Unspecified vulnerability in the Java Runtime Environment (JRE) component in Ora...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-2384</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-2384</guid>
    <pubDate>Wed, 17 Apr 2013 18:55:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2013-2384</strong></p>
  <p>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, 6 Update 43 and earlier, and 5.0 Update 41 and earlier; and OpenJDK 6 and 7; allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D, a different vulnerability than CVE-2013-1569, CVE-2013-2383, and CVE-2013-2420. NOTE: the p…</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-2384">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2013-2383 – Unspecified vulnerability in the Java Runtime Environment (JRE) component in Ora...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-2383</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-2383</guid>
    <pubDate>Wed, 17 Apr 2013 18:55:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2013-2383</strong></p>
  <p>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, 6 Update 43 and earlier, and 5.0 Update 41 and earlier; and OpenJDK 6 and 7; allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D, a different vulnerability than CVE-2013-1569, CVE-2013-2384, and CVE-2013-2420. NOTE: the p…</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-2383">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2013-1569 – Unspecified vulnerability in the Java Runtime Environment (JRE) component in Ora...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-1569</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-1569</guid>
    <pubDate>Wed, 17 Apr 2013 18:55:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2013-1569</strong></p>
  <p>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, 6 Update 43 and earlier, and 5.0 Update 41 and earlier; and OpenJDK 6 and 7; allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D.  NOTE: the previous information is from the April 2013 CPU. Oracle has not commented on cla…</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-1569">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2013-1557 – Unspecified vulnerability in the Java Runtime Environment (JRE) component in Ora...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-1557</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-1557</guid>
    <pubDate>Wed, 17 Apr 2013 18:55:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2013-1557</strong></p>
  <p>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, 6 Update 43 and earlier, and 5.0 Update 41 and earlier; and OpenJDK 6 and 7; allows remote attackers to affect confidentiality, integrity, and availability via vectors related to RMI.  NOTE: the previous information is from the April 2013 CPU. Oracle has not commented on claims fro…</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-1557">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2013-1537 – Unspecified vulnerability in the Java Runtime Environment (JRE) component in Ora...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-1537</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-1537</guid>
    <pubDate>Wed, 17 Apr 2013 18:55:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2013-1537</strong></p>
  <p>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, 6 Update 43 and earlier, and 5.0 Update 41 and earlier; and OpenJDK 6 and 7; allows remote attackers to affect confidentiality, integrity, and availability via vectors related to RMI.  NOTE: the previous information is from the April 2013 CPU. Oracle has not commented on claims fro…</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-1537">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2013-1518 – Unspecified vulnerability in the Java Runtime Environment (JRE) component in Ora...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-1518</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-1518</guid>
    <pubDate>Wed, 17 Apr 2013 18:55:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2013-1518</strong></p>
  <p>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, 6 Update 43 and earlier, and 5.0 Update 41 and earlier; and OpenJDK 6 and 7; allows remote attackers to affect confidentiality, integrity, and availability via vectors related to JAXP.  NOTE: the previous information is from the April 2013 CPU. Oracle has not commented on claims fr…</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-1518">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2013-1488 – The Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and e...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-1488</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-1488</guid>
    <pubDate>Fri, 08 Mar 2013 18:55:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2013-1488</strong></p>
  <p>The Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, and OpenJDK 6 and 7, allows remote attackers to execute arbitrary code via unspecified vectors involving reflection, Libraries, "improper toString calls," and the JDBC driver manager, as demonstrated by James Forshaw during a Pwn2Own competition at CanSecWest 2013.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-1488">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2013-0401 – The Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and e...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-0401</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-0401</guid>
    <pubDate>Fri, 08 Mar 2013 18:55:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2013-0401</strong></p>
  <p>The Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, 6 Update 43 and earlier, and 5.0 Update 41 and earlier; and OpenJDK 6 and 7; allows remote attackers to execute arbitrary code via vectors related to AWT, as demonstrated by Ben Murphy during a Pwn2Own competition at CanSecWest 2013.  NOTE: the previous information is from the April 2013 CPU. Oracle has not co…</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-0401">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2013-1480 – Unspecified vulnerability in the Java Runtime Environment (JRE) component in Ora...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-1480</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-1480</guid>
    <pubDate>Sat, 02 Feb 2013 00:55:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2013-1480</strong></p>
  <p>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, 5.0 through Update 38, and 1.4.2_40 and earlier, and OpenJDK 6 and 7, allows remote attackers to affect confidentiality, integrity, and availability via vectors related to AWT.  NOTE: the previous information is from the February 2013 CPU. Oracle has not commented…</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-1480">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2013-1478 – Unspecified vulnerability in the Java Runtime Environment (JRE) component in Ora...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-1478</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-1478</guid>
    <pubDate>Sat, 02 Feb 2013 00:55:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2013-1478</strong></p>
  <p>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, 5.0 through Update 38, and 1.4.2_40 and earlier, and OpenJDK 6 and 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D.  NOTE: the previous information is from the February 2013 CPU. Oracle has not com…</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-1478">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2013-1476 – Unspecified vulnerability in the Java Runtime Environment (JRE) component in Ora...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-1476</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-1476</guid>
    <pubDate>Sat, 02 Feb 2013 00:55:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2013-1476</strong></p>
  <p>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, 5.0 through Update 38, and 1.4.2_40 and earlier, and OpenJDK 6 and 7, allows remote attackers to affect confidentiality, integrity, and availability via vectors related to CORBA, a different vulnerability than CVE-2013-0441 and CVE-2013-1475.  NOTE: the previous in…</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-1476">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2013-1475 – Unspecified vulnerability in the Java Runtime Environment (JRE) component in Ora...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-1475</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-1475</guid>
    <pubDate>Sat, 02 Feb 2013 00:55:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2013-1475</strong></p>
  <p>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, 5.0 through Update 38, and 1.4.2_40 and earlier, and OpenJDK 6 and 7, allows remote attackers to affect confidentiality, integrity, and availability via vectors related to CORBA.  NOTE: the previous information is from the February 2013 CPU. Oracle has not commente…</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-1475">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2013-0450 – Unspecified vulnerability in the Java Runtime Environment (JRE) component in Ora...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-0450</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-0450</guid>
    <pubDate>Sat, 02 Feb 2013 00:55:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2013-0450</strong></p>
  <p>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, and 5.0 through Update 38, and OpenJDK 6 and 7, allows remote attackers to affect confidentiality, integrity, and availability via vectors related to JMX.  NOTE: the previous information is from the February 2013 CPU. Oracle has not commented on claims from another…</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-0450">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2013-0445 – Unspecified vulnerability in the Java Runtime Environment (JRE) component in Ora...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-0445</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-0445</guid>
    <pubDate>Sat, 02 Feb 2013 00:55:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2013-0445</strong></p>
  <p>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, and 5.0 through Update 38, and OpenJDK 6 and 7, allows remote attackers to affect confidentiality, integrity, and availability via vectors related to AWT.  NOTE: the previous information is from the February 2013 CPU. Oracle has not commented on claims from another…</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-0445">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2013-0444 – Unspecified vulnerability in the Java Runtime Environment (JRE) component in Ora...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-0444</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-0444</guid>
    <pubDate>Sat, 02 Feb 2013 00:55:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2013-0444</strong></p>
  <p>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, and OpenJDK 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Beans.  NOTE: the previous information is from the February 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to "insuf…</p>
  <p><strong>CVSS:</strong> 7.6 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-0444">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2013-0442 – Unspecified vulnerability in the Java Runtime Environment (JRE) component in Ora...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-0442</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-0442</guid>
    <pubDate>Sat, 02 Feb 2013 00:55:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2013-0442</strong></p>
  <p>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, 5.0 through Update 38, and 1.4.2_40 and earlier, and OpenJDK 6 and 7, allows remote attackers to affect confidentiality, integrity, and availability via vectors related to AWT.  NOTE: the previous information is from the February 2013 CPU. Oracle has not commented…</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-0442">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2013-0441 – Unspecified vulnerability in the Java Runtime Environment (JRE) component in Ora...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-0441</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-0441</guid>
    <pubDate>Sat, 02 Feb 2013 00:55:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2013-0441</strong></p>
  <p>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, 5.0 through Update 38, and 1.4.2_40 and earlier, and OpenJDK 6 and 7, allows remote attackers to affect confidentiality, integrity, and availability via vectors related to CORBA, a different vulnerability than CVE-2013-1476 and CVE-2013-1475.  NOTE: the previous in…</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-0441">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2013-0429 – Unspecified vulnerability in the Java Runtime Environment (JRE) component in Ora...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-0429</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-0429</guid>
    <pubDate>Sat, 02 Feb 2013 00:55:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2013-0429</strong></p>
  <p>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, and 5.0 through Update 38, and OpenJDK 6 and 7, allows remote attackers to affect confidentiality, integrity, and availability via vectors related to CORBA.  NOTE: the previous information is from the February 2013 CPU. Oracle has not commented on claims from anoth…</p>
  <p><strong>CVSS:</strong> 7.6 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-0429">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2013-0428 – Unspecified vulnerability in the Java Runtime Environment (JRE) component in Ora...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-0428</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-0428</guid>
    <pubDate>Sat, 02 Feb 2013 00:55:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2013-0428</strong></p>
  <p>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, 5.0 through Update 38, and 1.4.2_40 and earlier, and OpenJDK 6 and 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries, a different vulnerability than CVE-2013-0425 and CVE-2013-0426.  NOTE: the…</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-0428">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2013-0426 – Unspecified vulnerability in the Java Runtime Environment (JRE) component in Ora...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-0426</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-0426</guid>
    <pubDate>Sat, 02 Feb 2013 00:55:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2013-0426</strong></p>
  <p>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, 5.0 through Update 38, and 1.4.2_40 and earlier, and OpenJDK 6 and 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries, a different vulnerability than CVE-2013-0425 and CVE-2013-0428.  NOTE: the…</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-0426">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2013-0425 – Unspecified vulnerability in the Java Runtime Environment (JRE) component in Ora...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-0425</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-0425</guid>
    <pubDate>Sat, 02 Feb 2013 00:55:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2013-0425</strong></p>
  <p>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, 5.0 through Update 38, and 1.4.2_40 and earlier, and OpenJDK 6 and 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries, a different vulnerability than CVE-2013-0428 and CVE-2013-0426.  NOTE: the…</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-0425">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2011-0706 – The JNLPClassLoader class in IcedTea-Web before 1.0.1, as used in OpenJDK Runtim...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-0706</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-0706</guid>
    <pubDate>Sat, 19 Feb 2011 01:00:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2011-0706</strong></p>
  <p>The JNLPClassLoader class in IcedTea-Web before 1.0.1, as used in OpenJDK Runtime Environment 1.6.0, allows remote attackers to gain privileges via unknown vectors related to multiple signers and the assignment of "an inappropriate security descriptor."</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-0706">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2009-3883 – Multiple unspecified vulnerabilities in the Windows Pluggable Look and Feel (PL&amp;...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2009-3883</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2009-3883</guid>
    <pubDate>Mon, 09 Nov 2009 19:30:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2009-3883</strong></p>
  <p>Multiple unspecified vulnerabilities in the Windows Pluggable Look and Feel (PL&F) feature in the Swing implementation in Sun Java SE 5.0 before Update 22 and 6 before Update 17, and OpenJDK, have unknown impact and remote attack vectors, related to "information leaks in mutable variables," aka Bug Id 6657138.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2009-3883">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2009-3882 – Multiple unspecified vulnerabilities in the Swing implementation in Sun Java SE ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2009-3882</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2009-3882</guid>
    <pubDate>Mon, 09 Nov 2009 19:30:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2009-3882</strong></p>
  <p>Multiple unspecified vulnerabilities in the Swing implementation in Sun Java SE 5.0 before Update 22 and 6 before Update 17, and OpenJDK, have unknown impact and remote attack vectors, related to "information leaks in mutable variables," aka Bug Id 6657026.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2009-3882">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2009-3881 – Sun Java SE 5.0 before Update 22 and 6 before Update 17, and OpenJDK, does not p...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2009-3881</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2009-3881</guid>
    <pubDate>Mon, 09 Nov 2009 19:30:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2009-3881</strong></p>
  <p>Sun Java SE 5.0 before Update 22 and 6 before Update 17, and OpenJDK, does not prevent the existence of children of a resurrected ClassLoader, which allows remote attackers to gain privileges via unspecified vectors, related to an "information leak vulnerability," aka Bug Id 6636650.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2009-3881">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2009-3879 – Multiple unspecified vulnerabilities in the (1) X11 and (2) Win32GraphicsDevice ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2009-3879</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2009-3879</guid>
    <pubDate>Mon, 09 Nov 2009 19:30:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2009-3879</strong></p>
  <p>Multiple unspecified vulnerabilities in the (1) X11 and (2) Win32GraphicsDevice subsystems in Sun Java SE 5.0 before Update 22 and 6 before Update 17, and OpenJDK, have unknown impact and attack vectors, related to failure to clone arrays that are returned by the getConfigurations function, aka Bug Id 6822057.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2009-3879">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2009-2689 – JDK13Services.getProviders in Sun Java SE 5.0 before Update 20 and 6 before Upda...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2009-2689</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2009-2689</guid>
    <pubDate>Mon, 10 Aug 2009 18:30:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2009-2689</strong></p>
  <p>JDK13Services.getProviders in Sun Java SE 5.0 before Update 20 and 6 before Update 15, and OpenJDK, grants full privileges to instances of unspecified object types, which allows context-dependent attackers to bypass intended access restrictions via an untrusted (1) applet or (2) application.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2009-2689">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2009-2476 – The Java Management Extensions (JMX) implementation in Sun Java SE 6 before Upda...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2009-2476</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2009-2476</guid>
    <pubDate>Mon, 10 Aug 2009 18:30:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2009-2476</strong></p>
  <p>The Java Management Extensions (JMX) implementation in Sun Java SE 6 before Update 15, and OpenJDK, does not properly enforce OpenType checks, which allows context-dependent attackers to bypass intended access restrictions by leveraging finalizer resurrection to obtain a reference to a privileged object.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2009-2476">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2009-2475 – Sun Java SE 5.0 before Update 20 and 6 before Update 15, and OpenJDK, might allo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2009-2475</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2009-2475</guid>
    <pubDate>Mon, 10 Aug 2009 18:30:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2009-2475</strong></p>
  <p>Sun Java SE 5.0 before Update 20 and 6 before Update 15, and OpenJDK, might allow context-dependent attackers to obtain sensitive information via vectors involving static variables that are declared without the final keyword, related to (1) LayoutQueue, (2) Cursor.predefined, (3) AccessibleResourceBundle.getContents, (4) ImageReaderSpi.STANDARD_INPUT_TYPE, (5) ImageWriterSpi.STANDARD_OUTPUT_TYPE,…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2009-2475">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2009-1896 – The Java Web Start framework in IcedTea in OpenJDK before 1.6.0.0-20.b16.fc10 on...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2009-1896</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2009-1896</guid>
    <pubDate>Mon, 10 Aug 2009 18:30:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2009-1896</strong></p>
  <p>The Java Web Start framework in IcedTea in OpenJDK before 1.6.0.0-20.b16.fc10 on Fedora 10, and before 1.6.0.0-27.b16.fc11 on Fedora 11, trusts an entire application when at least one of the listed jar files is trusted, which allows context-dependent attackers to execute arbitrary code without the untrusted-code restrictions via a crafted application, related to NetX.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2009-1896">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2009-0733 – Multiple stack-based buffer overflows in the ReadSetOfCurves function in LittleC...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2009-0733</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2009-0733</guid>
    <pubDate>Mon, 23 Mar 2009 14:19:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2009-0733</strong></p>
  <p>Multiple stack-based buffer overflows in the ReadSetOfCurves function in LittleCMS (aka lcms or liblcms) before 1.18beta2, as used in Firefox 3.1beta, OpenJDK, and GIMP, allow context-dependent attackers to execute arbitrary code via a crafted image file associated with a large integer value for the (1) input or (2) output channel, related to the ReadLUT_A2B and ReadLUT_B2A functions.</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2009-0733">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2009-0723 – Multiple integer overflows in LittleCMS (aka lcms or liblcms) before 1.18beta2, ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2009-0723</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2009-0723</guid>
    <pubDate>Mon, 23 Mar 2009 14:19:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2009-0723</strong></p>
  <p>Multiple integer overflows in LittleCMS (aka lcms or liblcms) before 1.18beta2, as used in Firefox 3.1beta, OpenJDK, and GIMP, allow context-dependent attackers to execute arbitrary code via a crafted image file that triggers a heap-based buffer overflow.  NOTE: some of these details are obtained from third party information.</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2009-0723">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
