<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – OpenJDK builds from Oracle</title>
  <link>https://cvedaily.com/pages/tags/openjdk-builds-from-oracle.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/openjdk-builds-from-oracle.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – OpenJDK builds from Oracle</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:27:06 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2025-4447 – In Eclipse OpenJ9 versions up to 0.51, when used with OpenJDK version 8 a stack ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-4447</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-4447</guid>
    <pubDate>Fri, 09 May 2025 21:15:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-4447</strong></p>
  <p>In Eclipse OpenJ9 versions up to 0.51, when used with OpenJDK version 8 a stack based buffer overflow can be caused by modifying a file on disk that is read when the JVM starts.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-121</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-4447">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-39913 – Deserialization of Untrusted Data, Improper Input Validation vulnerability in Ap...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-39913</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-39913</guid>
    <pubDate>Wed, 08 Nov 2023 08:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-39913</strong></p>
  <p>Deserialization of Untrusted Data, Improper Input Validation vulnerability in Apache UIMA Java SDK, Apache UIMA Java SDK, Apache UIMA Java SDK, Apache UIMA Java SDK.This issue affects Apache UIMA Java SDK: before 3.5.0.  Users are recommended to upgrade to version 3.5.0, which fixes the issue.  There are several locations in the code where serialized Java objects are deserialized without verifyin…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-39913">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-42503 – Improper Input Validation, Uncontrolled Resource Consumption vulnerability in Ap...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-42503</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-42503</guid>
    <pubDate>Thu, 14 Sep 2023 08:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-42503</strong></p>
  <p>Improper Input Validation, Uncontrolled Resource Consumption vulnerability in Apache Commons Compress in TAR parsing.This issue affects Apache Commons Compress: from 1.22 before 1.24.0.  Users are recommended to upgrade to version 1.24.0, which fixes the issue.  A third party can create a malformed TAR file by manipulating file modification times headers, which when parsed with Apache Commons Com…</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-42503">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-34169 – The Apache Xalan Java XSLT library is vulnerable to an integer truncation issue ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-34169</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-34169</guid>
    <pubDate>Tue, 19 Jul 2022 18:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-34169</strong></p>
  <p>The Apache Xalan Java XSLT library is vulnerable to an integer truncation issue when processing malicious XSLT stylesheets. This can be used to corrupt Java class files generated by the internal XSLTC compiler and execute arbitrary Java bytecode. Users are recommended to update to version 2.7.3 or later. Note: Java runtimes (such as OpenJDK) include repackaged copies of Xalan.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-681</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-34169">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-20264 – An insecure modification flaw in the /etc/passwd file was found in the openjdk-1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-20264</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-20264</guid>
    <pubDate>Wed, 06 Oct 2021 16:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-20264</strong></p>
  <p>An insecure modification flaw in the /etc/passwd file was found in the openjdk-1.8 and openjdk-11 containers. This flaw allows an attacker with access to the container to modify the /etc/passwd and escalate their privileges. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-266</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-20264">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-32553 – It was discovered that read_file() in apport/hookutils.py would follow symbolic ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-32553</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-32553</guid>
    <pubDate>Sat, 12 Jun 2021 04:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-32553</strong></p>
  <p>It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function is used by the openjdk-17 package apport hooks, it could expose private data to other local users.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-59</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-32553">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-32552 – It was discovered that read_file() in apport/hookutils.py would follow symbolic ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-32552</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-32552</guid>
    <pubDate>Sat, 12 Jun 2021 04:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-32552</strong></p>
  <p>It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function is used by the openjdk-16 package apport hooks, it could expose private data to other local users.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-59</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-32552">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-32551 – It was discovered that read_file() in apport/hookutils.py would follow symbolic ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-32551</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-32551</guid>
    <pubDate>Sat, 12 Jun 2021 04:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-32551</strong></p>
  <p>It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function is used by the openjdk-15 package apport hooks, it could expose private data to other local users.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-59</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-32551">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-32550 – It was discovered that read_file() in apport/hookutils.py would follow symbolic ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-32550</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-32550</guid>
    <pubDate>Sat, 12 Jun 2021 04:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-32550</strong></p>
  <p>It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function is used by the openjdk-14 package apport hooks, it could expose private data to other local users.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-59</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-32550">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-32549 – It was discovered that read_file() in apport/hookutils.py would follow symbolic ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-32549</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-32549</guid>
    <pubDate>Sat, 12 Jun 2021 04:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-32549</strong></p>
  <p>It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function is used by the openjdk-13 package apport hooks, it could expose private data to other local users.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-59</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-32549">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-32548 – It was discovered that read_file() in apport/hookutils.py would follow symbolic ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-32548</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-32548</guid>
    <pubDate>Sat, 12 Jun 2021 04:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-32548</strong></p>
  <p>It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function is used by the openjdk-8 package apport hooks, it could expose private data to other local users.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-59</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-32548">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-32547 – It was discovered that read_file() in apport/hookutils.py would follow symbolic ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-32547</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-32547</guid>
    <pubDate>Sat, 12 Jun 2021 04:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-32547</strong></p>
  <p>It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function is used by the openjdk-lts package apport hooks, it could expose private data to other local users.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-59</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-32547">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-14338 – A flaw was found in Wildfly's implementation of Xerces, specifically in the way ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-14338</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-14338</guid>
    <pubDate>Thu, 17 Sep 2020 15:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-14338</strong></p>
  <p>A flaw was found in Wildfly's implementation of Xerces, specifically in the way the XMLSchemaValidator class in the JAXP component of Wildfly enforced the "use-grammar-pool-only" feature. This flaw allows a specially-crafted XML file to manipulate the validation process in certain cases. This issue is the same flaw as CVE-2020-14621, which affected OpenJDK, and uses a similar code. This flaw affe…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-14338">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2012-4420 – An information disclosure flaw was found in the way the Java Virtual Machine (JV...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2012-4420</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2012-4420</guid>
    <pubDate>Thu, 26 Dec 2019 21:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2012-4420</strong></p>
  <p>An information disclosure flaw was found in the way the Java Virtual Machine (JVM) implementation of Java SE 7 as provided by OpenJDK 7 incorrectly initialized integer arrays after memory allocation (in certain circumstances they had nonzero elements right after the allocation). A remote attacker could use this flaw to obtain potentially sensitive information.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2012-4420">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2018-12548 – In OpenJDK + Eclipse OpenJ9 version 0.11.0 builds, the public jdk.crypto.jniprov...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-12548</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-12548</guid>
    <pubDate>Thu, 31 Jan 2019 20:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2018-12548</strong></p>
  <p>In OpenJDK + Eclipse OpenJ9 version 0.11.0 builds, the public jdk.crypto.jniprovider.NativeCrypto class contains public static natives which accept pointer values that are dereferenced in the native code.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-822</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-12548">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2018-14627 – The IIOP OpenJDK Subsystem in WildFly before version 14.0.0 does not honour conf...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-14627</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-14627</guid>
    <pubDate>Tue, 04 Sep 2018 12:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2018-14627</strong></p>
  <p>The IIOP OpenJDK Subsystem in WildFly before version 14.0.0 does not honour configuration when SSL transport is required. Servers before this version that are configured with the following setting allow clients to create plaintext connections: <transport-config confidentiality="required" trust-in-target="supported"/></p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-319</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-14627">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2013-4578 – jarsigner in OpenJDK and Oracle Java SE before 7u51 allows remote attackers to b...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-4578</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-4578</guid>
    <pubDate>Fri, 29 Dec 2017 22:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2013-4578</strong></p>
  <p>jarsigner in OpenJDK and Oracle Java SE before 7u51 allows remote attackers to bypass a code-signing protection mechanism and inject unsigned bytecode into a signed JAR file by leveraging improper file validation.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-4578">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-1000357 – Denial of Service attack when the switch rejects to receive packets from the con...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-1000357</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-1000357</guid>
    <pubDate>Mon, 24 Apr 2017 16:59:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-1000357</strong></p>
  <p>Denial of Service attack when the switch rejects to receive packets from the controller. Component: This vulnerability affects OpenDaylight odl-l2switch-switch, which is the feature responsible for the OpenFlow communication. Version: OpenDaylight versions 3.3 (Lithium-SR3), 3.4 (Lithium-SR4), 4.0 (Beryllium), 4.1 (Beryllium-SR1), 4.2 (Beryllium-SR2), and 4.4 (Beryllium-SR4) are affected by this…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-1000357">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2014-8873 – A .desktop file in the Debian openjdk-7 package 7u79-2.5.5-1~deb8u1 includes a M...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-8873</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-8873</guid>
    <pubDate>Mon, 09 Nov 2015 16:59:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2014-8873</strong></p>
  <p>A .desktop file in the Debian openjdk-7 package 7u79-2.5.5-1~deb8u1 includes a MIME type registration that is added to /etc/mailcap by mime-support, which allows remote attackers to execute arbitrary code via a JAR file.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-8873">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2014-2483 – Unspecified vulnerability in the Java SE component in Oracle Java SE Java SE 7u6...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-2483</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-2483</guid>
    <pubDate>Thu, 17 Jul 2014 05:10:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2014-2483</strong></p>
  <p>Unspecified vulnerability in the Java SE component in Oracle Java SE Java SE 7u60 and OpenJDK 7 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries, a different vulnerability than CVE-2014-4223. NOTE: the previous information is from the July 2014 CPU. Oracle has not commented on another vendor's claim that the issue is related t…</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-2483">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2014-2405 – Unspecified vulnerability in OpenJDK 6 before 6b31 on Debian GNU/Linux and Ubunt...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-2405</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-2405</guid>
    <pubDate>Wed, 14 May 2014 00:55:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2014-2405</strong></p>
  <p>Unspecified vulnerability in OpenJDK 6 before 6b31 on Debian GNU/Linux and Ubuntu 12.04 LTS and 10.04 LTS has unknown impact and attack vectors, a different vulnerability than CVE-2014-0462.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-2405">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2014-0462 – Unspecified vulnerability in OpenJDK 6 before 6b31 on Debian GNU/Linux and Ubunt...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-0462</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-0462</guid>
    <pubDate>Wed, 14 May 2014 00:55:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2014-0462</strong></p>
  <p>Unspecified vulnerability in OpenJDK 6 before 6b31 on Debian GNU/Linux and Ubuntu 12.04 LTS and 10.04 LTS has unknown impact and attack vectors, a different vulnerability than CVE-2014-2405.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-0462">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2014-1876 – The unpacker::redirect_stdio function in unpack.cpp in unpack200 in OpenJDK 6, 7...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-1876</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-1876</guid>
    <pubDate>Mon, 10 Feb 2014 23:55:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2014-1876</strong></p>
  <p>The unpacker::redirect_stdio function in unpack.cpp in unpack200 in OpenJDK 6, 7, and 8; Oracle Java SE 5.0u61, 6u71, 7u51, and 8; JRockit R27.8.1 and R28.3.1; and Java SE Embedded 7u51 does not securely create temporary files when a log file cannot be opened, which allows local users to overwrite arbitrary files via a symlink attack on /tmp/unpack.log.</p>
  <p><strong>CVSS:</strong> 4.4 · <strong>CWE:</strong> CWE-59</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-1876">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2013-4160 – Little CMS (lcms2) before 2.5, as used in OpenJDK 7 and possibly other products,...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-4160</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-4160</guid>
    <pubDate>Tue, 21 Jan 2014 18:55:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2013-4160</strong></p>
  <p>Little CMS (lcms2) before 2.5, as used in OpenJDK 7 and possibly other products, allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via vectors related to (1) cmsStageAllocLabV2ToV4curves, (2) cmsPipelineDup, (3) cmsAllocProfileSequenceDescription, (4) CurvesAlloc, and (5) cmsnamed.</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-4160">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2013-5884 – Unspecified vulnerability in Oracle Java SE 5.0u55, 6u65, and 7u45; Java SE Embe...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-5884</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-5884</guid>
    <pubDate>Wed, 15 Jan 2014 16:11:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2013-5884</strong></p>
  <p>Unspecified vulnerability in Oracle Java SE 5.0u55, 6u65, and 7u45; Java SE Embedded 7u45; and OpenJDK 7 allows remote attackers to affect confidentiality via vectors related to CORBA.  NOTE: the previous information is from the January 2014 CPU. Oracle has not commented on third-party claims that the issue is related to an incorrect check for code permissions by CORBA stub factories.</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-5884">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2013-5878 – Unspecified vulnerability in Oracle Java SE 6u65 and 7u45, Java SE Embedded 7u45...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-5878</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-5878</guid>
    <pubDate>Wed, 15 Jan 2014 16:11:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2013-5878</strong></p>
  <p>Unspecified vulnerability in Oracle Java SE 6u65 and 7u45, Java SE Embedded 7u45, and OpenJDK 7 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Security.  NOTE: the previous information is from the January 2014 CPU.  Oracle has not commented on third-party claims that the Security component does not properly handle null XML namespace (…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-5878">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2014-0428 – Unspecified vulnerability in Oracle Java SE 5.0u55, 6u65, and 7u45; Java SE Embe...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-0428</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-0428</guid>
    <pubDate>Wed, 15 Jan 2014 16:08:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2014-0428</strong></p>
  <p>Unspecified vulnerability in Oracle Java SE 5.0u55, 6u65, and 7u45; Java SE Embedded 7u45; and OpenJDK 7 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to CORBA.  NOTE: the previous information is from the January 2014 CPU. Oracle has not commented on third-party claims that the issue is related to "insufficient security checks in IIOP streams,"…</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-0428">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2014-0423 – Unspecified vulnerability in Oracle Java SE 5.0u55, 6u65, and 7u45; JRockit R27...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-0423</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-0423</guid>
    <pubDate>Wed, 15 Jan 2014 16:08:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2014-0423</strong></p>
  <p>Unspecified vulnerability in Oracle Java SE 5.0u55, 6u65, and 7u45; JRockit R27.7.7 and R28.2.9; Java SE Embedded 7u45; and OpenJDK 7 allows remote authenticated users to affect confidentiality and availability via unknown vectors related to Beans.  NOTE: the previous information is from the January 2014 CPU. Oracle has not commented on third-party claims that this issue is an XML External Entity…</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-0423">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2014-0422 – Unspecified vulnerability in Oracle Java SE 5.0u55, 6u65, and 7u45; Java SE Embe...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-0422</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-0422</guid>
    <pubDate>Wed, 15 Jan 2014 16:08:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2014-0422</strong></p>
  <p>Unspecified vulnerability in Oracle Java SE 5.0u55, 6u65, and 7u45; Java SE Embedded 7u45; and OpenJDK 7 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to JNDI.  NOTE: the previous information is from the January 2014 CPU. Oracle has not commented on third-party claims that the issue is related to missing package access checks in the Naming / JN…</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-0422">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2014-0416 – Unspecified vulnerability in Oracle Java SE 5.0u55, 6u65, and 7u45; Java SE Embe...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-0416</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-0416</guid>
    <pubDate>Wed, 15 Jan 2014 16:08:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2014-0416</strong></p>
  <p>Unspecified vulnerability in Oracle Java SE 5.0u55, 6u65, and 7u45; Java SE Embedded 7u45; and OpenJDK 7 allows remote attackers to affect integrity via vectors related to JAAS.  NOTE: the previous information is from the January 2014 CPU. Oracle has not commented on third-party claims that the issue is related to how principals are set for the Subject class, which allows attackers to escape the…</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-0416">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2014-0411 – Unspecified vulnerability in Oracle Java SE 5.0u55, 6u65, and 7u45; JRockit R27...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-0411</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-0411</guid>
    <pubDate>Wed, 15 Jan 2014 16:08:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2014-0411</strong></p>
  <p>Unspecified vulnerability in Oracle Java SE 5.0u55, 6u65, and 7u45; JRockit R27.7.7 and R28.2.9; Java SE Embedded 7u45; and OpenJDK 7 allows remote attackers to affect confidentiality and integrity via vectors related to JSSE.  NOTE: the previous information is from the January 2014 CPU. Oracle has not commented on third-party claims that this issue allows remote attackers to obtain sensitive inf…</p>
  <p><strong>CVSS:</strong> 4.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-0411">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2014-0376 – Unspecified vulnerability in Oracle Java SE 5.0u55, 6u65, and 7u45; Java SE Embe...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-0376</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-0376</guid>
    <pubDate>Wed, 15 Jan 2014 16:08:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2014-0376</strong></p>
  <p>Unspecified vulnerability in Oracle Java SE 5.0u55, 6u65, and 7u45; Java SE Embedded 7u45; and OpenJDK 7 allows remote attackers to affect integrity via vectors related to JAXP.  NOTE: the previous information is from the January 2014 CPU. Oracle has not commented on third-party claims that the issue is related to an improper check for "code permissions when creating document builder factories."</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-0376">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2014-0373 – Unspecified vulnerability in Oracle Java SE 5.0u55, 6u65, and 7u45, and OpenJDK ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-0373</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-0373</guid>
    <pubDate>Wed, 15 Jan 2014 16:08:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2014-0373</strong></p>
  <p>Unspecified vulnerability in Oracle Java SE 5.0u55, 6u65, and 7u45, and OpenJDK 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Serviceability.  NOTE: the previous information is from the January 2014 CPU. Oracle has not commented on third-party claims that the issue is related to throwing of an incorrect exception when SnmpStatusEx…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-0373">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2013-5910 – Unspecified vulnerability in Oracle Java SE 6u65 and 7u45, Java SE Embedded 7u45...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-5910</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-5910</guid>
    <pubDate>Wed, 15 Jan 2014 16:08:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2013-5910</strong></p>
  <p>Unspecified vulnerability in Oracle Java SE 6u65 and 7u45, Java SE Embedded 7u45, and OpenJDK 7 allows remote attackers to affect integrity via unknown vectors related to Security.  NOTE: the previous information is from the January 2014 CPU. Oracle has not commented on third-party claims that CanonicalizerBase.java in the XML canonicalizer allows untrusted code to access mutable byte arrays.</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-5910">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2013-5907 – Unspecified vulnerability in Oracle Java SE 5.0u55, 6u65, and 7u45; JRockit R27...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-5907</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-5907</guid>
    <pubDate>Wed, 15 Jan 2014 16:08:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2013-5907</strong></p>
  <p>Unspecified vulnerability in Oracle Java SE 5.0u55, 6u65, and 7u45; JRockit R27.7.7 and R28.2.9; Java SE Embedded 7u45; and OpenJDK 7 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D.  NOTE: the previous information is from the January 2014 CPU. Oracle has not commented on third-party claims that the issue is due to incorrect input v…</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-5907">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2013-5896 – Unspecified vulnerability in Oracle Java SE 5.0u55, 6u65, and 7u45; Java SE Embe...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-5896</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-5896</guid>
    <pubDate>Wed, 15 Jan 2014 16:08:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2013-5896</strong></p>
  <p>Unspecified vulnerability in Oracle Java SE 5.0u55, 6u65, and 7u45; Java SE Embedded 7u45; and OpenJDK 7 allows remote attackers to affect availability via vectors related to CORBA.  NOTE: the previous information is from the January 2014 CPU. Oracle has not commented on third-party claims that com.sun.corba.se and its sub-packages are not included on the restricted package list.</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-5896">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2013-5893 – Unspecified vulnerability in Oracle Java SE 7u45 and Java SE Embedded 7u45, and ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-5893</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-5893</guid>
    <pubDate>Wed, 15 Jan 2014 16:08:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2013-5893</strong></p>
  <p>Unspecified vulnerability in Oracle Java SE 7u45 and Java SE Embedded 7u45, and OpenJDK 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries.  NOTE: the previous information is from the January 2014 CPU. Oracle has not commented on third-party claims that the issue is related to improper handling of methods in MethodHandles in…</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-5893">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2013-2473 – Unspecified vulnerability in the Java Runtime Environment (JRE) component in Ora...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-2473</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-2473</guid>
    <pubDate>Tue, 18 Jun 2013 22:55:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2013-2473</strong></p>
  <p>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier, and OpenJDK 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D.  NOTE: the previous information is from the June 2013 CPU. Oracle has not commented on claims fro…</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-2473">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2013-2472 – Unspecified vulnerability in the Java Runtime Environment (JRE) component in Ora...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-2472</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-2472</guid>
    <pubDate>Tue, 18 Jun 2013 22:55:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2013-2472</strong></p>
  <p>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier, and OpenJDK 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D.  NOTE: the previous information is from the June 2013 CPU. Oracle has not commented on claims fro…</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-2472">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2013-2471 – Unspecified vulnerability in the Java Runtime Environment (JRE) component in Ora...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-2471</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-2471</guid>
    <pubDate>Tue, 18 Jun 2013 22:55:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2013-2471</strong></p>
  <p>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier, and OpenJDK 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D.  NOTE: the previous information is from the June 2013 CPU. Oracle has not commented on claims fro…</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-2471">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2013-2470 – Unspecified vulnerability in the Java Runtime Environment (JRE) component in Ora...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-2470</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-2470</guid>
    <pubDate>Tue, 18 Jun 2013 22:55:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2013-2470</strong></p>
  <p>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier, and OpenJDK 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D.  NOTE: the previous information is from the June 2013 CPU. Oracle has not commented on claims fro…</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-2470">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2013-2469 – Unspecified vulnerability in the Java Runtime Environment (JRE) component in Ora...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-2469</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-2469</guid>
    <pubDate>Tue, 18 Jun 2013 22:55:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2013-2469</strong></p>
  <p>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier, and OpenJDK 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D.  NOTE: the previous information is from the June 2013 CPU. Oracle has not commented on claims fro…</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-2469">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2013-2465 – Unspecified vulnerability in the Java Runtime Environment (JRE) component in Ora...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-2465</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-2465</guid>
    <pubDate>Tue, 18 Jun 2013 22:55:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2013-2465</strong></p>
  <p>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier, and OpenJDK 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D.  NOTE: the previous information is from the June 2013 CPU. Oracle has not commented on claims fro…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-693</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-2465">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2013-2463 – Unspecified vulnerability in the Java Runtime Environment (JRE) component in Ora...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-2463</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-2463</guid>
    <pubDate>Tue, 18 Jun 2013 22:55:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2013-2463</strong></p>
  <p>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier, and OpenJDK 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D.  NOTE: the previous information is from the June 2013 CPU. Oracle has not commented on claims fro…</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-2463">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2013-2461 – Unspecified vulnerability in the Java Runtime Environment (JRE) component in Ora...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-2461</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-2461</guid>
    <pubDate>Tue, 18 Jun 2013 22:55:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2013-2461</strong></p>
  <p>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier and 6 Update 45 and earlier; the Oracle JRockit component in Oracle Fusion Middleware R27.7.5 and earlier and R28.2.7 and earlier; and OpenJDK 7 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries.  NOTE: the previo…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-2461">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2013-2460 – Unspecified vulnerability in the Java Runtime Environment (JRE) component in Ora...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-2460</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-2460</guid>
    <pubDate>Tue, 18 Jun 2013 22:55:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2013-2460</strong></p>
  <p>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, and OpenJDK 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Serviceability.  NOTE: the previous information is from the June 2013 CPU. Oracle has not commented on claims from another vendor that this issue allows remo…</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-2460">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2013-2459 – Unspecified vulnerability in the Java Runtime Environment (JRE) component in Ora...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-2459</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-2459</guid>
    <pubDate>Tue, 18 Jun 2013 22:55:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2013-2459</strong></p>
  <p>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier, and OpenJDK 7, allows remote attackers to affect confidentiality, integrity, and availability via vectors related to AWT.  NOTE: the previous information is from the June 2013 CPU. Oracle has not commented on claims from anoth…</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-2459">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2013-2458 – Unspecified vulnerability in the Java Runtime Environment (JRE) component in Ora...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-2458</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-2458</guid>
    <pubDate>Tue, 18 Jun 2013 22:55:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2013-2458</strong></p>
  <p>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, and OpenJDK 7, allows remote attackers to affect confidentiality and integrity via unknown vectors related to Libraries.  NOTE: the previous information is from the June 2013 CPU. Oracle has not commented on claims from another vendor that this issue allows remote attackers to bypa…</p>
  <p><strong>CVSS:</strong> 5.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-2458">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2013-2457 – Unspecified vulnerability in the Java Runtime Environment (JRE) component in Ora...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-2457</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-2457</guid>
    <pubDate>Tue, 18 Jun 2013 22:55:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2013-2457</strong></p>
  <p>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier, and OpenJDK 7, allows remote attackers to affect integrity via vectors related to JMX.  NOTE: the previous information is from the June 2013 CPU. Oracle has not commented on claims from another vendor that this issue is due to…</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-2457">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2013-2456 – Unspecified vulnerability in the Java Runtime Environment (JRE) component in Ora...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-2456</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-2456</guid>
    <pubDate>Tue, 18 Jun 2013 22:55:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2013-2456</strong></p>
  <p>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier, and OpenJDK 7, allows remote attackers to affect confidentiality via unknown vectors related to Serialization.  NOTE: the previous information is from the June 2013 CPU. Oracle has not commented on claims from another vendor t…</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-2456">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2013-2455 – Unspecified vulnerability in the Java Runtime Environment (JRE) component in Ora...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-2455</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-2455</guid>
    <pubDate>Tue, 18 Jun 2013 22:55:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2013-2455</strong></p>
  <p>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier, and OpenJDK 7, allows remote attackers to affect confidentiality via unknown vectors related to Libraries, a different vulnerability than CVE-2013-2443 and CVE-2013-2452.  NOTE: the previous information is from the June 2013 C…</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-2455">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2013-2454 – Unspecified vulnerability in the Java Runtime Environment (JRE) component in Ora...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-2454</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-2454</guid>
    <pubDate>Tue, 18 Jun 2013 22:55:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2013-2454</strong></p>
  <p>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier, and OpenJDK 7, allows remote attackers to affect confidentiality and integrity via vectors related to JDBC.  NOTE: the previous information is from the June 2013 CPU. Oracle has not commented on claims from another vendor that…</p>
  <p><strong>CVSS:</strong> 5.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-2454">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2013-2452 – Unspecified vulnerability in the Java Runtime Environment (JRE) component in Ora...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-2452</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-2452</guid>
    <pubDate>Tue, 18 Jun 2013 22:55:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2013-2452</strong></p>
  <p>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier, and OpenJDK 7, allows remote attackers to affect confidentiality via unknown vectors related to Libraries, a different vulnerability than CVE-2013-2443 and CVE-2013-2455.  NOTE: the previous information is from the June 2013 C…</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-2452">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2013-2451 – Unspecified vulnerability in the Java Runtime Environment (JRE) component in Ora...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-2451</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-2451</guid>
    <pubDate>Tue, 18 Jun 2013 22:55:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2013-2451</strong></p>
  <p>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier and 6 Update 45 and earlier, and OpenJDK 7, allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Networking.  NOTE: the previous information is from the June 2013 CPU. Oracle has not commented on claims from another vendor that thi…</p>
  <p><strong>CVSS:</strong> 3.7 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-2451">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2013-2450 – Unspecified vulnerability in the Java Runtime Environment (JRE) component in Ora...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-2450</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-2450</guid>
    <pubDate>Tue, 18 Jun 2013 22:55:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2013-2450</strong></p>
  <p>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier, and OpenJDK 7, allows remote attackers to affect availability via unknown vectors related to Serialization.  NOTE: the previous information is from the June 2013 CPU. Oracle has not commented on claims from another vendor that…</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-2450">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2013-2449 – Unspecified vulnerability in the Java Runtime Environment (JRE) component in Ora...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-2449</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-2449</guid>
    <pubDate>Tue, 18 Jun 2013 22:55:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2013-2449</strong></p>
  <p>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, and OpenJDK 7, allows remote attackers to affect confidentiality via unknown vectors related to Libraries.  NOTE: the previous information is from the June 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to GnomeFileTypeDetector and a mis…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-2449">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2013-2448 – Unspecified vulnerability in the Java Runtime Environment (JRE) component in Ora...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-2448</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-2448</guid>
    <pubDate>Tue, 18 Jun 2013 22:55:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2013-2448</strong></p>
  <p>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier, and OpenJDK 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Sound.  NOTE: the previous information is from the June 2013 CPU. Oracle has not commented on claims…</p>
  <p><strong>CVSS:</strong> 7.6 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-2448">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2013-2447 – Unspecified vulnerability in the Java Runtime Environment (JRE) component in Ora...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-2447</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-2447</guid>
    <pubDate>Tue, 18 Jun 2013 22:55:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2013-2447</strong></p>
  <p>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier, and OpenJDK 7, allows remote attackers to affect confidentiality via unknown vectors related to Networking.  NOTE: the previous information is from the June 2013 CPU. Oracle has not commented on claims from another vendor that…</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-2447">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2013-2446 – Unspecified vulnerability in the Java Runtime Environment (JRE) component in Ora...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-2446</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-2446</guid>
    <pubDate>Tue, 18 Jun 2013 22:55:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2013-2446</strong></p>
  <p>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier, and OpenJDK 7, allows remote attackers to affect confidentiality via vectors related to CORBA. NOTE: the previous information is from the June 2013 CPU. Oracle has not commented on claims from another vendor that this issue do…</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-2446">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2013-2445 – Unspecified vulnerability in the Java Runtime Environment (JRE) component in Ora...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-2445</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-2445</guid>
    <pubDate>Tue, 18 Jun 2013 22:55:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2013-2445</strong></p>
  <p>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier, and OpenJDK 7, allows remote attackers to affect availability via unknown vectors related to Hotspot.  NOTE: the previous information is from the June 2013 CPU. Oracle has not commented on claims from another vendor that this…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-2445">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2013-2444 – Unspecified vulnerability in the Java Runtime Environment (JRE) component in Ora...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-2444</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-2444</guid>
    <pubDate>Tue, 18 Jun 2013 22:55:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2013-2444</strong></p>
  <p>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier; JavaFX 2.2.21 and earlier; and OpenJDK 7 allows remote attackers to affect availability via vectors related to AWT.  NOTE: the previous information is from the June 2013 CPU. Oracle has not commented on claims from another ven…</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-2444">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2013-2443 – Unspecified vulnerability in the Java Runtime Environment (JRE) component in Ora...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-2443</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-2443</guid>
    <pubDate>Tue, 18 Jun 2013 22:55:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2013-2443</strong></p>
  <p>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier, and OpenJDK 7, allows remote attackers to affect confidentiality via unknown vectors related to Libraries, a different vulnerability than CVE-2013-2452 and CVE-2013-2455.  NOTE: the previous information is from the June 2013 C…</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-2443">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2013-2412 – Unspecified vulnerability in the Java Runtime Environment (JRE) component in Ora...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-2412</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-2412</guid>
    <pubDate>Tue, 18 Jun 2013 22:55:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2013-2412</strong></p>
  <p>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier and 6 Update 45 and earlier, and OpenJDK 7, allows remote attackers to affect confidentiality via unknown vectors related to Serviceability.  NOTE: the previous information is from the June 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related t…</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-2412">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2013-2407 – Unspecified vulnerability in the Java Runtime Environment (JRE) component in Ora...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-2407</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-2407</guid>
    <pubDate>Tue, 18 Jun 2013 22:55:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2013-2407</strong></p>
  <p>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier and 6 Update 45 and earlier, and OpenJDK 7, allows remote attackers to affect confidentiality and availability via unknown vectors related to Libraries.  NOTE: the previous information is from the June 2013 CPU. Oracle has not commented on claims from another vendor that this issue…</p>
  <p><strong>CVSS:</strong> 6.4 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-2407">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2013-1571 – Unspecified vulnerability in the Javadoc component in Oracle Java SE 7 Update 21...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-1571</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-1571</guid>
    <pubDate>Tue, 18 Jun 2013 22:55:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2013-1571</strong></p>
  <p>Unspecified vulnerability in the Javadoc component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier; JavaFX 2.2.21 and earlier; and OpenJDK 7 allows remote attackers to affect integrity via unknown vectors related to Javadoc. NOTE: the previous information is from the June 2013 CPU. Oracle has not commented on claims from another vendor that this i…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-1571">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2013-1500 – Unspecified vulnerability in the Java Runtime Environment (JRE) component in Ora...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-1500</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-1500</guid>
    <pubDate>Tue, 18 Jun 2013 22:55:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2013-1500</strong></p>
  <p>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier, and OpenJDK 7, allows local users to affect confidentiality and integrity via unknown vectors related to 2D.  NOTE: the previous information is from the June 2013 CPU. Oracle has not commented on claims from another vendor tha…</p>
  <p><strong>CVSS:</strong> 3.6 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-1500">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2013-2436 – Unspecified vulnerability in the Java Runtime Environment (JRE) component in Ora...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-2436</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-2436</guid>
    <pubDate>Wed, 17 Apr 2013 18:55:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2013-2436</strong></p>
  <p>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, and OpenJDK 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries, a different vulnerability than CVE-2013-1488 and CVE-2013-2426.  NOTE: the previous information is from the April 2013 CPU. Oracle has not comment…</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-2436">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2013-2431 – Unspecified vulnerability in the Java Runtime Environment (JRE) component in Ora...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-2431</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-2431</guid>
    <pubDate>Wed, 17 Apr 2013 18:55:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2013-2431</strong></p>
  <p>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, and OpenJDK 6 and 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to HotSpot.  NOTE: the previous information is from the April 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related…</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-2431">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2013-2430 – Unspecified vulnerability in the Java Runtime Environment (JRE) component in Ora...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-2430</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-2430</guid>
    <pubDate>Wed, 17 Apr 2013 18:55:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2013-2430</strong></p>
  <p>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, 6 Update 43 and earlier, and 5.0 Update 41 and earlier; JavaFX 2.2.7 and earlier; and OpenJDK 6 and 7 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to ImageIO. NOTE: the previous information is from the April 2013 CPU. Or…</p>
  <p><strong>CVSS:</strong> 7.6 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-2430">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2013-2429 – Unspecified vulnerability in the Java Runtime Environment (JRE) component in Ora...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-2429</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-2429</guid>
    <pubDate>Wed, 17 Apr 2013 18:55:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2013-2429</strong></p>
  <p>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, 6 Update 43 and earlier, and 5.0 Update 41 and earlier; and OpenJDK 6 and 7; allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to ImageIO.  NOTE: the previous information is from the April 2013 CPU. Oracle has not commented o…</p>
  <p><strong>CVSS:</strong> 7.6 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-2429">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2013-2426 – Unspecified vulnerability in the Java Runtime Environment (JRE) component in Ora...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-2426</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-2426</guid>
    <pubDate>Wed, 17 Apr 2013 18:55:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2013-2426</strong></p>
  <p>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, and OpenJDK 6 and 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries.  NOTE: the previous information is from the April 2013 CPU. Oracle has not commented on claims from another vendor that this issue is relate…</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-2426">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2013-2424 – Unspecified vulnerability in the Java Runtime Environment (JRE) component in Ora...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-2424</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-2424</guid>
    <pubDate>Wed, 17 Apr 2013 18:55:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2013-2424</strong></p>
  <p>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, 6 Update 43 and earlier, and 5.0 Update 41 and earlier; and OpenJDK 6 and 7; allows remote attackers to affect confidentiality via vectors related to JMX. NOTE: the previous information is from the April 2013 CPU. Oracle has not commented on claims from another vendor that this iss…</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-2424">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2013-2423 – Unspecified vulnerability in the Java Runtime Environment (JRE) component in Ora...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-2423</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-2423</guid>
    <pubDate>Wed, 17 Apr 2013 18:55:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2013-2423</strong></p>
  <p>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, and OpenJDK 7, allows remote attackers to affect integrity via unknown vectors related to HotSpot.  NOTE: the previous information is from the April 2013 CPU. Oracle has not commented on claims from the original researcher that this vulnerability allows remote attackers to bypass p…</p>
  <p><strong>CVSS:</strong> 3.7 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-2423">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2013-2422 – Unspecified vulnerability in the Java Runtime Environment (JRE) component in Ora...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-2422</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-2422</guid>
    <pubDate>Wed, 17 Apr 2013 18:55:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2013-2422</strong></p>
  <p>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier and 6 Update 43 and earlier; and OpenJDK 6 and 7; allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries.  NOTE: the previous information is from the April 2013 CPU. Oracle has not commented on claims from another vend…</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-2422">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2013-2421 – Unspecified vulnerability in the Java Runtime Environment (JRE) component in Ora...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-2421</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-2421</guid>
    <pubDate>Wed, 17 Apr 2013 18:55:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2013-2421</strong></p>
  <p>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, and OpenJDK 6 and 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to HotSpot.  NOTE: the previous information is from the April 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related…</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-2421">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2013-2420 – Unspecified vulnerability in the Java Runtime Environment (JRE) component in Ora...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-2420</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-2420</guid>
    <pubDate>Wed, 17 Apr 2013 18:55:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2013-2420</strong></p>
  <p>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, 6 Update 43 and earlier, and 5.0 Update 41 and earlier; and OpenJDK 6 and 7; allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D.  NOTE: the previous information is from the April 2013 CPU. Oracle has not commented on cla…</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-2420">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2013-2419 – Unspecified vulnerability in the Java Runtime Environment (JRE) component in Ora...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-2419</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-2419</guid>
    <pubDate>Wed, 17 Apr 2013 18:55:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2013-2419</strong></p>
  <p>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, 6 Update 43 and earlier, and 5.0 Update 41 and earlier; and OpenJDK 6 and 7; allows remote attackers to affect availability via unknown vectors related to 2D.  NOTE: the previous information is from the April 2013 CPU. Oracle has not commented on claims from another vendor that thi…</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-2419">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2013-2417 – Unspecified vulnerability in the Java Runtime Environment (JRE) component in Ora...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-2417</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-2417</guid>
    <pubDate>Wed, 17 Apr 2013 18:55:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2013-2417</strong></p>
  <p>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, 6 Update 43 and earlier, and 5.0 Update 41 and earlier; and OpenJDK 6 and 7; allows remote attackers to affect availability via unknown vectors related to Networking.  NOTE: the previous information is from the April 2013 CPU. Oracle has not commented on claims from another vendor…</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-2417">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2013-2415 – Unspecified vulnerability in the Java Runtime Environment (JRE) component in Ora...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-2415</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-2415</guid>
    <pubDate>Wed, 17 Apr 2013 18:55:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2013-2415</strong></p>
  <p>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, and OpenJDK 6 and 7, allows local users to affect confidentiality via vectors related to JAX-WS.  NOTE: the previous information is from the April 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to "processing of MTOM attachments" and the…</p>
  <p><strong>CVSS:</strong> 2.1 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-2415">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2013-2384 – Unspecified vulnerability in the Java Runtime Environment (JRE) component in Ora...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-2384</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-2384</guid>
    <pubDate>Wed, 17 Apr 2013 18:55:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2013-2384</strong></p>
  <p>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, 6 Update 43 and earlier, and 5.0 Update 41 and earlier; and OpenJDK 6 and 7; allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D, a different vulnerability than CVE-2013-1569, CVE-2013-2383, and CVE-2013-2420. NOTE: the p…</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-2384">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2013-2383 – Unspecified vulnerability in the Java Runtime Environment (JRE) component in Ora...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-2383</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-2383</guid>
    <pubDate>Wed, 17 Apr 2013 18:55:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2013-2383</strong></p>
  <p>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, 6 Update 43 and earlier, and 5.0 Update 41 and earlier; and OpenJDK 6 and 7; allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D, a different vulnerability than CVE-2013-1569, CVE-2013-2384, and CVE-2013-2420. NOTE: the p…</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-2383">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2013-1569 – Unspecified vulnerability in the Java Runtime Environment (JRE) component in Ora...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-1569</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-1569</guid>
    <pubDate>Wed, 17 Apr 2013 18:55:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2013-1569</strong></p>
  <p>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, 6 Update 43 and earlier, and 5.0 Update 41 and earlier; and OpenJDK 6 and 7; allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D.  NOTE: the previous information is from the April 2013 CPU. Oracle has not commented on cla…</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-1569">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2013-1557 – Unspecified vulnerability in the Java Runtime Environment (JRE) component in Ora...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-1557</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-1557</guid>
    <pubDate>Wed, 17 Apr 2013 18:55:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2013-1557</strong></p>
  <p>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, 6 Update 43 and earlier, and 5.0 Update 41 and earlier; and OpenJDK 6 and 7; allows remote attackers to affect confidentiality, integrity, and availability via vectors related to RMI.  NOTE: the previous information is from the April 2013 CPU. Oracle has not commented on claims fro…</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-1557">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2013-1537 – Unspecified vulnerability in the Java Runtime Environment (JRE) component in Ora...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-1537</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-1537</guid>
    <pubDate>Wed, 17 Apr 2013 18:55:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2013-1537</strong></p>
  <p>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, 6 Update 43 and earlier, and 5.0 Update 41 and earlier; and OpenJDK 6 and 7; allows remote attackers to affect confidentiality, integrity, and availability via vectors related to RMI.  NOTE: the previous information is from the April 2013 CPU. Oracle has not commented on claims fro…</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-1537">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2013-1518 – Unspecified vulnerability in the Java Runtime Environment (JRE) component in Ora...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-1518</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-1518</guid>
    <pubDate>Wed, 17 Apr 2013 18:55:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2013-1518</strong></p>
  <p>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, 6 Update 43 and earlier, and 5.0 Update 41 and earlier; and OpenJDK 6 and 7; allows remote attackers to affect confidentiality, integrity, and availability via vectors related to JAXP.  NOTE: the previous information is from the April 2013 CPU. Oracle has not commented on claims fr…</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-1518">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2013-1488 – The Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and e...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-1488</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-1488</guid>
    <pubDate>Fri, 08 Mar 2013 18:55:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2013-1488</strong></p>
  <p>The Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, and OpenJDK 6 and 7, allows remote attackers to execute arbitrary code via unspecified vectors involving reflection, Libraries, "improper toString calls," and the JDBC driver manager, as demonstrated by James Forshaw during a Pwn2Own competition at CanSecWest 2013.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-1488">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2013-0401 – The Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and e...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-0401</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-0401</guid>
    <pubDate>Fri, 08 Mar 2013 18:55:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2013-0401</strong></p>
  <p>The Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, 6 Update 43 and earlier, and 5.0 Update 41 and earlier; and OpenJDK 6 and 7; allows remote attackers to execute arbitrary code via vectors related to AWT, as demonstrated by Ben Murphy during a Pwn2Own competition at CanSecWest 2013.  NOTE: the previous information is from the April 2013 CPU. Oracle has not co…</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-0401">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2013-0169 – The TLS protocol 1.1 and 1.2 and the DTLS protocol 1.0 and 1.2, as used in OpenS...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-0169</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-0169</guid>
    <pubDate>Fri, 08 Feb 2013 19:55:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2013-0169</strong></p>
  <p>The TLS protocol 1.1 and 1.2 and the DTLS protocol 1.0 and 1.2, as used in OpenSSL, OpenJDK, PolarSSL, and other products, do not properly consider timing side-channel attacks on a MAC check requirement during the processing of malformed CBC padding, which allows remote attackers to conduct distinguishing attacks and plaintext-recovery attacks via statistical analysis of timing data for crafted p…</p>
  <p><strong>CVSS:</strong> 2.6 · <strong>CWE:</strong> CWE-310</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-0169">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2013-1480 – Unspecified vulnerability in the Java Runtime Environment (JRE) component in Ora...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-1480</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-1480</guid>
    <pubDate>Sat, 02 Feb 2013 00:55:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2013-1480</strong></p>
  <p>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, 5.0 through Update 38, and 1.4.2_40 and earlier, and OpenJDK 6 and 7, allows remote attackers to affect confidentiality, integrity, and availability via vectors related to AWT.  NOTE: the previous information is from the February 2013 CPU. Oracle has not commented…</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-1480">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2013-1478 – Unspecified vulnerability in the Java Runtime Environment (JRE) component in Ora...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-1478</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-1478</guid>
    <pubDate>Sat, 02 Feb 2013 00:55:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2013-1478</strong></p>
  <p>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, 5.0 through Update 38, and 1.4.2_40 and earlier, and OpenJDK 6 and 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D.  NOTE: the previous information is from the February 2013 CPU. Oracle has not com…</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-1478">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2013-1476 – Unspecified vulnerability in the Java Runtime Environment (JRE) component in Ora...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-1476</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-1476</guid>
    <pubDate>Sat, 02 Feb 2013 00:55:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2013-1476</strong></p>
  <p>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, 5.0 through Update 38, and 1.4.2_40 and earlier, and OpenJDK 6 and 7, allows remote attackers to affect confidentiality, integrity, and availability via vectors related to CORBA, a different vulnerability than CVE-2013-0441 and CVE-2013-1475.  NOTE: the previous in…</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-1476">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2013-1475 – Unspecified vulnerability in the Java Runtime Environment (JRE) component in Ora...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-1475</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-1475</guid>
    <pubDate>Sat, 02 Feb 2013 00:55:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2013-1475</strong></p>
  <p>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, 5.0 through Update 38, and 1.4.2_40 and earlier, and OpenJDK 6 and 7, allows remote attackers to affect confidentiality, integrity, and availability via vectors related to CORBA.  NOTE: the previous information is from the February 2013 CPU. Oracle has not commente…</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-1475">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2013-0450 – Unspecified vulnerability in the Java Runtime Environment (JRE) component in Ora...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-0450</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-0450</guid>
    <pubDate>Sat, 02 Feb 2013 00:55:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2013-0450</strong></p>
  <p>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, and 5.0 through Update 38, and OpenJDK 6 and 7, allows remote attackers to affect confidentiality, integrity, and availability via vectors related to JMX.  NOTE: the previous information is from the February 2013 CPU. Oracle has not commented on claims from another…</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-0450">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2013-0445 – Unspecified vulnerability in the Java Runtime Environment (JRE) component in Ora...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-0445</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-0445</guid>
    <pubDate>Sat, 02 Feb 2013 00:55:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2013-0445</strong></p>
  <p>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, and 5.0 through Update 38, and OpenJDK 6 and 7, allows remote attackers to affect confidentiality, integrity, and availability via vectors related to AWT.  NOTE: the previous information is from the February 2013 CPU. Oracle has not commented on claims from another…</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-0445">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2013-0444 – Unspecified vulnerability in the Java Runtime Environment (JRE) component in Ora...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-0444</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-0444</guid>
    <pubDate>Sat, 02 Feb 2013 00:55:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2013-0444</strong></p>
  <p>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, and OpenJDK 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Beans.  NOTE: the previous information is from the February 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to "insuf…</p>
  <p><strong>CVSS:</strong> 7.6 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-0444">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2013-0443 – Unspecified vulnerability in the Java Runtime Environment (JRE) component in Ora...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-0443</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-0443</guid>
    <pubDate>Sat, 02 Feb 2013 00:55:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2013-0443</strong></p>
  <p>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, 5.0 through Update 38, and 1.4.2_40 and earlier, and OpenJDK 6 and 7, allows remote attackers to affect confidentiality and integrity via vectors related to JSSE.  NOTE: the previous information is from the February 2013 CPU. Oracle has not commented on claims from…</p>
  <p><strong>CVSS:</strong> 4.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-0443">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2013-0442 – Unspecified vulnerability in the Java Runtime Environment (JRE) component in Ora...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-0442</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-0442</guid>
    <pubDate>Sat, 02 Feb 2013 00:55:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2013-0442</strong></p>
  <p>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, 5.0 through Update 38, and 1.4.2_40 and earlier, and OpenJDK 6 and 7, allows remote attackers to affect confidentiality, integrity, and availability via vectors related to AWT.  NOTE: the previous information is from the February 2013 CPU. Oracle has not commented…</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-0442">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2013-0441 – Unspecified vulnerability in the Java Runtime Environment (JRE) component in Ora...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-0441</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-0441</guid>
    <pubDate>Sat, 02 Feb 2013 00:55:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2013-0441</strong></p>
  <p>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, 5.0 through Update 38, and 1.4.2_40 and earlier, and OpenJDK 6 and 7, allows remote attackers to affect confidentiality, integrity, and availability via vectors related to CORBA, a different vulnerability than CVE-2013-1476 and CVE-2013-1475.  NOTE: the previous in…</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-0441">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2013-0440 – Unspecified vulnerability in the Java Runtime Environment (JRE) component in Ora...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-0440</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-0440</guid>
    <pubDate>Sat, 02 Feb 2013 00:55:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2013-0440</strong></p>
  <p>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, 5.0 through Update 38, and 1.4.2_40 and earlier, and OpenJDK 7, allows remote attackers to affect availability via vectors related to JSSE.  NOTE: the previous information is from the February 2013 CPU.  Oracle has not commented on claims from another vendor that t…</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-0440">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2013-0435 – Unspecified vulnerability in the Java Runtime Environment (JRE) component in Ora...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-0435</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-0435</guid>
    <pubDate>Sat, 02 Feb 2013 00:55:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2013-0435</strong></p>
  <p>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11 and 6 through Update 38, and OpenJDK 6 and 7, allows remote attackers to affect confidentiality via vectors related to JAX-WS.  NOTE: the previous information is from the February 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to improper res…</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-0435">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
