Oracle / Jrockit
107 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2018-3214 | OpenJDK: Infinite loop in RIFF format reader (Sound, 8205361) | MEDIUM | 5.3 | Oct 17, 2018 |
| CVE-2018-3183 | OpenJDK: Unrestricted access to scripting engine (Scripting, 8202936) | CRITICAL | 9.0 | Oct 17, 2018 |
| CVE-2018-3180 | OpenJDK: Missing endpoint identification algorithm check during TLS session resumption (JSSE, 8202613) | MEDIUM | 5.6 | Oct 17, 2018 |
| CVE-2018-3149 | OpenJDK: Incomplete enforcement of the trustURLCodebase restriction (JNDI, 8199177) | HIGH | 8.3 | Oct 17, 2018 |
| CVE-2018-2952 | OpenJDK: insufficient index validation in PatternSyntaxException getMessage() (Concurrency, 8199547) | LOW | 3.7 | Jul 18, 2018 |
| CVE-2018-2815 | OpenJDK: unbounded memory allocation during deserialization in StubIORImpl (Serialization, 8192757) | MEDIUM | 5.3 | Apr 19, 2018 |
| CVE-2018-2800 | OpenJDK: RMI HTTP transport enabled by default (RMI, 8193833) | MEDIUM | 4.2 | Apr 19, 2018 |
| CVE-2018-2799 | OpenJDK: unbounded memory allocation during deserialization in NamedNodeMapImpl (JAXP, 8189993) | MEDIUM | 5.3 | Apr 19, 2018 |
| CVE-2018-2798 | OpenJDK: unbounded memory allocation during deserialization in Container (AWT, 8189989) | MEDIUM | 5.3 | Apr 19, 2018 |
| CVE-2018-2797 | OpenJDK: unbounded memory allocation during deserialization in TabularDataSupport (JMX, 8189985) | MEDIUM | 5.3 | Apr 19, 2018 |
| CVE-2018-2796 | OpenJDK: unbounded memory allocation during deserialization in PriorityBlockingQueue (Concurrency, 8189981) | MEDIUM | 5.3 | Apr 19, 2018 |
| CVE-2018-2795 | OpenJDK: insufficient consistency checks in deserialization of multiple classes (Security, 8189977) | MEDIUM | 5.3 | Apr 19, 2018 |
| CVE-2018-2794 | OpenJDK: unrestricted deserialization of data from JCEKS key stores (Security, 8189997) | HIGH | 7.7 | Apr 19, 2018 |
| CVE-2018-2783 | JDK: unspecified vulnerability fixed in 6u191, 7u171, and 8u161 (Security) | HIGH | 7.4 | Apr 19, 2018 |
| CVE-2018-2678 | OpenJDK: unbounded memory allocation in BasicAttributes deserialization (JNDI, 8191142) | MEDIUM | 4.3 | Jan 18, 2018 |
| CVE-2018-2663 | OpenJDK: ArrayBlockingQueue deserialization to an inconsistent state (Libraries, 8189284) | MEDIUM | 4.3 | Jan 18, 2018 |
| CVE-2018-2657 | JDK: unspecified vulnerability fixed in 6u181 and 7u171 (Serialization) | MEDIUM | 5.3 | Jan 18, 2018 |
| CVE-2018-2637 | OpenJDK: SingleEntryRegistry incorrect setup of deserialization filter (JMX, 8186998) | HIGH | 7.4 | Jan 18, 2018 |
| CVE-2018-2633 | OpenJDK: LDAPCertStore insecure handling of LDAP referrals (JNDI, 8186606) | HIGH | 8.3 | Jan 18, 2018 |
| CVE-2018-2629 | OpenJDK: GSS context use-after-free (JGSS, 8186212) | MEDIUM | 5.3 | Jan 18, 2018 |
| CVE-2018-2618 | OpenJDK: insufficient strength of key agreement (JCE, 8185292) | MEDIUM | 5.9 | Jan 18, 2018 |
| CVE-2018-2603 | OpenJDK: DerValue unbounded memory allocation (Libraries, 8182387) | MEDIUM | 5.3 | Jan 18, 2018 |
| CVE-2018-2599 | OpenJDK: DnsClient missing source port randomization (JNDI, 8182125) | MEDIUM | 4.8 | Jan 18, 2018 |
| CVE-2018-2588 | OpenJDK: LdapLoginModule insufficient username encoding in LDAP query (LDAP, 8178449) | MEDIUM | 4.3 | Jan 18, 2018 |
| CVE-2018-2579 | OpenJDK: unsynchronized access to encryption key data (Libraries, 8172525) | LOW | 3.7 | Jan 18, 2018 |
Showing 1 to 25 of 107 CVEs