HP / Xp7 Command View
53 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2018-2814 | OpenJDK: incorrect handling of Reference clones can lead to sandbox bypass (Hotspot, 8192025) | HIGH | 8.3 | Apr 19, 2018 |
| CVE-2018-2800 | OpenJDK: RMI HTTP transport enabled by default (RMI, 8193833) | MEDIUM | 4.2 | Apr 19, 2018 |
| CVE-2018-2799 | OpenJDK: unbounded memory allocation during deserialization in NamedNodeMapImpl (JAXP, 8189993) | MEDIUM | 5.3 | Apr 19, 2018 |
| CVE-2018-2798 | OpenJDK: unbounded memory allocation during deserialization in Container (AWT, 8189989) | MEDIUM | 5.3 | Apr 19, 2018 |
| CVE-2018-2797 | OpenJDK: unbounded memory allocation during deserialization in TabularDataSupport (JMX, 8189985) | MEDIUM | 5.3 | Apr 19, 2018 |
| CVE-2018-2796 | OpenJDK: unbounded memory allocation during deserialization in PriorityBlockingQueue (Concurrency, 8189981) | MEDIUM | 5.3 | Apr 19, 2018 |
| CVE-2018-2795 | OpenJDK: insufficient consistency checks in deserialization of multiple classes (Security, 8189977) | MEDIUM | 5.3 | Apr 19, 2018 |
| CVE-2018-2794 | OpenJDK: unrestricted deserialization of data from JCEKS key stores (Security, 8189997) | HIGH | 7.7 | Apr 19, 2018 |
| CVE-2018-2790 | OpenJDK: incorrect merging of sections in the JAR manifest (Security, 8189969) | LOW | 3.1 | Apr 19, 2018 |
| CVE-2018-2783 | JDK: unspecified vulnerability fixed in 6u191, 7u171, and 8u161 (Security) | HIGH | 7.4 | Apr 19, 2018 |
| CVE-2018-2678 | OpenJDK: unbounded memory allocation in BasicAttributes deserialization (JNDI, 8191142) | MEDIUM | 4.3 | Jan 18, 2018 |
| CVE-2018-2677 | OpenJDK: unbounded memory allocation during deserialization (AWT, 8190289) | MEDIUM | 4.3 | Jan 18, 2018 |
| CVE-2018-2663 | OpenJDK: ArrayBlockingQueue deserialization to an inconsistent state (Libraries, 8189284) | MEDIUM | 4.3 | Jan 18, 2018 |
| CVE-2018-2657 | JDK: unspecified vulnerability fixed in 6u181 and 7u171 (Serialization) | MEDIUM | 5.3 | Jan 18, 2018 |
| CVE-2018-2641 | OpenJDK: GTK library loading use-after-free (AWT, 8185325) | MEDIUM | 6.1 | Jan 18, 2018 |
| CVE-2018-2637 | OpenJDK: SingleEntryRegistry incorrect setup of deserialization filter (JMX, 8186998) | HIGH | 7.4 | Jan 18, 2018 |
| CVE-2018-2634 | OpenJDK: use of global credentials for HTTP/SPNEGO (JGSS, 8186600) | MEDIUM | 6.8 | Jan 18, 2018 |
| CVE-2018-2633 | OpenJDK: LDAPCertStore insecure handling of LDAP referrals (JNDI, 8186606) | HIGH | 8.3 | Jan 18, 2018 |
| CVE-2018-2629 | OpenJDK: GSS context use-after-free (JGSS, 8186212) | MEDIUM | 5.3 | Jan 18, 2018 |
| CVE-2018-2618 | OpenJDK: insufficient strength of key agreement (JCE, 8185292) | MEDIUM | 5.9 | Jan 18, 2018 |
| CVE-2018-2603 | OpenJDK: DerValue unbounded memory allocation (Libraries, 8182387) | MEDIUM | 5.3 | Jan 18, 2018 |
| CVE-2018-2602 | OpenJDK: loading of classes from untrusted locations (I18n, 8182601) | MEDIUM | 4.5 | Jan 18, 2018 |
| CVE-2018-2599 | OpenJDK: DnsClient missing source port randomization (JNDI, 8182125) | MEDIUM | 4.8 | Jan 18, 2018 |
| CVE-2018-2588 | OpenJDK: LdapLoginModule insufficient username encoding in LDAP query (LDAP, 8178449) | MEDIUM | 4.3 | Jan 18, 2018 |
| CVE-2018-2582 | OpenJDK: insufficient validation of the invokeinterface instruction (Hotspot, 8174962) | MEDIUM | 6.5 | Jan 18, 2018 |
Showing 26 to 50 of 53 CVEs