Oracle / Java
179 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2020-14664 | JavaFX: Out-of-bounds write in HTML Rendering | HIGH | 8.3 | Jul 15, 2020 |
| CVE-2020-14621 | OpenJDK: XML validation manipulation due to incomplete application of the use-grammar-pool-only feature (JAXP, 8242136) | MEDIUM | 5.3 | Jul 15, 2020 |
| CVE-2020-14593 | OpenJDK: Incomplete bounds checks in Affine Transformations (2D, 8240119) | HIGH | 7.4 | Jul 15, 2020 |
| CVE-2020-14583 | OpenJDK: Bypass of boundary checks in nio.Buffer via concurrent access (Libraries, 8238920) | HIGH | 8.3 | Jul 15, 2020 |
| CVE-2020-14581 | OpenJDK: Information disclosure in color management (2D, 8238002) | LOW | 3.7 | Jul 15, 2020 |
| CVE-2020-14579 | OpenJDK: Unexpected exception raised by DerValue.equals() (Libraries, 8237736) | LOW | 3.7 | Jul 15, 2020 |
| CVE-2020-14578 | OpenJDK: Unexpected exception raised by DerInputStream (Libraries, 8237731) | LOW | 3.7 | Jul 15, 2020 |
| CVE-2020-14577 | OpenJDK: HostnameChecker does not ensure X.509 certificate names are in normalized form (JSSE, 8237592) | LOW | 3.7 | Jul 15, 2020 |
| CVE-2020-14573 | OpenJDK: Incomplete interface type checks in Graal compiler (Hotspot, 8236867) | LOW | 3.7 | Jul 15, 2020 |
| CVE-2020-14562 | OpenJDK: Excessive memory usage in ImageIO TIFF plugin (ImageIO, 8233239) | MEDIUM | 5.3 | Jul 15, 2020 |
| CVE-2020-14556 | OpenJDK: Incorrect handling of access control context in ForkJoinPool (Libraries, 8237117) | MEDIUM | 4.8 | Jul 15, 2020 |
| CVE-2020-2830 | OpenJDK: Regular expression DoS in Scanner (Concurrency, 8236201) | MEDIUM | 5.3 | Apr 15, 2020 |
| CVE-2020-2816 | OpenJDK: Application data accepted before TLS handshake completion (JSSE, 8235691) | HIGH | 7.5 | Apr 15, 2020 |
| CVE-2020-2805 | OpenJDK: Incorrect type checks in MethodType.readObject() (Libraries, 8235274) | HIGH | 8.3 | Apr 15, 2020 |
| CVE-2020-2803 | OpenJDK: Incorrect bounds checks in NIO Buffers (Libraries, 8234841) | HIGH | 8.3 | Apr 15, 2020 |
| CVE-2020-2800 | OpenJDK: CRLF injection into HTTP headers in HttpServer (Lightweight HTTP Server, 8234825) | MEDIUM | 4.8 | Apr 15, 2020 |
| CVE-2020-2781 | OpenJDK: Re-use of single TLS session for new connections (JSSE, 8234408) | MEDIUM | 5.3 | Apr 15, 2020 |
| CVE-2020-2778 | OpenJDK: Incomplete enforcement of algorithm restrictions for TLS (JSSE, 8232424) | LOW | 3.7 | Apr 15, 2020 |
| CVE-2020-2773 | OpenJDK: Unexpected exceptions raised by DOMKeyInfoFactory and DOMXMLSignatureFactory (Security, 8231415) | LOW | 3.7 | Apr 15, 2020 |
| CVE-2020-2767 | OpenJDK: Incorrect handling of Certificate messages during TLS handshake (JSSE, 8232581) | MEDIUM | 4.8 | Apr 15, 2020 |
| CVE-2020-2764 | Vulnerability in the Java SE product of Oracle Java SE (component: Advanced Management Console). The supported version that is affected is Java Advanced Manage… | LOW | 3.7 | Apr 15, 2020 |
| CVE-2020-2757 | OpenJDK: Uncaught InstantiationError exception in ObjectStreamClass (Serialization, 8224549) | LOW | 3.7 | Apr 15, 2020 |
| CVE-2020-2756 | OpenJDK: Incorrect handling of references to uninitialized class descriptors during deserialization (Serialization, 8224541) | LOW | 3.7 | Apr 15, 2020 |
| CVE-2020-2755 | OpenJDK: Incorrect handling of empty string nodes in regular expression Parser (Scripting, 8223904) | LOW | 3.7 | Apr 15, 2020 |
| CVE-2020-2754 | OpenJDK: Misplaced regular expression syntax error check in RegExpScanner (Scripting, 8223898) | LOW | 3.7 | Apr 15, 2020 |
Showing 1 to 25 of 179 CVEs