Oracle / Java
179 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2019-2945 | OpenJDK: Missing restrictions on use of custom SocketImpl (Networking, 8218573) | LOW | 3.1 | Oct 16, 2019 |
| CVE-2019-2933 | OpenJDK: FilePermission checks not preformed correctly on Windows (Libraries, 8213429) | LOW | 3.1 | Oct 16, 2019 |
| CVE-2019-2894 | OpenJDK: Side-channel vulnerability in the ECDSA implementation (Security, 8228825) | LOW | 3.7 | Oct 16, 2019 |
| CVE-2019-2842 | OpenJDK: Missing array bounds check in crypto providers (JCE, 8223511) | LOW | 3.7 | Jul 23, 2019 |
| CVE-2019-2821 | OpenJDK: Incorrect handling of certificate status messages during TLS handshake (JSSE, 8222678) | MEDIUM | 5.3 | Jul 23, 2019 |
| CVE-2019-2818 | OpenJDK: Non-constant time comparison in ChaCha20Cipher (Security, 8221344) | LOW | 3.1 | Jul 23, 2019 |
| CVE-2019-2816 | OpenJDK: Missing URL format validation (Networking, 8221518) | MEDIUM | 4.8 | Jul 23, 2019 |
| CVE-2019-2786 | OpenJDK: Insufficient restriction of privileges in AccessController (Security, 8216381) | LOW | 3.4 | Jul 23, 2019 |
| CVE-2019-2769 | OpenJDK: Unbounded memory allocation during deserialization in Collections (Utilities, 8213432) | MEDIUM | 5.3 | Jul 23, 2019 |
| CVE-2019-2766 | OpenJDK: Insufficient permission checks for file:// URLs on Windows (Networking, 8213431) | LOW | 3.1 | Jul 23, 2019 |
| CVE-2019-2762 | OpenJDK: Insufficient checks of suppressed exceptions in deserialization (Utilities, 8212328) | MEDIUM | 5.3 | Jul 23, 2019 |
| CVE-2019-2745 | OpenJDK: Side-channel attack risks in Elliptic Curve (EC) cryptography (Security, 8208698) | MEDIUM | 5.1 | Jul 23, 2019 |
| CVE-2019-2699 | Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Windows DLL). The supported version that is affected is Java SE: 8u202. Difficult to ex… | CRITICAL | 9.0 | Apr 23, 2019 |
| CVE-2019-2698 | OpenJDK: Font layout engine out of bounds access setCurrGlyphID() (2D, 8219022) | HIGH | 8.1 | Apr 23, 2019 |
| CVE-2019-2697 | JDK: Unspecified vulnerability fixed in 7u221 and 8u211 (2D) | HIGH | 8.1 | Apr 23, 2019 |
| CVE-2019-2684 | OpenJDK: Incorrect skeleton selection in RMI registry server-side dispatch handling (RMI, 8218453) | MEDIUM | 5.9 | Apr 23, 2019 |
| CVE-2019-2602 | OpenJDK: Slow conversion of BigDecimal to long (Libraries, 8211936) | HIGH | 7.5 | Apr 23, 2019 |
| CVE-2019-2540 | Vulnerability in the Java Advanced Management Console component of Oracle Java SE (subcomponent: Server). The supported version that is affected is Java Advanc… | MEDIUM | 6.1 | Jan 16, 2019 |
| CVE-2019-2449 | JDK: unspecified vulnerability fixed in 8u201 (Deployment) | LOW | 3.1 | Jan 16, 2019 |
| CVE-2019-2426 | OpenJDK: transparent NTLM authentication enabled by default (Networking, 8209094) | LOW | 3.7 | Jan 16, 2019 |
| CVE-2019-2422 | OpenJDK: memory disclosure in FileChannelImpl (Libraries, 8206290) | LOW | 3.1 | Jan 16, 2019 |
| CVE-2018-3214 | OpenJDK: Infinite loop in RIFF format reader (Sound, 8205361) | MEDIUM | 5.3 | Oct 17, 2018 |
| CVE-2018-3211 | JDK: unspecified vulnerability fixed in 8u191 and 11.0.1 (Serviceability) | MEDIUM | 6.6 | Oct 17, 2018 |
| CVE-2018-3183 | OpenJDK: Unrestricted access to scripting engine (Scripting, 8202936) | CRITICAL | 9.0 | Oct 17, 2018 |
| CVE-2018-3180 | OpenJDK: Missing endpoint identification algorithm check during TLS session resumption (JSSE, 8202613) | MEDIUM | 5.6 | Oct 17, 2018 |
Showing 51 to 75 of 179 CVEs