Oracle / Java
179 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2018-3157 | OpenJDK: Uninitialized memory use in MIDI device handling (Sound, 8200648) | LOW | 3.7 | Oct 17, 2018 |
| CVE-2018-3150 | OpenJDK: Multi-Release attribute read from outside of the main manifest attributes (Utility, 8199171) | LOW | 3.7 | Oct 17, 2018 |
| CVE-2018-3149 | OpenJDK: Incomplete enforcement of the trustURLCodebase restriction (JNDI, 8199177) | HIGH | 8.3 | Oct 17, 2018 |
| CVE-2018-3139 | OpenJDK: Leak of sensitive header data via HTTP redirect (Networking, 8196902) | LOW | 3.1 | Oct 17, 2018 |
| CVE-2018-3136 | OpenJDK: Incorrect handling of unsigned attributes in signed Jar manifests (Security, 8194534) | LOW | 3.4 | Oct 17, 2018 |
| CVE-2018-2973 | JDK: unspecified vulnerability fixed in 6u201, 7u191, 8u181, and 10.0.2 (JSSE) | MEDIUM | 5.9 | Jul 18, 2018 |
| CVE-2018-2972 | OpenJDK: GCTR counter roll over (Security, 8200332) | MEDIUM | 5.9 | Jul 18, 2018 |
| CVE-2018-2964 | JDK: unspecified vulnerability fixed in 8u181 and 10.0.2 (Deployment) | HIGH | 8.3 | Jul 18, 2018 |
| CVE-2018-2952 | OpenJDK: insufficient index validation in PatternSyntaxException getMessage() (Concurrency, 8199547) | LOW | 3.7 | Jul 18, 2018 |
| CVE-2018-2942 | JDK: unspecified vulnerability fixed in 7u191 and 8u181 (Windows DLL) | HIGH | 8.3 | Jul 18, 2018 |
| CVE-2018-2941 | JDK: unspecified vulnerability fixed in 7u191, 8u181, and 10.0.2 (JavaFX) | HIGH | 8.3 | Jul 18, 2018 |
| CVE-2018-2940 | JDK: unspecified vulnerability fixed in 6u201, 7u191, 8u181, and 10.0.2 (Libraries) | MEDIUM | 4.3 | Jul 18, 2018 |
| CVE-2018-2938 | JDK: unspecified vulnerability fixed in 6u201, 7u191, and 8u181 (Java DB) | CRITICAL | 9.0 | Jul 18, 2018 |
| CVE-2018-2826 | OpenJDK: incorrect type check for the MethodHandles' tryFinally cleanup exception type (Libraries, 8194238) | HIGH | 8.3 | Apr 19, 2018 |
| CVE-2018-2825 | OpenJDK: insufficient array type checks in VarHandle (Libraries, 8194233) | HIGH | 8.3 | Apr 19, 2018 |
| CVE-2018-2815 | OpenJDK: unbounded memory allocation during deserialization in StubIORImpl (Serialization, 8192757) | MEDIUM | 5.3 | Apr 19, 2018 |
| CVE-2018-2814 | OpenJDK: incorrect handling of Reference clones can lead to sandbox bypass (Hotspot, 8192025) | HIGH | 8.3 | Apr 19, 2018 |
| CVE-2018-2811 | JDK: unspecified vulnerability fixed in 8u171 and 10.0.1 (Install) | HIGH | 7.7 | Apr 19, 2018 |
| CVE-2018-2800 | OpenJDK: RMI HTTP transport enabled by default (RMI, 8193833) | MEDIUM | 4.2 | Apr 19, 2018 |
| CVE-2018-2799 | OpenJDK: unbounded memory allocation during deserialization in NamedNodeMapImpl (JAXP, 8189993) | MEDIUM | 5.3 | Apr 19, 2018 |
| CVE-2018-2798 | OpenJDK: unbounded memory allocation during deserialization in Container (AWT, 8189989) | MEDIUM | 5.3 | Apr 19, 2018 |
| CVE-2018-2797 | OpenJDK: unbounded memory allocation during deserialization in TabularDataSupport (JMX, 8189985) | MEDIUM | 5.3 | Apr 19, 2018 |
| CVE-2018-2796 | OpenJDK: unbounded memory allocation during deserialization in PriorityBlockingQueue (Concurrency, 8189981) | MEDIUM | 5.3 | Apr 19, 2018 |
| CVE-2018-2795 | OpenJDK: insufficient consistency checks in deserialization of multiple classes (Security, 8189977) | MEDIUM | 5.3 | Apr 19, 2018 |
| CVE-2018-2794 | OpenJDK: unrestricted deserialization of data from JCEKS key stores (Security, 8189997) | HIGH | 7.7 | Apr 19, 2018 |
Showing 76 to 100 of 179 CVEs