Oracle / Java
179 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2017-10350 | OpenJDK: unbounded memory allocation in JAXWSExceptionBase deserialization (JAX-WS, 8181100) | MEDIUM | 5.3 | Oct 19, 2017 |
| CVE-2017-10349 | OpenJDK: unbounded memory allocation in PredicatedNodeTest deserialization (JAXP, 8181327) | MEDIUM | 5.3 | Oct 19, 2017 |
| CVE-2017-10348 | OpenJDK: multiple unbounded memory allocations in deserialization (Libraries, 8181432) | MEDIUM | 5.3 | Oct 19, 2017 |
| CVE-2017-10347 | OpenJDK: unbounded memory allocation in SimpleTimeZone deserialization (Serialization, 8181323) | MEDIUM | 5.3 | Oct 19, 2017 |
| CVE-2017-10346 | OpenJDK: insufficient loader constraints checks for invokespecial (Hotspot, 8180711) | CRITICAL | 9.6 | Oct 19, 2017 |
| CVE-2017-10345 | OpenJDK: unbounded resource use in JceKeyStore deserialization (Serialization, 8181370) | LOW | 3.1 | Oct 19, 2017 |
| CVE-2017-10342 | Vulnerability in the Java Advanced Management Console component of Oracle Java SE (subcomponent: Server). The supported version that is affected is Java Advanc… | MEDIUM | 5.3 | Oct 19, 2017 |
| CVE-2017-10341 | Vulnerability in the Java Advanced Management Console component of Oracle Java SE (subcomponent: Server). The supported version that is affected is Java Advanc… | LOW | 3.7 | Oct 19, 2017 |
| CVE-2017-10309 | JDK: unspecified vulnerability fixed in 8u151 and 9.0.1 (Deployment) | HIGH | 7.1 | Oct 19, 2017 |
| CVE-2017-10295 | OpenJDK: HTTP client insufficient check for newline in URLs (Networking, 8176751) | MEDIUM | 4.0 | Oct 19, 2017 |
| CVE-2017-10293 | JDK: unspecified vulnerability fixed in 6u171, 7u161, 8u151, and 9.0.1 (Javadoc) | MEDIUM | 6.1 | Oct 19, 2017 |
| CVE-2017-10285 | OpenJDK: incorrect privilege use when handling unreferenced objects (RMI, 8174966) | CRITICAL | 9.6 | Oct 19, 2017 |
| CVE-2017-10281 | OpenJDK: multiple unbounded memory allocations in deserialization (Serialization, 8174109) | MEDIUM | 5.3 | Oct 19, 2017 |
| CVE-2017-10274 | OpenJDK: CardImpl incorrect state handling (Smart Card IO, 8169026) | MEDIUM | 6.8 | Oct 19, 2017 |
| CVE-2017-10243 | OpenJDK: insecure XML parsing in wsdlimport (JAX-WS, 8182054) | MEDIUM | 6.5 | Aug 8, 2017 |
| CVE-2017-10198 | OpenJDK: incorrect enforcement of certificate path restrictions (Security, 8179998) | MEDIUM | 6.8 | Aug 8, 2017 |
| CVE-2017-10193 | OpenJDK: incorrect key size constraint check (Security, 8179101) | LOW | 3.1 | Aug 8, 2017 |
| CVE-2017-10176 | OpenJDK: incorrect handling of certain EC points (Security, 8178135) | HIGH | 7.5 | Aug 8, 2017 |
| CVE-2017-10145 | Vulnerability in the Java Advanced Management Console component of Oracle Java SE (subcomponent: Server). The supported version that is affected is Java Advanc… | HIGH | 7.4 | Aug 8, 2017 |
| CVE-2017-10135 | OpenJDK: PKCS#8 implementation timing attack (JCE, 8176760) | MEDIUM | 5.9 | Aug 8, 2017 |
| CVE-2017-10125 | JDK: unspecified vulnerability fixed in 7u151 and 8u141 (Deployment) | HIGH | 7.1 | Aug 8, 2017 |
| CVE-2017-10121 | Vulnerability in the Java Advanced Management Console component of Oracle Java SE (subcomponent: Server). The supported version that is affected is Java Advanc… | MEDIUM | 6.1 | Aug 8, 2017 |
| CVE-2017-10118 | OpenJDK: ECDSA implementation timing attack (JCE, 8175110) | HIGH | 7.5 | Aug 8, 2017 |
| CVE-2017-10117 | Vulnerability in the Java Advanced Management Console component of Oracle Java SE (subcomponent: Server). The supported version that is affected is Java Advanc… | MEDIUM | 5.3 | Aug 8, 2017 |
| CVE-2017-10116 | OpenJDK: LDAPCertStore following referrals to non-LDAP URLs (Security, 8176067) | HIGH | 8.3 | Aug 8, 2017 |
Showing 126 to 150 of 179 CVEs