Loading HuntDB...

Java

96 Versions 179 CVEs

Versions

Java SE:7u251, 8u241, 11.0.6, 14

OTHER 8 CVEs

Java SE Embedded:8u191

OTHER 2 CVEs

Java SE Embedded:8u181

OTHER 6 CVEs

Java SE:6u141

OTHER 6 CVEs

8u131

OTHER 7 CVEs

Java SE:7u241, 8u231, 11.0.5, 13.0.1

OTHER 6 CVEs

Java SE:6u161

OTHER 14 CVEs

Java SE Embedded:8u211

OTHER 5 CVEs

10.0.1; Java SE Embedded:8u171; JRockit:R28.3.18

OTHER 1 CVE

Java SE:8u221, 11.0.4, 13

OTHER 1 CVE

Java SE:8u181, 11

OTHER 2 CVEs

9; Java SE Embedded:8u144

OTHER 8 CVEs

Java SE:7u211, 8u202

OTHER 2 CVEs

7u171

OTHER 8 CVEs

Java Advanced Management Console:2.12

OTHER 1 CVE

8u131; Java SE Embedded:8u131; JRockit:R28.3.14

OTHER 10 CVEs

Java Advanced Management Console:2.7

OTHER 4 CVEs

Java SE:8u212, 11.0.3, 12.0.1

OTHER 1 CVE

8u162

OTHER 9 CVEs

10.0.1

SEMANTIC 2 CVEs

10; Java SE Embedded:8u161; JRockit:R28.3.17

OTHER 6 CVEs

9

SINGLE_NUMBER 3 CVEs

Java SE Embedded:8u241

OTHER 10 CVEs

7u161; JRockit:R28.3.16

OTHER 1 CVE

Java SE:8u152

OTHER 3 CVEs

Java SE:10.0.1

OTHER 1 CVE

Java SE:7u261, 8u251

OTHER 2 CVEs

8u144

OTHER 15 CVEs

Java SE:7u261, 8u251, 11.0.7, 14.0.1

OTHER 4 CVEs

Java SE:7u131

OTHER 2 CVEs

Java SE:7u161

OTHER 1 CVE

Java SE:8u251, 11.0.7, 14.0.1

OTHER 2 CVEs

Java SE:11.0.5, 13.0.1

OTHER 1 CVE

Java SE:6u181

OTHER 8 CVEs

9.0.1; Java SE Embedded:8u151; JRockit:R28.3.16

OTHER 9 CVEs

Java SE Embedded:8u201

OTHER 2 CVEs

Java SE Embedded:8u231

OTHER 6 CVEs

Java SE:11.0.6, 14

OTHER 3 CVEs

Java SE:6u201, 7u191, 8u181

OTHER 2 CVEs

Java SE:8u162

OTHER 1 CVE

8u121

OTHER 2 CVEs

JRockit:R28.3.17

OTHER 1 CVE

7u131

OTHER 6 CVEs

Java SE:11.0.7, 14.0.1

OTHER 2 CVEs

10; Java SE Embedded:8u161

OTHER 2 CVEs

8u152

OTHER 13 CVEs

Java SE:7u141

OTHER 6 CVEs

Java Advanced Management Console:2.16

OTHER 1 CVE

8u121; Java SE Embedded:8u121

OTHER 2 CVEs

Java SE:8u251

OTHER 1 CVE

Java SE:7u221, 8u212, 11.0.3

OTHER 1 CVE

8u162; JRockit:R28.3.17

OTHER 1 CVE

Java SE:8u131; Java SE Embedded:8u131

OTHER 1 CVE

Java SE:8u144

OTHER 1 CVE

Java SE:8u131

OTHER 1 CVE

Java SE:8u212

OTHER 1 CVE

Java SE:6u151

OTHER 20 CVEs

9.0.1; Java SE Embedded:8u151

OTHER 5 CVEs

Java SE:7u181

OTHER 2 CVEs

Java Advanced Management Console:2.6

OTHER 4 CVEs

Java SE:7u151

OTHER 1 CVE

10.0.1; Java SE Embedded:8u171

OTHER 2 CVEs

10

SINGLE_NUMBER 2 CVEs

Java SE:7u171

OTHER 2 CVEs

Java SE:8u192

OTHER 1 CVE

Java SE:8u241, 11.0.6, 14

OTHER 2 CVEs

Java SE:6u171

OTHER 13 CVEs

Java SE:6u191

OTHER 4 CVEs

Java Advanced Management Console:2.8

OTHER 1 CVE

8u131; Java SE Embedded:8u131

OTHER 9 CVEs

Java SE:11.0.3, 12.0.1

OTHER 2 CVEs

JRockit:R28.3.19

OTHER 4 CVEs

7u181

OTHER 4 CVEs

Java SE:7u241, 8u231

OTHER 1 CVE

9.0.1

SEMANTIC 2 CVEs

Java SE:11.0.4, 13

OTHER 2 CVEs

7u161

OTHER 12 CVEs

Java SE:7u231, 8u221, 11.0.4, 13

OTHER 15 CVEs

Java SE:7u201, 8u192, 11.0.1

OTHER 2 CVEs

7u141

OTHER 20 CVEs

Java SE:8u172

OTHER 1 CVE

; Java SE Embedded:8u181

OTHER 1 CVE

7u151

OTHER 14 CVEs

Java SE Embedded:8u221

OTHER 16 CVEs

Java SE:8u221

OTHER 1 CVE

Java SE:10

OTHER 2 CVEs

9; Java SE Embedded:8u144; JRockit:R28.3.15

OTHER 5 CVEs

Java SE:11

OTHER 2 CVEs

Java SE:8u231

OTHER 1 CVE

Java SE:8u202

OTHER 1 CVE

Java SE:7u221, 8u212, 11.0.3, 12.0.1

OTHER 4 CVEs

Java SE Embedded:8u251

OTHER 8 CVEs

8u172

OTHER 6 CVEs

8u121; Java SE Embedded:8u121; JRockit:R28.3.13

OTHER 4 CVEs

Java SE:7u211, 8u202, 11.0.2, 12

OTHER 2 CVEs

Java SE:6u201, 7u191, 8u181, 11

OTHER 3 CVEs

Recent CVEs

CVE-2020-14664

Vulnerability in the Java SE product of Oracle Java SE (component: JavaFX). The supported version that is affected is Java SE: 8u251. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Java SE, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Java SE. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).

HIGH Jul 15, 2020

CVE-2020-14621

Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: JAXP). Supported versions that are affected are Java SE: 7u261, 8u251, 11.0.7 and 14.0.1; Java SE Embedded: 8u251. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Java SE, Java SE Embedded accessible data. Note: This vulnerability can only be exploited by supplying data to APIs in the specified Component without using Untrusted Java Web Start applications or Untrusted Java applets, such as through a web service. CVSS 3.1 Base Score 5.3 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N).

MEDIUM Jul 15, 2020

CVE-2020-14593

Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: 2D). Supported versions that are affected are Java SE: 7u261, 8u251, 11.0.7 and 14.0.1; Java SE Embedded: 8u251. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Java SE, Java SE Embedded, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Java SE, Java SE Embedded accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.1 Base Score 7.4 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N).

HIGH Jul 15, 2020

CVE-2020-14577

Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: JSSE). Supported versions that are affected are Java SE: 7u261, 8u251, 11.0.7 and 14.0.1; Java SE Embedded: 8u251. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TLS to compromise Java SE, Java SE Embedded. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Java SE, Java SE Embedded accessible data. Note: Applies to client and server deployment of Java. This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service. CVSS 3.1 Base Score 3.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N).

LOW Jul 15, 2020

CVE-2020-14583

Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 7u261, 8u251, 11.0.7 and 14.0.1; Java SE Embedded: 8u251. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Java SE, Java SE Embedded, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Java SE, Java SE Embedded. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).

HIGH Jul 15, 2020

CVE-2020-14579

Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 7u261 and 8u251; Java SE Embedded: 8u251. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE, Java SE Embedded. Note: Applies to client and server deployment of Java. This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service. CVSS 3.1 Base Score 3.7 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L).

LOW Jul 15, 2020

CVE-2020-14578

Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 7u261 and 8u251; Java SE Embedded: 8u251. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE, Java SE Embedded. Note: Applies to client and server deployment of Java. This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service. CVSS 3.1 Base Score 3.7 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L).

LOW Jul 15, 2020

CVE-2020-14581

Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: 2D). Supported versions that are affected are Java SE: 8u251, 11.0.7 and 14.0.1; Java SE Embedded: 8u251. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Java SE, Java SE Embedded accessible data. Note: Applies to client and server deployment of Java. This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service. CVSS 3.1 Base Score 3.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N).

LOW Jul 15, 2020

CVE-2020-14556

Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 8u251, 11.0.7 and 14.0.1; Java SE Embedded: 8u251. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Java SE, Java SE Embedded accessible data as well as unauthorized read access to a subset of Java SE, Java SE Embedded accessible data. Note: Applies to client and server deployment of Java. This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service. CVSS 3.1 Base Score 4.8 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N).

MEDIUM Jul 15, 2020