
CVE-2016-5568 – Oracle Java Runtime Environment java.awt.Menu Use-After-Free Remote Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2016-5568
25 Oct 2016 — Unspecified vulnerability in Oracle Java SE 6u121, 7u111, and 8u102 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to AWT. Vulnerabilidad no especificada en Oracle Java SE 6u121, 7u111 y 8u102 permite a atacantes remotos afectar a la confidencialidad, integridad y disponibilidad a través de vectores relacionados con AWT. This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Oracle Java. User interaction is requ... • http://www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.html • CWE-284: Improper Access Control •

CVE-2016-5556 – JDK: unspecified vulnerability fixed in 6u131, 7u121, and 8u111 (2D)
https://notcve.org/view.php?id=CVE-2016-5556
20 Oct 2016 — Unspecified vulnerability in Oracle Java SE 6u121, 7u111, and 8u102 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to 2D. Vulnerabilidad no especificada en Oracle Java SE 6u121, 7u111 y 8u102 permite a atacantes remotos afectar la confidencialidad, la integridad y la disponibilidad a través de vectores relacionados con 2D. Oracle Java SE version 8 includes the Oracle Java Runtime Environment and the Oracle Java Software Development Kit. This update upgrade... • http://rhn.redhat.com/errata/RHSA-2016-2088.html • CWE-284: Improper Access Control •

CVE-2016-5542 – OpenJDK: missing algorithm restrictions for jar verification (Libraries, 8155973)
https://notcve.org/view.php?id=CVE-2016-5542
19 Oct 2016 — Unspecified vulnerability in Oracle Java SE 6u121, 7u111, 8u102; and Java SE Embedded 8u101 allows remote attackers to affect integrity via vectors related to Libraries. Vulnerabilidad no especificada en Oracle Java SE 6u121, 7u111, 8u102 y Java SE Embedded 8u101 permite a atacantes remotos afectar a la integridad a través de vectores relacionados con Libraries. It was discovered that the Libraries component of OpenJDK did not restrict the set of algorithms used for JAR integrity verification. This flaw cou... • http://rhn.redhat.com/errata/RHSA-2016-2079.html • CWE-327: Use of a Broken or Risky Cryptographic Algorithm •

CVE-2016-5554 – OpenJDK: insufficient classloader consistency checks in ClassLoaderWithRepository (JMX, 8157739)
https://notcve.org/view.php?id=CVE-2016-5554
19 Oct 2016 — Unspecified vulnerability in Oracle Java SE 6u121, 7u111, 8u102; and Java SE Embedded 8u101 allows remote attackers to affect integrity via vectors related to JMX. Vulnerabilidad no especificada en Oracle Java SE 6u121, 7u111, 8u102 y Java SE Embedded 8u101 permite a atacantes remotos afectar a la integridad a través de vectores relacionados con JMX. A flaw was found in the way the JMX component of OpenJDK handled classloaders. An untrusted Java application or applet could use this flaw to bypass certain Ja... • http://rhn.redhat.com/errata/RHSA-2016-2079.html •

CVE-2016-5573 – OpenJDK: insufficient checks of JDWP packets (Hotspot, 8159519)
https://notcve.org/view.php?id=CVE-2016-5573
19 Oct 2016 — Unspecified vulnerability in Oracle Java SE 6u121, 7u111, 8u102; and Java SE Embedded 8u101 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Hotspot, a different vulnerability than CVE-2016-5582. Vulnerabilidad no especificada en Oracle Java SE 6u121, 7u111, 8u102 y Java SE Embedded 8u101 permite a atacantes remotos afectar la confidencialidad, la integridad y la disponibilidad a través de vectores relacionados con Hotspot, una vulnerabilidad diferente a ... • http://rhn.redhat.com/errata/RHSA-2016-2079.html • CWE-20: Improper Input Validation CWE-264: Permissions, Privileges, and Access Controls •

CVE-2016-5582 – OpenJDK: incomplete type checks of System.arraycopy arguments (Hotspot, 8160591)
https://notcve.org/view.php?id=CVE-2016-5582
19 Oct 2016 — Unspecified vulnerability in Oracle Java SE 6u121, 7u111, 8u102; and Java SE Embedded 8u101 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Hotspot, a different vulnerability than CVE-2016-5573. Vulnerabilidad no especificada en Oracle Java SE 6u121, 7u111, 8u102 y Java SE Embedded 8u101 permite a atacantes remotos afectar la confidencialidad, la integridad y la disponibilidad a través de vectores relacionados con Hotspot, una vulnerabilidad diferente a ... • http://rhn.redhat.com/errata/RHSA-2016-2079.html • CWE-284: Improper Access Control CWE-843: Access of Resource Using Incompatible Type ('Type Confusion') •

CVE-2016-5597 – OpenJDK: exposure of server authentication credentials to proxy (Networking, 8160838)
https://notcve.org/view.php?id=CVE-2016-5597
19 Oct 2016 — Unspecified vulnerability in Oracle Java SE 6u121, 7u111, 8u102; and Java SE Embedded 8u101 allows remote attackers to affect confidentiality via vectors related to Networking. Vulnerabilidad no especificada en Oracle Java SE 6u121, 7u111, 8u102 y Java SE Embedded 8u101 permite a atacantes remotos afectar la confidencialidad a través de vectores relacionados con Networking. A flaw was found in the way the Networking component of OpenJDK handled HTTP proxy authentication. A Java application could possibly ex... • http://rhn.redhat.com/errata/RHSA-2016-2079.html • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-319: Cleartext Transmission of Sensitive Information •

CVE-2016-3485 – Gentoo Linux Security Advisory 201701-43
https://notcve.org/view.php?id=CVE-2016-3485
21 Jul 2016 — Unspecified vulnerability in Oracle Java SE 6u115, 7u101, and 8u92; Java SE Embedded 8u91; and JRockit R28.3.10 allows local users to affect integrity via vectors related to Networking. Vulnerabilidad no especificada en Oracle Java SE 6u115, 7u101 y 8u92; Java SE Embedded 8u91 y JRockit R28.3.10 permite a usuarios locales afectar la integridad a través de vectores relacionados con Networking. Multiple vulnerabilities have been found in Oracle's JRE and JDK software suites allowing remote attackers to remote... • http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00011.html •

CVE-2016-3508 – OpenJDK: missing entity replacement limits (JAXP, 8149962)
https://notcve.org/view.php?id=CVE-2016-3508
21 Jul 2016 — Unspecified vulnerability in Oracle Java SE 6u115, 7u101, and 8u92; Java SE Embedded 8u91; and JRockit R28.3.10 allows remote attackers to affect availability via vectors related to JAXP, a different vulnerability than CVE-2016-3500. Vulnerabilidad no especificada en Oracle Java SE 6u115, 7u101 y 8u92; Java SE Embedded 8u91 y JRockit R28.3.10 permite a atacantes remotos afectar la disponibilidad a través de vectores relacionados con JAXP, una vulnerabilidad diferente a CVE-2016-3500. The java-1.6.0-openjdk ... • http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00011.html • CWE-770: Allocation of Resources Without Limits or Throttling •

CVE-2016-3550 – OpenJDK: integer overflows in bytecode streams (Hotspot, 8152479)
https://notcve.org/view.php?id=CVE-2016-3550
21 Jul 2016 — Unspecified vulnerability in Oracle Java SE 6u115, 7u101, and 8u92 and Java SE Embedded 8u91 allows remote attackers to affect confidentiality via vectors related to Hotspot. Vulnerabilidad en Oracle Java SE 6u115, 7u101 y 8u92 y Java SE Embedded 8u91 permite a atacantes remotos afectar la confidencialidad a través de vectores relacionados con Hotspot. The java-1.6.0-openjdk packages provide the OpenJDK 6 Java Runtime Environment and the OpenJDK 6 Java Software Development Kit. Security Fix: An insufficient... • http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00011.html • CWE-190: Integer Overflow or Wraparound •