
CVE-2013-1475 – OpenJDK: IIOP type reuse sandbox bypass (CORBA, 8000540, SE-2012-01 Issue 50)
https://notcve.org/view.php?id=CVE-2013-1475
02 Feb 2013 — Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, 5.0 through Update 38, and 1.4.2_40 and earlier, and OpenJDK 6 and 7, allows remote attackers to affect confidentiality, integrity, and availability via vectors related to CORBA. NOTE: the previous information is from the February 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to "IIOP type reuse management" in ObjectStreamClass.ja... • http://icedtea.classpath.org/hg/release/icedtea6-1.11/file/icedtea6-1.11.6/NEWS •

CVE-2013-1476 – OpenJDK: missing ValueHandlerImpl class constructor access restriction (CORBA, 8000631)
https://notcve.org/view.php?id=CVE-2013-1476
02 Feb 2013 — Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, 5.0 through Update 38, and 1.4.2_40 and earlier, and OpenJDK 6 and 7, allows remote attackers to affect confidentiality, integrity, and availability via vectors related to CORBA, a different vulnerability than CVE-2013-0441 and CVE-2013-1475. NOTE: the previous information is from the February 2013 CPU. Oracle has not commented on claims from another vendor that this issue al... • http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=907457 •

CVE-2013-1478 – OpenJDK: image parser insufficient raster parameter checks (2D, 8001972)
https://notcve.org/view.php?id=CVE-2013-1478
02 Feb 2013 — Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, 5.0 through Update 38, and 1.4.2_40 and earlier, and OpenJDK 6 and 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D. NOTE: the previous information is from the February 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to "insufficient validation of raster parameters" ... • https://packetstorm.news/files/id/120084 •

CVE-2013-1481 – Oracle Java PV_ProcessSampleWithSMOD Remote Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2013-1481
02 Feb 2013 — Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 6 through Update 38, 5.0 through Update 38, and 1.4.2_40 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Sound. Vulnerabilidad no especificada en el componente Java Runtime Environment (JRE) en Oracle Java SE 6 hasta la actualización 38, 5,0 hasta la actualización 38 y v1.4.2_40 y anteriores permite a atacantes remotos para afectar la confidenc... • http://lists.opensuse.org/opensuse-security-announce/2013-03/msg00034.html •

CVE-2013-1480 – Oracle Java AWT Image Transform Remote Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2013-1480
02 Feb 2013 — Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, 5.0 through Update 38, and 1.4.2_40 and earlier, and OpenJDK 6 and 7, allows remote attackers to affect confidentiality, integrity, and availability via vectors related to AWT. NOTE: the previous information is from the February 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to "insufficient validation of raster parameters" in awt_... • https://packetstorm.news/files/id/120084 •

CVE-2012-5373
https://notcve.org/view.php?id=CVE-2012-5373
28 Nov 2012 — Oracle Java SE 7 and earlier, and OpenJDK 7 and earlier, computes hash values without properly restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table, as demonstrated by a universal multicollision attack against the MurmurHash3 algorithm, a different vulnerability than CVE-2012-2739. Oracle Java SE 7 y anteriores, y OpenJDK 7 y anteriores, calcula l... • http://2012.appsec-forum.ch/conferences/#c17 • CWE-310: Cryptographic Issues •

CVE-2012-2739
https://notcve.org/view.php?id=CVE-2012-2739
28 Nov 2012 — Oracle Java SE before 7 Update 6, and OpenJDK 7 before 7u6 build 12 and 8 before build 39, computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table. Oracle Java SE anteriores a 7 Update 6, y OpenJDK 7 anteriores a 7u6 build 12 y 8 anteriores a build 39, calculan los valores de hash sin restringir la posibilidad de provocar... • http://armoredbarista.blogspot.de/2012/02/investigating-hashdos-issue.html • CWE-310: Cryptographic Issues •

CVE-2012-5067 – Java Applet - JAX-WS Remote Code Execution
https://notcve.org/view.php?id=CVE-2012-5067
16 Oct 2012 — Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier allows remote attackers to affect confidentiality via unknown vectors related to Deployment. Una vulnerabilidad no especificada en el componente Java Runtime Environment (JRE) en Oracle Java SE v7 Update 7 y versiones anteriores, permite a atacantes remotos afectar la confidencialidad a través de vectores desconocidos relacionados con el "Deployment". Oracle Java SE version 7 includes the Oracl... • https://www.exploit-db.com/exploits/22657 •

CVE-2012-5070 – OpenJDK: EnvHelp information disclosure (JMX, 7158796)
https://notcve.org/view.php?id=CVE-2012-5070
16 Oct 2012 — Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier allows remote attackers to affect confidentiality, related to JMX. Una vulnerabilidad no especificada en el componente Java Runtime Environment (JRE) en Oracle Java SE v7 Update 7 permite a atacantes remotos afectar la confidencialidad a través de vectores desconocidos relacionados con JMX. These packages provide the OpenJDK 7 Java Runtime Environment and the OpenJDK 7 Software Development Kit.... • http://lists.opensuse.org/opensuse-security-announce/2012-10/msg00016.html •

CVE-2012-5074 – OpenJDK: com.sun.org.glassfish.* not restricted packages (JAX-WS, 7169887)
https://notcve.org/view.php?id=CVE-2012-5074
16 Oct 2012 — Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier allows remote attackers to affect confidentiality and integrity, related to JAX-WS. Una vulnerabilidad no especificada en el componente Java Runtime Environment (JRE) en Oracle Java SE v7 Update 7 y versiones anteriores permite a atacantes remotos afectar la confidencialidad y la integridad. Se trata de un problema relacionado con JAX-WS. These packages provide the OpenJDK 7 Java Runtime Enviro... • http://lists.opensuse.org/opensuse-security-announce/2012-10/msg00016.html •