
CVE-2017-3289 – Oracle Java Uninitialized Memory Remote Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2017-3289
20 Jan 2017 — Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Hotspot). Supported versions that are affected are Java SE: 7u121 and 8u112; Java SE Embedded: 8u111. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Java SE, Java SE Embedded, attacks may significantly i... • http://rhn.redhat.com/errata/RHSA-2017-0175.html •

CVE-2017-3241 – Oracle OpenJDK Runtime Environment 1.8.0_112-b15 - Java Serialization Denial Of Service
https://notcve.org/view.php?id=CVE-2017-3241
20 Jan 2017 — Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: RMI). Supported versions that are affected are Java SE: 6u131, 7u121 and 8u112; Java SE Embedded: 8u111; JRockit: R28.3.12. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded, JRockit. While the vulnerability is in Java SE, Java SE Embedded, JRockit, attacks may significantly impact additional products. Successfu... • https://packetstorm.news/files/id/141104 • CWE-20: Improper Input Validation CWE-502: Deserialization of Untrusted Data •

CVE-2016-8328 – JDK: unspecified vulnerability fixed in 8u121 (Java Mission Control)
https://notcve.org/view.php?id=CVE-2016-8328
19 Jan 2017 — Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Java Mission Control). The supported version that is affected is Java SE: 8u112. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Java SE accessible data. Note: Applies to Java Mission Control Installation. • https://packetstorm.news/files/id/140606 •

CVE-2016-5568 – Oracle Java Runtime Environment java.awt.Menu Use-After-Free Remote Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2016-5568
25 Oct 2016 — Unspecified vulnerability in Oracle Java SE 6u121, 7u111, and 8u102 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to AWT. Vulnerabilidad no especificada en Oracle Java SE 6u121, 7u111 y 8u102 permite a atacantes remotos afectar a la confidencialidad, integridad y disponibilidad a través de vectores relacionados con AWT. This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Oracle Java. User interaction is requ... • http://www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.html • CWE-284: Improper Access Control •

CVE-2016-5556 – JDK: unspecified vulnerability fixed in 6u131, 7u121, and 8u111 (2D)
https://notcve.org/view.php?id=CVE-2016-5556
20 Oct 2016 — Unspecified vulnerability in Oracle Java SE 6u121, 7u111, and 8u102 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to 2D. Vulnerabilidad no especificada en Oracle Java SE 6u121, 7u111 y 8u102 permite a atacantes remotos afectar la confidencialidad, la integridad y la disponibilidad a través de vectores relacionados con 2D. Oracle Java SE version 8 includes the Oracle Java Runtime Environment and the Oracle Java Software Development Kit. This update upgrade... • http://rhn.redhat.com/errata/RHSA-2016-2088.html • CWE-284: Improper Access Control •

CVE-2016-5542 – OpenJDK: missing algorithm restrictions for jar verification (Libraries, 8155973)
https://notcve.org/view.php?id=CVE-2016-5542
19 Oct 2016 — Unspecified vulnerability in Oracle Java SE 6u121, 7u111, 8u102; and Java SE Embedded 8u101 allows remote attackers to affect integrity via vectors related to Libraries. Vulnerabilidad no especificada en Oracle Java SE 6u121, 7u111, 8u102 y Java SE Embedded 8u101 permite a atacantes remotos afectar a la integridad a través de vectores relacionados con Libraries. It was discovered that the Libraries component of OpenJDK did not restrict the set of algorithms used for JAR integrity verification. This flaw cou... • http://rhn.redhat.com/errata/RHSA-2016-2079.html • CWE-327: Use of a Broken or Risky Cryptographic Algorithm •

CVE-2016-5554 – OpenJDK: insufficient classloader consistency checks in ClassLoaderWithRepository (JMX, 8157739)
https://notcve.org/view.php?id=CVE-2016-5554
19 Oct 2016 — Unspecified vulnerability in Oracle Java SE 6u121, 7u111, 8u102; and Java SE Embedded 8u101 allows remote attackers to affect integrity via vectors related to JMX. Vulnerabilidad no especificada en Oracle Java SE 6u121, 7u111, 8u102 y Java SE Embedded 8u101 permite a atacantes remotos afectar a la integridad a través de vectores relacionados con JMX. A flaw was found in the way the JMX component of OpenJDK handled classloaders. An untrusted Java application or applet could use this flaw to bypass certain Ja... • http://rhn.redhat.com/errata/RHSA-2016-2079.html •

CVE-2016-5573 – OpenJDK: insufficient checks of JDWP packets (Hotspot, 8159519)
https://notcve.org/view.php?id=CVE-2016-5573
19 Oct 2016 — Unspecified vulnerability in Oracle Java SE 6u121, 7u111, 8u102; and Java SE Embedded 8u101 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Hotspot, a different vulnerability than CVE-2016-5582. Vulnerabilidad no especificada en Oracle Java SE 6u121, 7u111, 8u102 y Java SE Embedded 8u101 permite a atacantes remotos afectar la confidencialidad, la integridad y la disponibilidad a través de vectores relacionados con Hotspot, una vulnerabilidad diferente a ... • http://rhn.redhat.com/errata/RHSA-2016-2079.html • CWE-20: Improper Input Validation CWE-264: Permissions, Privileges, and Access Controls •

CVE-2016-5582 – OpenJDK: incomplete type checks of System.arraycopy arguments (Hotspot, 8160591)
https://notcve.org/view.php?id=CVE-2016-5582
19 Oct 2016 — Unspecified vulnerability in Oracle Java SE 6u121, 7u111, 8u102; and Java SE Embedded 8u101 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Hotspot, a different vulnerability than CVE-2016-5573. Vulnerabilidad no especificada en Oracle Java SE 6u121, 7u111, 8u102 y Java SE Embedded 8u101 permite a atacantes remotos afectar la confidencialidad, la integridad y la disponibilidad a través de vectores relacionados con Hotspot, una vulnerabilidad diferente a ... • http://rhn.redhat.com/errata/RHSA-2016-2079.html • CWE-284: Improper Access Control CWE-843: Access of Resource Using Incompatible Type ('Type Confusion') •

CVE-2016-5597 – OpenJDK: exposure of server authentication credentials to proxy (Networking, 8160838)
https://notcve.org/view.php?id=CVE-2016-5597
19 Oct 2016 — Unspecified vulnerability in Oracle Java SE 6u121, 7u111, 8u102; and Java SE Embedded 8u101 allows remote attackers to affect confidentiality via vectors related to Networking. Vulnerabilidad no especificada en Oracle Java SE 6u121, 7u111, 8u102 y Java SE Embedded 8u101 permite a atacantes remotos afectar la confidencialidad a través de vectores relacionados con Networking. A flaw was found in the way the Networking component of OpenJDK handled HTTP proxy authentication. A Java application could possibly ex... • http://rhn.redhat.com/errata/RHSA-2016-2079.html • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-319: Cleartext Transmission of Sensitive Information •