
CVE-2014-6504 – OpenJDK: incorrect optimization of range checks in C2 compiler (Hotspot, 8022783)
https://notcve.org/view.php?id=CVE-2014-6504
15 Oct 2014 — Unspecified vulnerability in Oracle Java SE 5.0u71, 6u81, and 7u67, and Java SE Embedded 7u60, allows remote attackers to affect confidentiality via unknown vectors related to Hotspot. Vulnerabilidad sin especificar en Oracle Java SE 5.0u71, 6u81, y 7u67, y Java SE Embedded 7u60, permite a atacantes remotos afectar a a la confidencialidad a través de vectores relacionados con Hotspot. The java-1.7.0-openjdk packages provide the OpenJDK 7 Java Runtime Environment and the OpenJDK 7 Java Software Development K... • http://linux.oracle.com/errata/ELSA-2014-1633.html •

CVE-2014-6506 – OpenJDK: insufficient permission checks when setting resource bundle on system logger (Libraries, 8041564)
https://notcve.org/view.php?id=CVE-2014-6506
15 Oct 2014 — Unspecified vulnerability in Oracle Java SE 5.0u71, 6u81, 7u67, and 8u20, and Java SE Embedded 7u60, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries. Vulnerabilidad sin especificar en Oracle Java SE 5.0u71, 6u81, 7u67, and 8u20, y Java SE Embedded 7u60, permite a atacantes remotos afectar la confidencialidad, la integridad y la disponibilidad a través de vectores relacionados con las librerías. The java-1.7.0-openjdk packages provide th... • http://linux.oracle.com/errata/ELSA-2014-1633.html •

CVE-2014-6511 – ICU: Layout Engine ContextualSubstitution missing boundary checks (JDK 2D, 8041540)
https://notcve.org/view.php?id=CVE-2014-6511
15 Oct 2014 — Unspecified vulnerability in Oracle Java SE 5.0u71, 6u81, 7u67, and 8u20 allows remote attackers to affect confidentiality via unknown vectors related to 2D. Vulnerabilidad sin especificar en Oracle Java SE 5.0u71, 6u81, 7u67, y 8u20 permite a atacantes remotos afectar la confidencialidad a través de vectores desconocidos relacionados con el 2D. The java-1.7.0-openjdk packages provide the OpenJDK 7 Java Runtime Environment and the OpenJDK 7 Java Software Development Kit. Multiple flaws were discovered in th... • http://linux.oracle.com/errata/ELSA-2014-1633.html •

CVE-2014-6512 – OpenJDK: DatagramSocket connected socket missing source check (Libraries, 8039509)
https://notcve.org/view.php?id=CVE-2014-6512
15 Oct 2014 — Unspecified vulnerability in Oracle Java SE 5.0u71, 6u81, 7u67, and 8u20; Java SE Embedded 7u60; and JRockit R27.8.3 and R28.3.3 allows remote attackers to affect integrity via unknown vectors related to Libraries. Vulnerabilidad sin especificar en Oracle Java SE 5.0u71, 6u81, 7u67, y 8u20; Java SE Embedded 7u60; y JRockit R27.8.3 y R28.3.3 permite a atacantes remotos afectar a la integridad a través de vectores relacionados con las librerías. It was discovered that the DatagramSocket implementation in Open... • http://linux.oracle.com/errata/ELSA-2014-1633.html • CWE-345: Insufficient Verification of Data Authenticity •

CVE-2014-6531 – OpenJDK: insufficient ResourceBundle name check (Libraries, 8044274)
https://notcve.org/view.php?id=CVE-2014-6531
15 Oct 2014 — Unspecified vulnerability in Oracle Java SE 5.0u71, 6u81, 7u67, and 8u20, and Java SE Embedded 7u60, allows remote attackers to affect confidentiality via unknown vectors related to Libraries. Vulnerabilidad sin especificar en Oracle Java SE 5.0u71, 6u81, 7u67, y 8u20, y Java SE Embedded 7u60, permite a atacantes remotos afectar a la confidencialidad a través de vectores relacionados con las librerías. The java-1.7.0-openjdk packages provide the OpenJDK 7 Java Runtime Environment and the OpenJDK 7 Java Soft... • http://linux.oracle.com/errata/ELSA-2014-1633.html •

CVE-2014-6558 – OpenJDK: CipherInputStream incorrect exception handling (Security, 8037846)
https://notcve.org/view.php?id=CVE-2014-6558
15 Oct 2014 — Unspecified vulnerability in Oracle Java SE 5.0u71, 6u81, 7u67, and 8u20; Java SE Embedded 7u60; and JRockit R27.8.3 and JRockit R28.3.3 allows remote attackers to affect integrity via unknown vectors related to Security. Vulnerabilidad sin especificar en Oracle Java SE 5.0u71, 6u81, 7u67, y 8u20; Java SE Embedded 7u60; y JRockit R27.8.3 y JRockit R28.3.3 permite a atacantes remotos afectar la integridad a través de vectores desconocidos relacionados con la seguridad. It was discovered that the CipherInputS... • http://linux.oracle.com/errata/ELSA-2014-1633.html •

CVE-2014-4268 – Debian Security Advisory 2987-1
https://notcve.org/view.php?id=CVE-2014-4268
17 Jul 2014 — Unspecified vulnerability in Oracle Java SE 5.0u65, 6u75, 7u60, and 8u5 allows remote attackers to affect confidentiality via unknown vectors related to Swing. Vulnerabilidad no especificada en Oracle Java SE 5.0u65, 6u75, 7u60, y 8u5 permite a atacantes remotos afectar a la confidencialidad a través de vectores desconocidos relacionados con Swing. Several vulnerabilities were discovered in the OpenJDK JRE related to information disclosure, data integrity and availability. An attacker could exploit these to... • http://lists.opensuse.org/opensuse-security-announce/2015-02/msg00026.html •

CVE-2014-4216 – OpenJDK: Incorrect generic signature attribute parsing (Hotspot, 8037076)
https://notcve.org/view.php?id=CVE-2014-4216
16 Jul 2014 — Unspecified vulnerability in Oracle Java SE 5.0u65, 6u75, 7u60, and 8u5 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Hotspot. Vulnerabilidad no especificada en Oracle Java SE 5.0u65, 6u75, 7u60 y 8u5 permite a atacantes remotos afectar la confidencialidad, integridad y disponibilidad a través de vectores desconocidos relacionados con Hotspot. It was discovered that the Hotspot component in OpenJDK did not properly verify bytecode from the clas... • http://marc.info/?l=bugtraq&m=140852886808946&w=2 •

CVE-2014-4209 – OpenJDK: SubjectDelegator protection insufficient (JMX, 8029755)
https://notcve.org/view.php?id=CVE-2014-4209
16 Jul 2014 — Unspecified vulnerability in Oracle Java SE 5.0u65, 6u75, 7u60, and 8u5 allows remote attackers to affect confidentiality and integrity via vectors related to JMX. Vulnerabilidad no especificada en Oracle Java SE 5.0u65, 6u75, 7u60 y 8u5 permite a atacantes remotos afecatr la confidencialidad e integridad a través de vectores relacionados con JMX. It was discovered that the Hotspot component in OpenJDK did not properly verify bytecode from the class files. An untrusted Java application or applet could possi... • http://lists.opensuse.org/opensuse-security-announce/2015-02/msg00026.html •

CVE-2014-4218 – OpenJDK: Clone interfaces passed to proxy methods (Libraries, 8035009)
https://notcve.org/view.php?id=CVE-2014-4218
16 Jul 2014 — Unspecified vulnerability in Oracle Java SE 5.0u65, 6u75, 7u60, and 8u5 allows remote attackers to affect integrity via unknown vectors related to Libraries. Vulnerabilidad no especificada en Oracle Java SE 5.0u65, 6u75, 7u60 y 8u5 permite a atacantes remotos afectar la integridad a través de vectores desconocidos relacionados con Libraries. It was discovered that the Hotspot component in OpenJDK did not properly verify bytecode from the class files. An untrusted Java application or applet could possibly us... • http://lists.opensuse.org/opensuse-security-announce/2015-02/msg00026.html •