
CVE-2014-6512 – OpenJDK: DatagramSocket connected socket missing source check (Libraries, 8039509)
https://notcve.org/view.php?id=CVE-2014-6512
15 Oct 2014 — Unspecified vulnerability in Oracle Java SE 5.0u71, 6u81, 7u67, and 8u20; Java SE Embedded 7u60; and JRockit R27.8.3 and R28.3.3 allows remote attackers to affect integrity via unknown vectors related to Libraries. Vulnerabilidad sin especificar en Oracle Java SE 5.0u71, 6u81, 7u67, y 8u20; Java SE Embedded 7u60; y JRockit R27.8.3 y R28.3.3 permite a atacantes remotos afectar a la integridad a través de vectores relacionados con las librerías. It was discovered that the DatagramSocket implementation in Open... • http://linux.oracle.com/errata/ELSA-2014-1633.html • CWE-345: Insufficient Verification of Data Authenticity •

CVE-2014-6506 – OpenJDK: insufficient permission checks when setting resource bundle on system logger (Libraries, 8041564)
https://notcve.org/view.php?id=CVE-2014-6506
15 Oct 2014 — Unspecified vulnerability in Oracle Java SE 5.0u71, 6u81, 7u67, and 8u20, and Java SE Embedded 7u60, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries. Vulnerabilidad sin especificar en Oracle Java SE 5.0u71, 6u81, 7u67, and 8u20, y Java SE Embedded 7u60, permite a atacantes remotos afectar la confidencialidad, la integridad y la disponibilidad a través de vectores relacionados con las librerías. The java-1.7.0-openjdk packages provide th... • http://linux.oracle.com/errata/ELSA-2014-1633.html •

CVE-2014-6457 – OpenJDK: Triple Handshake attack against TLS/SSL connections (JSSE, 8037066)
https://notcve.org/view.php?id=CVE-2014-6457
15 Oct 2014 — Unspecified vulnerability in Oracle Java SE 5.0u71, 6u81, 7u67, and 8u20; Java SE Embedded 7u60; and JRockit R27.8.3, and R28.3.3 allows remote attackers to affect confidentiality and integrity via vectors related to JSSE. Vulnerabilidad sin especificar en Oracle Java SE 5.0u71, 6u81, 7u67, y 8u20; Java SE Embedded 7u60; y JRockit R27.8.3, y R28.3.3 permite a atacantes remotos afectar la confidencialidad y la integridad a través de vectores relacionados con JSSE. It was discovered that the TLS/SSL implement... • http://linux.oracle.com/errata/ELSA-2014-1633.html •

CVE-2014-6502 – OpenJDK: LogRecord use of incorrect CL when loading ResourceBundle (Libraries, 8042797)
https://notcve.org/view.php?id=CVE-2014-6502
15 Oct 2014 — Unspecified vulnerability in Oracle Java SE 5.0u71, 6u81, 7u67, and 8u20, and Java SE Embedded 7u60, allows remote attackers to affect integrity via unknown vectors related to Libraries. Vulnerabilidad sin especificar en Oracle Java SE 5.0u71, 6u81, 7u67 y 8u20, y Java SE Embedded 7u60, permite a atacantes remotos afectar la confidencialidad a través de vectores relacionados con las librerías. The java-1.7.0-openjdk packages provide the OpenJDK 7 Java Runtime Environment and the OpenJDK 7 Java Software Deve... • http://linux.oracle.com/errata/ELSA-2014-1633.html •

CVE-2014-6511 – ICU: Layout Engine ContextualSubstitution missing boundary checks (JDK 2D, 8041540)
https://notcve.org/view.php?id=CVE-2014-6511
15 Oct 2014 — Unspecified vulnerability in Oracle Java SE 5.0u71, 6u81, 7u67, and 8u20 allows remote attackers to affect confidentiality via unknown vectors related to 2D. Vulnerabilidad sin especificar en Oracle Java SE 5.0u71, 6u81, 7u67, y 8u20 permite a atacantes remotos afectar la confidencialidad a través de vectores desconocidos relacionados con el 2D. The java-1.7.0-openjdk packages provide the OpenJDK 7 Java Runtime Environment and the OpenJDK 7 Java Software Development Kit. Multiple flaws were discovered in th... • http://linux.oracle.com/errata/ELSA-2014-1633.html •

CVE-2014-6558 – OpenJDK: CipherInputStream incorrect exception handling (Security, 8037846)
https://notcve.org/view.php?id=CVE-2014-6558
15 Oct 2014 — Unspecified vulnerability in Oracle Java SE 5.0u71, 6u81, 7u67, and 8u20; Java SE Embedded 7u60; and JRockit R27.8.3 and JRockit R28.3.3 allows remote attackers to affect integrity via unknown vectors related to Security. Vulnerabilidad sin especificar en Oracle Java SE 5.0u71, 6u81, 7u67, y 8u20; Java SE Embedded 7u60; y JRockit R27.8.3 y JRockit R28.3.3 permite a atacantes remotos afectar la integridad a través de vectores desconocidos relacionados con la seguridad. It was discovered that the CipherInputS... • http://linux.oracle.com/errata/ELSA-2014-1633.html •

CVE-2014-4268 – Debian Security Advisory 2987-1
https://notcve.org/view.php?id=CVE-2014-4268
17 Jul 2014 — Unspecified vulnerability in Oracle Java SE 5.0u65, 6u75, 7u60, and 8u5 allows remote attackers to affect confidentiality via unknown vectors related to Swing. Vulnerabilidad no especificada en Oracle Java SE 5.0u65, 6u75, 7u60, y 8u5 permite a atacantes remotos afectar a la confidencialidad a través de vectores desconocidos relacionados con Swing. Several vulnerabilities were discovered in the OpenJDK JRE related to information disclosure, data integrity and availability. An attacker could exploit these to... • http://lists.opensuse.org/opensuse-security-announce/2015-02/msg00026.html •

CVE-2014-4218 – OpenJDK: Clone interfaces passed to proxy methods (Libraries, 8035009)
https://notcve.org/view.php?id=CVE-2014-4218
16 Jul 2014 — Unspecified vulnerability in Oracle Java SE 5.0u65, 6u75, 7u60, and 8u5 allows remote attackers to affect integrity via unknown vectors related to Libraries. Vulnerabilidad no especificada en Oracle Java SE 5.0u65, 6u75, 7u60 y 8u5 permite a atacantes remotos afectar la integridad a través de vectores desconocidos relacionados con Libraries. It was discovered that the Hotspot component in OpenJDK did not properly verify bytecode from the class files. An untrusted Java application or applet could possibly us... • http://lists.opensuse.org/opensuse-security-announce/2015-02/msg00026.html •

CVE-2014-4244 – OpenJDK: RSA blinding issues (Security, 8031346)
https://notcve.org/view.php?id=CVE-2014-4244
16 Jul 2014 — Unspecified vulnerability in Oracle Java SE 5.0u65, 6u75, 7u60, and 8u5, and JRockit R27.8.2 and JRockit R28.3.2, allows remote attackers to affect confidentiality and integrity via unknown vectors related to Security. Vulnerabilidad no especificada en Oracle Java SE 5.0u65, 6u75, 7u60, y 8u5, y JRockit R27.8.2 y JRockit R28.3.2, permite a atacantes remotos afectar la confidencialidad e integridad a través de vectores desconocidos relacionados con Security. It was discovered that the Hotspot component in Op... • http://lists.opensuse.org/opensuse-security-announce/2015-02/msg00026.html •

CVE-2014-4209 – OpenJDK: SubjectDelegator protection insufficient (JMX, 8029755)
https://notcve.org/view.php?id=CVE-2014-4209
16 Jul 2014 — Unspecified vulnerability in Oracle Java SE 5.0u65, 6u75, 7u60, and 8u5 allows remote attackers to affect confidentiality and integrity via vectors related to JMX. Vulnerabilidad no especificada en Oracle Java SE 5.0u65, 6u75, 7u60 y 8u5 permite a atacantes remotos afecatr la confidencialidad e integridad a través de vectores relacionados con JMX. It was discovered that the Hotspot component in OpenJDK did not properly verify bytecode from the class files. An untrusted Java application or applet could possi... • http://lists.opensuse.org/opensuse-security-announce/2015-02/msg00026.html •