
CVE-2014-6593 – JSSE - SKIP-TLS
https://notcve.org/view.php?id=CVE-2014-6593
21 Jan 2015 — Unspecified vulnerability in Oracle Java SE 5.0u75, 6u85, 7u72, and 8u25; Java SE Embedded 7u71 and 8u6; and JRockit 27.8.4 and 28.3.4 allows remote attackers to affect confidentiality and integrity via vectors related to JSSE. Vulnerabilidad no especificada en Oracle Java SE 5.0u75, 6u85, 7u72, y 8u25; Java SE Embedded 7u71 y 8u6; y JRockit 27.8.4 y 28.3.4 permite a atacantes remotos afectar la confidencialidad e integridad a través de vectores relacionados con JSSE. It was discovered that the SSL/TLS impl... • https://packetstorm.news/files/id/133054 • CWE-372: Incomplete Internal State Distinction •

CVE-2015-0410 – OpenJDK: DER decoder infinite loop (Security, 8059485)
https://notcve.org/view.php?id=CVE-2015-0410
21 Jan 2015 — Unspecified vulnerability in the Java SE, Java SE Embedded, JRockit component in Oracle Java SE 5.0u75, 6u85, 7u72, and 8u25; Java SE Embedded 7u71 and 8u6; and JRockit R27.8.4 and R28.3.4 allows remote attackers to affect availability via unknown vectors related to Security. Vulnerabilidad no especificada en el componente Java SE, Java SE Embedded, JRockit en Oracle Java SE 5.0u75, 6u85, 7u72, y 8u25; Java SE Embedded 7u71 y 8u6; y JRockit R27.8.4 y R28.3.4 permite a atacantes remotos afectar la disponibil... • http://h20564.www2.hp.com/hpsc/doc/public/display?docId=emr_na-c04583581 • CWE-835: Loop with Unreachable Exit Condition ('Infinite Loop') •

CVE-2014-6457 – OpenJDK: Triple Handshake attack against TLS/SSL connections (JSSE, 8037066)
https://notcve.org/view.php?id=CVE-2014-6457
15 Oct 2014 — Unspecified vulnerability in Oracle Java SE 5.0u71, 6u81, 7u67, and 8u20; Java SE Embedded 7u60; and JRockit R27.8.3, and R28.3.3 allows remote attackers to affect confidentiality and integrity via vectors related to JSSE. Vulnerabilidad sin especificar en Oracle Java SE 5.0u71, 6u81, 7u67, y 8u20; Java SE Embedded 7u60; y JRockit R27.8.3, y R28.3.3 permite a atacantes remotos afectar la confidencialidad y la integridad a través de vectores relacionados con JSSE. It was discovered that the TLS/SSL implement... • http://linux.oracle.com/errata/ELSA-2014-1633.html •

CVE-2014-6502 – OpenJDK: LogRecord use of incorrect CL when loading ResourceBundle (Libraries, 8042797)
https://notcve.org/view.php?id=CVE-2014-6502
15 Oct 2014 — Unspecified vulnerability in Oracle Java SE 5.0u71, 6u81, 7u67, and 8u20, and Java SE Embedded 7u60, allows remote attackers to affect integrity via unknown vectors related to Libraries. Vulnerabilidad sin especificar en Oracle Java SE 5.0u71, 6u81, 7u67 y 8u20, y Java SE Embedded 7u60, permite a atacantes remotos afectar la confidencialidad a través de vectores relacionados con las librerías. The java-1.7.0-openjdk packages provide the OpenJDK 7 Java Runtime Environment and the OpenJDK 7 Java Software Deve... • http://linux.oracle.com/errata/ELSA-2014-1633.html •

CVE-2014-6504 – OpenJDK: incorrect optimization of range checks in C2 compiler (Hotspot, 8022783)
https://notcve.org/view.php?id=CVE-2014-6504
15 Oct 2014 — Unspecified vulnerability in Oracle Java SE 5.0u71, 6u81, and 7u67, and Java SE Embedded 7u60, allows remote attackers to affect confidentiality via unknown vectors related to Hotspot. Vulnerabilidad sin especificar en Oracle Java SE 5.0u71, 6u81, y 7u67, y Java SE Embedded 7u60, permite a atacantes remotos afectar a a la confidencialidad a través de vectores relacionados con Hotspot. The java-1.7.0-openjdk packages provide the OpenJDK 7 Java Runtime Environment and the OpenJDK 7 Java Software Development K... • http://linux.oracle.com/errata/ELSA-2014-1633.html •

CVE-2014-6506 – OpenJDK: insufficient permission checks when setting resource bundle on system logger (Libraries, 8041564)
https://notcve.org/view.php?id=CVE-2014-6506
15 Oct 2014 — Unspecified vulnerability in Oracle Java SE 5.0u71, 6u81, 7u67, and 8u20, and Java SE Embedded 7u60, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries. Vulnerabilidad sin especificar en Oracle Java SE 5.0u71, 6u81, 7u67, and 8u20, y Java SE Embedded 7u60, permite a atacantes remotos afectar la confidencialidad, la integridad y la disponibilidad a través de vectores relacionados con las librerías. The java-1.7.0-openjdk packages provide th... • http://linux.oracle.com/errata/ELSA-2014-1633.html •

CVE-2014-6511 – ICU: Layout Engine ContextualSubstitution missing boundary checks (JDK 2D, 8041540)
https://notcve.org/view.php?id=CVE-2014-6511
15 Oct 2014 — Unspecified vulnerability in Oracle Java SE 5.0u71, 6u81, 7u67, and 8u20 allows remote attackers to affect confidentiality via unknown vectors related to 2D. Vulnerabilidad sin especificar en Oracle Java SE 5.0u71, 6u81, 7u67, y 8u20 permite a atacantes remotos afectar la confidencialidad a través de vectores desconocidos relacionados con el 2D. The java-1.7.0-openjdk packages provide the OpenJDK 7 Java Runtime Environment and the OpenJDK 7 Java Software Development Kit. Multiple flaws were discovered in th... • http://linux.oracle.com/errata/ELSA-2014-1633.html •

CVE-2014-6512 – OpenJDK: DatagramSocket connected socket missing source check (Libraries, 8039509)
https://notcve.org/view.php?id=CVE-2014-6512
15 Oct 2014 — Unspecified vulnerability in Oracle Java SE 5.0u71, 6u81, 7u67, and 8u20; Java SE Embedded 7u60; and JRockit R27.8.3 and R28.3.3 allows remote attackers to affect integrity via unknown vectors related to Libraries. Vulnerabilidad sin especificar en Oracle Java SE 5.0u71, 6u81, 7u67, y 8u20; Java SE Embedded 7u60; y JRockit R27.8.3 y R28.3.3 permite a atacantes remotos afectar a la integridad a través de vectores relacionados con las librerías. It was discovered that the DatagramSocket implementation in Open... • http://linux.oracle.com/errata/ELSA-2014-1633.html • CWE-345: Insufficient Verification of Data Authenticity •

CVE-2014-6531 – OpenJDK: insufficient ResourceBundle name check (Libraries, 8044274)
https://notcve.org/view.php?id=CVE-2014-6531
15 Oct 2014 — Unspecified vulnerability in Oracle Java SE 5.0u71, 6u81, 7u67, and 8u20, and Java SE Embedded 7u60, allows remote attackers to affect confidentiality via unknown vectors related to Libraries. Vulnerabilidad sin especificar en Oracle Java SE 5.0u71, 6u81, 7u67, y 8u20, y Java SE Embedded 7u60, permite a atacantes remotos afectar a la confidencialidad a través de vectores relacionados con las librerías. The java-1.7.0-openjdk packages provide the OpenJDK 7 Java Runtime Environment and the OpenJDK 7 Java Soft... • http://linux.oracle.com/errata/ELSA-2014-1633.html •

CVE-2014-6558 – OpenJDK: CipherInputStream incorrect exception handling (Security, 8037846)
https://notcve.org/view.php?id=CVE-2014-6558
15 Oct 2014 — Unspecified vulnerability in Oracle Java SE 5.0u71, 6u81, 7u67, and 8u20; Java SE Embedded 7u60; and JRockit R27.8.3 and JRockit R28.3.3 allows remote attackers to affect integrity via unknown vectors related to Security. Vulnerabilidad sin especificar en Oracle Java SE 5.0u71, 6u81, 7u67, y 8u20; Java SE Embedded 7u60; y JRockit R27.8.3 y JRockit R28.3.3 permite a atacantes remotos afectar la integridad a través de vectores desconocidos relacionados con la seguridad. It was discovered that the CipherInputS... • http://linux.oracle.com/errata/ELSA-2014-1633.html •