![](/assets/img/cve_300x82_sin_bg.png)
CVE-2014-0411 – OpenJDK: TLS/SSL handshake timing issues (JSSE, 8023069)
https://notcve.org/view.php?id=CVE-2014-0411
15 Jan 2014 — Unspecified vulnerability in Oracle Java SE 5.0u55, 6u65, and 7u45; JRockit R27.7.7 and R28.2.9; Java SE Embedded 7u45; and OpenJDK 7 allows remote attackers to affect confidentiality and integrity via vectors related to JSSE. NOTE: the previous information is from the January 2014 CPU. Oracle has not commented on third-party claims that this issue allows remote attackers to obtain sensitive information about encryption keys via a timing discrepancy during the TLS/SSL handshake. Vulnerabilidad no especifica... • http://hg.openjdk.java.net/jdk7u/jdk7u/jdk/rev/d533e96c7acc •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2014-0368 – OpenJDK: insufficient Socket checkListen checks (Networking, 8011786)
https://notcve.org/view.php?id=CVE-2014-0368
15 Jan 2014 — Unspecified vulnerability in Oracle Java SE 5.0u55, 6u65, and 7u45, and Java SE Embedded 7u45, allows remote attackers to affect confidentiality via unknown vectors related to Networking. NOTE: the previous information is from the January 2014 CPU. Oracle has not commented on third-party claims that the issue is related to incorrect permission checks when listening on a socket, which allows attackers to escape the sandbox. Vulnerabilidad no especificada en Oracle Java SE 5.0u55, 6u65 y 7u45, y Java SE Embed... • http://hg.openjdk.java.net/jdk7u/jdk7u/jdk/rev/e6160aedadd5 •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2013-5896 – OpenJDK: com.sun.corba.se. should be restricted package (CORBA, 8025022)
https://notcve.org/view.php?id=CVE-2013-5896
15 Jan 2014 — Unspecified vulnerability in Oracle Java SE 5.0u55, 6u65, and 7u45; Java SE Embedded 7u45; and OpenJDK 7 allows remote attackers to affect availability via vectors related to CORBA. NOTE: the previous information is from the January 2014 CPU. Oracle has not commented on third-party claims that com.sun.corba.se and its sub-packages are not included on the restricted package list. Vulnerabilidad no especificada en Oracle Java SE 5.0u55, 6u64 y 7u45; y Java SE Embedded 7u45; permite a atacantes remotos afectar... • http://hg.openjdk.java.net/jdk7u/jdk7u/jdk/rev/694ad155b344 •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2014-0428 – OpenJDK: insufficient security checks in IIOP streams (CORBA, 8025767)
https://notcve.org/view.php?id=CVE-2014-0428
15 Jan 2014 — Unspecified vulnerability in Oracle Java SE 5.0u55, 6u65, and 7u45; Java SE Embedded 7u45; and OpenJDK 7 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to CORBA. NOTE: the previous information is from the January 2014 CPU. Oracle has not commented on third-party claims that the issue is related to "insufficient security checks in IIOP streams," which allows attackers to escape the sandbox. Vulnerabilidad no especificada en Oracle Java SE 5.0u55, 6u65 y 7u4... • http://hg.openjdk.java.net/jdk7u/jdk7u/corba/rev/0a879f00b698 •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2014-0373 – OpenJDK: SnmpStatusException handling issues (Serviceability, 7068126)
https://notcve.org/view.php?id=CVE-2014-0373
15 Jan 2014 — Unspecified vulnerability in Oracle Java SE 5.0u55, 6u65, and 7u45, and OpenJDK 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Serviceability. NOTE: the previous information is from the January 2014 CPU. Oracle has not commented on third-party claims that the issue is related to throwing of an incorrect exception when SnmpStatusException should have been used in the SNMP implementation, which allows attackers to escape the sandbox. Vulnerabil... • http://hg.openjdk.java.net/jdk7u/jdk7u/jdk/rev/496c51673dec •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2013-5851 – OpenJDK: XML stream factory finder information leak (JAXP, 8013502)
https://notcve.org/view.php?id=CVE-2013-5851
16 Oct 2013 — Unspecified vulnerability in Oracle Java SE 7u40 and earlier and Java SE Embedded 7u40 and earlier allows remote attackers to affect confidentiality via vectors related to JAXP. Vulnerabilidad no especificada en Oracle Java SE v7u40 y anteriores, y Java SE Embedded v7u40 y anteriores permite a atacantes remotos afectar a la confidencialidad a través de vectores relacionados con JAXP. The java-1.7.0-openjdk packages provide the OpenJDK 7 Java Runtime Environment and the OpenJDK 7 Java Software Development Ki... • http://lists.opensuse.org/opensuse-security-announce/2013-11/msg00010.html •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2013-5852 – JDK: unspecified vulnerability fixed in 7u45 (Deployment)
https://notcve.org/view.php?id=CVE-2013-5852
16 Oct 2013 — Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, and Java SE Embedded 7u40 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment, a different vulnerability than CVE-2013-5787, CVE-2013-5789, CVE-2013-5824, and CVE-2013-5832. Vulnerabilidad no especificada en Oracle Java SE 7u40 y versiones anteriores, Java SE 6u60 y versiones anteriores y Java SE Embedded 7u40 y versiones anteriores permite ... • http://marc.info/?l=bugtraq&m=138674031212883&w=2 •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2013-5854 – JDK: multiple unspecified vulnerabilities fixed in 7u45 (JavaFX)
https://notcve.org/view.php?id=CVE-2013-5854
16 Oct 2013 — Unspecified vulnerability in Oracle Java SE 7u40 and earlier and JavaFX 2.2.40 and earlier allows remote attackers to affect confidentiality via unknown vectors. Vulnerabilidad no especificada en Oracle Java SE v7u40 y anteriores, y JavaFX v2.2.40 y anteriores permite a atacantes remotos afectar a la confidencialidad a través de vectores desconocidos. Oracle Java SE version 7 includes the Oracle Java Runtime Environment and the Oracle Java Software Development Kit. This update fixes several vulnerabilities ... • http://marc.info/?l=bugtraq&m=138674073720143&w=2 •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2013-5840 – OpenJDK: getDeclaringClass() information leak (Libraries, 8014349)
https://notcve.org/view.php?id=CVE-2013-5840
16 Oct 2013 — Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, and Java SE Embedded 7u40 and earlier allows remote attackers to affect confidentiality via unknown vectors related to Libraries. Vulnerabilidad no especificada en Oracle Java SE v7u40 y anteriores, Java SE v6u60 y anteriores, Java SE v5.0u51 y anteriores, y Java SE Embedded v7u40 y anteriores permite a atacantes remotos afectar a la confidencialidad a través de vectores desconocidos relaciona... • http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=1018831 •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2013-5850 – OpenJDK: Missing CORBA security checks (Libraries, 8017196)
https://notcve.org/view.php?id=CVE-2013-5850
16 Oct 2013 — Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, and Java SE Embedded 7u40 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries, a different vulnerability than CVE-2013-5842. Vulnerabilidad no especificada en Oracle Java SE 7u40 y versiones anteriores, Java SE 6u60 y versiones anteriores, Java SE 5.0u51 y versiones anteriores y Java SE Embedded 7u40 y versiones an... • http://lists.apple.com/archives/security-announce/2013/Oct/msg00001.html •