
CVE-2014-6457 – OpenJDK: Triple Handshake attack against TLS/SSL connections (JSSE, 8037066)
https://notcve.org/view.php?id=CVE-2014-6457
15 Oct 2014 — Unspecified vulnerability in Oracle Java SE 5.0u71, 6u81, 7u67, and 8u20; Java SE Embedded 7u60; and JRockit R27.8.3, and R28.3.3 allows remote attackers to affect confidentiality and integrity via vectors related to JSSE. Vulnerabilidad sin especificar en Oracle Java SE 5.0u71, 6u81, 7u67, y 8u20; Java SE Embedded 7u60; y JRockit R27.8.3, y R28.3.3 permite a atacantes remotos afectar la confidencialidad y la integridad a través de vectores relacionados con JSSE. It was discovered that the TLS/SSL implement... • http://linux.oracle.com/errata/ELSA-2014-1633.html •

CVE-2014-6512 – OpenJDK: DatagramSocket connected socket missing source check (Libraries, 8039509)
https://notcve.org/view.php?id=CVE-2014-6512
15 Oct 2014 — Unspecified vulnerability in Oracle Java SE 5.0u71, 6u81, 7u67, and 8u20; Java SE Embedded 7u60; and JRockit R27.8.3 and R28.3.3 allows remote attackers to affect integrity via unknown vectors related to Libraries. Vulnerabilidad sin especificar en Oracle Java SE 5.0u71, 6u81, 7u67, y 8u20; Java SE Embedded 7u60; y JRockit R27.8.3 y R28.3.3 permite a atacantes remotos afectar a la integridad a través de vectores relacionados con las librerías. It was discovered that the DatagramSocket implementation in Open... • http://linux.oracle.com/errata/ELSA-2014-1633.html • CWE-345: Insufficient Verification of Data Authenticity •

CVE-2014-6517 – OpenJDK: StAX parser parameter entity XXE (JAXP, 8039533)
https://notcve.org/view.php?id=CVE-2014-6517
15 Oct 2014 — Unspecified vulnerability in Oracle Java SE 6u81, 7u67, and 8u20; Java SE Embedded 7u60; and Jrockit R27.8.3 and R28.3.3 allows remote attackers to affect confidentiality via vectors related to JAXP. Vulnerabilidad sin especificar en Oracle Java SE 6u81, 7u67, y 8u20; Java SE Embedded 7u60; y Jrockit R27.8.3 y R28.3.3, permite a atacantes remotos afectar a la confidencialidad a través de vectores relacionados con JAXP. It was discovered that the StAX XML parser in the JAXP component in OpenJDK performed exp... • http://linux.oracle.com/errata/ELSA-2014-1633.html •

CVE-2014-6558 – OpenJDK: CipherInputStream incorrect exception handling (Security, 8037846)
https://notcve.org/view.php?id=CVE-2014-6558
15 Oct 2014 — Unspecified vulnerability in Oracle Java SE 5.0u71, 6u81, 7u67, and 8u20; Java SE Embedded 7u60; and JRockit R27.8.3 and JRockit R28.3.3 allows remote attackers to affect integrity via unknown vectors related to Security. Vulnerabilidad sin especificar en Oracle Java SE 5.0u71, 6u81, 7u67, y 8u20; Java SE Embedded 7u60; y JRockit R27.8.3 y JRockit R28.3.3 permite a atacantes remotos afectar la integridad a través de vectores desconocidos relacionados con la seguridad. It was discovered that the CipherInputS... • http://linux.oracle.com/errata/ELSA-2014-1633.html •

CVE-2013-5797 – OpenJDK: insufficient escaping of window title string (Javadoc, 8016675)
https://notcve.org/view.php?id=CVE-2013-5797
16 Oct 2013 — Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, JRockit R28.2.8 and earlier, JRockit R27.7.6 and earlier, and JavaFX 2.2.40 and earlier allows remote authenticated users to affect integrity via unknown vectors related to Javadoc. Vulnerablidad sin especificar en Oracle Java SE 7u40 y anteriores, Java SE 6u60 y anteriores, Java SE 5.0u51 y anteriores, JRockit R28.2.8 y anteriores, JRockit R27.7.6 y anteriores, y JavaFX 2.2.40 y anteriores pe... • http://lists.apple.com/archives/security-announce/2013/Oct/msg00001.html •

CVE-2013-5802 – OpenJDK: javax.xml.transform.TransformerFactory does not properly honor XMLConstants.FEATURE_SECURE_PROCESSING (JAXP, 8012425)
https://notcve.org/view.php?id=CVE-2013-5802
16 Oct 2013 — Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, JRockit R28.2.8 and earlier, JRockit R27.7.6 and earlier, and Java SE Embedded 7u40 and earlier allows remote attackers to affect confidentiality, integrity, and availability via vectors related to JAXP. Vulnerabilidad sin especificar en Oracle Java SE 7u40 y anteriores, Java SE 6u60 y anteriores, Java SE 5.0u51 y anteriores, JRockit R28.2.8 y anteriores, JRockit R27.7.6 y anteriores, y Java S... • http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=1019130 •

CVE-2013-5803 – OpenJDK: insufficient checks of KDC replies (JGSS, 8014341)
https://notcve.org/view.php?id=CVE-2013-5803
16 Oct 2013 — Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, JRockit R28.2.8 and earlier, JRockit R27.7.6 and earlier, and Java SE Embedded 7u40 and earlier allows remote attackers to affect availability via vectors related to JGSS. Vulnerabilidad sin especificar en Oracle Java SE 7u40 y anteriores, Java SE 6u60 y anteriores, Java SE 5.0u51 y anteriores, JRockit R28.2.8 y anteriores, JRockit R27.7.6 y anteriores, and Java SE Embedded 7u40 y anteriores p... • http://lists.apple.com/archives/security-announce/2013/Oct/msg00001.html •

CVE-2013-5804 – OpenJDK: javac does not ignore certain ignorable characters (Javadoc, 8016653)
https://notcve.org/view.php?id=CVE-2013-5804
16 Oct 2013 — Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, JRockit R28.2.8 and earlier, and JRockit R27.7.6 and earlier allows remote attackers to affect confidentiality and integrity via unknown vectors related to Javadoc. Vulnerabilidad no especificada en Oracle Java SE 7u40 y anteriores, Java SE 6u60 y anteriores, Java SE 5.0u51 y anteriores, JRockit R28.2.8 y anteriores, y JRockit R27.7.6 y anteriores que permite a atacantes remotos afectar la con... • http://lists.apple.com/archives/security-announce/2013/Oct/msg00001.html •

CVE-2013-5823 – OpenJDK: com.sun.org.apache.xml.internal.security.utils.UnsyncByteArrayOutputStream Denial of Service (Security, 8021290)
https://notcve.org/view.php?id=CVE-2013-5823
16 Oct 2013 — Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, JRockit R28.2.8 and earlier, JRockit R27.7.6 and earlier, and Java SE Embedded 7u40 and earlier allows remote attackers to affect availability via unknown vectors related to Security. Vulnerabilidad no especificada en Oracle Java SE y anteriores, Java SE 6u60 y anteriores, JRockit R28.2.8 y anteriores, JRockit R27.7.6 y anteriores, y Java SE Embedded 7u40 y anteriores permite a atacantes remotos afectar la disponibilidad... • http://lists.apple.com/archives/security-announce/2013/Oct/msg00001.html •

CVE-2013-5825 – OpenJDK: XML parsing Denial of Service (JAXP, 8014530)
https://notcve.org/view.php?id=CVE-2013-5825
16 Oct 2013 — Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, JRockit R28.2.8 and earlier, JRockit R27.7.6 and earlier, and Java SE Embedded 7u40 and earlier allows remote attackers to affect availability via vectors related to JAXP. Vulnerabilidad no especificada en Oracle Java SE 7u40 y anteriores, Java SE 6u60 y anteriores, Java SE 5.0u51 y anteriores, JRockit R28.2.8 y anteriores, JRockit R27.7.6 y anteriores, y Java SE Embedded 7u40 y anteriores per... • http://lists.apple.com/archives/security-announce/2013/Oct/msg00001.html •