CVE-2014-6504
OpenJDK: incorrect optimization of range checks in C2 compiler (Hotspot, 8022783)
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Unspecified vulnerability in Oracle Java SE 5.0u71, 6u81, and 7u67, and Java SE Embedded 7u60, allows remote attackers to affect confidentiality via unknown vectors related to Hotspot.
Vulnerabilidad sin especificar en Oracle Java SE 5.0u71, 6u81, y 7u67, y Java SE Embedded 7u60, permite a atacantes remotos afectar a a la confidencialidad a través de vectores relacionados con Hotspot.
The java-1.7.0-openjdk packages provide the OpenJDK 7 Java Runtime Environment and the OpenJDK 7 Java Software Development Kit. Multiple flaws were discovered in the Libraries, 2D, and Hotspot components in OpenJDK. An untrusted Java application or applet could use these flaws to bypass certain Java sandbox restrictions. It was discovered that the StAX XML parser in the JAXP component in OpenJDK performed expansion of external parameter entities even when external entity substitution was disabled. A remote attacker could use this flaw to perform XML eXternal Entity attack against applications using the StAX parser to parse untrusted XML documents.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2014-09-17 CVE Reserved
- 2014-10-15 CVE Published
- 2024-08-06 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
CAPEC
References (33)
URL | Tag | Source |
---|---|---|
http://linux.oracle.com/errata/ELSA-2014-1633.html | X_refsource_confirm | |
http://linux.oracle.com/errata/ELSA-2014-1634.html | X_refsource_confirm | |
http://linux.oracle.com/errata/ELSA-2014-1636 | X_refsource_confirm | |
http://secunia.com/advisories/60414 | Third Party Advisory | |
http://secunia.com/advisories/60416 | Third Party Advisory | |
http://secunia.com/advisories/60417 | Third Party Advisory | |
http://secunia.com/advisories/61018 | Third Party Advisory | |
http://secunia.com/advisories/61020 | Third Party Advisory | |
http://secunia.com/advisories/61143 | Third Party Advisory | |
http://secunia.com/advisories/61163 | Third Party Advisory | |
http://secunia.com/advisories/61164 | Third Party Advisory | |
http://secunia.com/advisories/61346 | Third Party Advisory | |
http://secunia.com/advisories/61609 | Third Party Advisory | |
http://secunia.com/advisories/61629 | Third Party Advisory | |
http://secunia.com/advisories/61928 | Third Party Advisory | |
http://www.securityfocus.com/bid/70564 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://www.oracle.com/technetwork/topics/security/cpuoct2014-1972960.html | 2022-05-13 |
URL | Date | SRC |
---|---|---|
http://lists.opensuse.org/opensuse-security-announce/2014-11/msg00013.html | 2022-05-13 | |
http://marc.info/?l=bugtraq&m=141775382904016&w=2 | 2022-05-13 | |
http://rhn.redhat.com/errata/RHSA-2014-1620.html | 2022-05-13 | |
http://rhn.redhat.com/errata/RHSA-2014-1633.html | 2022-05-13 | |
http://rhn.redhat.com/errata/RHSA-2014-1634.html | 2022-05-13 | |
http://rhn.redhat.com/errata/RHSA-2014-1636.html | 2022-05-13 | |
http://rhn.redhat.com/errata/RHSA-2014-1657.html | 2022-05-13 | |
http://rhn.redhat.com/errata/RHSA-2014-1658.html | 2022-05-13 | |
http://security.gentoo.org/glsa/glsa-201502-12.xml | 2022-05-13 | |
http://www.debian.org/security/2014/dsa-3077 | 2022-05-13 | |
http://www.debian.org/security/2014/dsa-3080 | 2022-05-13 | |
http://www.ubuntu.com/usn/USN-2386-1 | 2022-05-13 | |
http://www.ubuntu.com/usn/USN-2388-1 | 2022-05-13 | |
http://www.ubuntu.com/usn/USN-2388-2 | 2022-05-13 | |
https://access.redhat.com/security/cve/CVE-2014-6504 | 2014-10-16 | |
https://bugzilla.redhat.com/show_bug.cgi?id=1150182 | 2014-10-16 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Oracle Search vendor "Oracle" | Jdk Search vendor "Oracle" for product "Jdk" | 1.5.0 Search vendor "Oracle" for product "Jdk" and version "1.5.0" | update_71 |
Affected
| ||||||
Oracle Search vendor "Oracle" | Jdk Search vendor "Oracle" for product "Jdk" | 1.6.0 Search vendor "Oracle" for product "Jdk" and version "1.6.0" | update81 |
Affected
| ||||||
Oracle Search vendor "Oracle" | Jdk Search vendor "Oracle" for product "Jdk" | 1.7.0 Search vendor "Oracle" for product "Jdk" and version "1.7.0" | update60 |
Affected
| ||||||
Oracle Search vendor "Oracle" | Jre Search vendor "Oracle" for product "Jre" | 1.5.0 Search vendor "Oracle" for product "Jre" and version "1.5.0" | update_71 |
Affected
| ||||||
Oracle Search vendor "Oracle" | Jre Search vendor "Oracle" for product "Jre" | 1.6.0 Search vendor "Oracle" for product "Jre" and version "1.6.0" | update_81 |
Affected
| ||||||
Oracle Search vendor "Oracle" | Jre Search vendor "Oracle" for product "Jre" | 1.7.0 Search vendor "Oracle" for product "Jre" and version "1.7.0" | update_67 |
Affected
| ||||||
Oracle Search vendor "Oracle" | Jre Search vendor "Oracle" for product "Jre" | 1.7.0 Search vendor "Oracle" for product "Jre" and version "1.7.0" | update60 |
Affected
|