rpm package
suse/java-1_7_1-ibm&distro=SUSE Linux Enterprise Software Development Kit 12
pkg:rpm/suse/java-1_7_1-ibm&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012
Vulnerabilities (75)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2015-1931 | — | < 1.7.1_sr3.10-14.1 | 1.7.1_sr3.10-14.1 | Jan 23, 2020 | IBM Java Security Components in IBM SDK, Java Technology Edition 8 before SR1 FP10, 7 R1 before SR3 FP10, 7 before SR9 FP10, 6 R1 before SR8 FP7, 6 before SR16 FP7, and 5.0 before SR16 FP13 stores plaintext information in memory dumps, which allows local users to obtain sensitive | ||
| CVE-2015-5041 | Cri | 9.1 | < 1.7.1_sr3.30-21.1 | 1.7.1_sr3.30-21.1 | Jun 6, 2016 | The J9 JVM in IBM SDK, Java Technology Edition 6 before SR16 FP20, 6 R1 before SR8 FP20, 7 before SR9 FP30, and 7 R1 before SR3 FP30 allows remote attackers to obtain sensitive information or inject data by invoking non-public interface methods. | |
| CVE-2016-0376 | Hig | 8.1 | < 1.7.1_sr3.40-25.1 | 1.7.1_sr3.40-25.1 | Jun 3, 2016 | The com.ibm.rmi.io.SunSerializableFactory class in IBM SDK, Java Technology Edition 6 before SR16 FP25 (6.0.16.25), 6 R1 before SR8 FP25 (6.1.8.25), 7 before SR9 FP40 (7.0.9.40), 7 R1 before SR3 FP40 (7.1.3.40), and 8 before SR3 (8.0.3.0) does not properly deserialize classes in | |
| CVE-2016-0363 | Hig | 8.1 | < 1.7.1_sr3.40-25.1 | 1.7.1_sr3.40-25.1 | Jun 3, 2016 | The com.ibm.CORBA.iiop.ClientDelegate class in IBM SDK, Java Technology Edition 6 before SR16 FP25 (6.0.16.25), 6 R1 before SR8 FP25 (6.1.8.25), 7 before SR9 FP40 (7.0.9.40), 7 R1 before SR3 FP40 (7.1.3.40), and 8 before SR3 (8.0.3.0) uses the invoke method of the java.lang.refle | |
| CVE-2016-0264 | Med | 5.6 | < 1.7.1_sr3.40-25.1 | 1.7.1_sr3.40-25.1 | May 24, 2016 | Buffer overflow in the Java Virtual Machine (JVM) in IBM SDK, Java Technology Edition 6 before SR16 FP25 (6.0.16.25), 6 R1 before SR8 FP25 (6.1.8.25), 7 before SR9 FP40 (7.0.9.40), 7 R1 before SR3 FP40 (7.1.3.40), and 8 before SR3 (8.0.3.0) allows remote attackers to execute arbi | |
| CVE-2016-3449 | Hig | 8.3 | < 1.7.1_sr3.40-25.1 | 1.7.1_sr3.40-25.1 | Apr 21, 2016 | Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Deployment. | |
| CVE-2016-3443 | Cri | 9.6 | < 1.7.1_sr3.40-25.1 | 1.7.1_sr3.40-25.1 | Apr 21, 2016 | Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to 2D. NOTE: the previous information is from the April 2016 CPU. Oracle has not commented on third-party claims t | |
| CVE-2016-3427 | Cri | 9.8 | KEV | < 1.7.1_sr3.40-25.1 | 1.7.1_sr3.40-25.1 | Apr 21, 2016 | Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to JMX. |
| CVE-2016-3426 | Low | 3.1 | < 1.7.1_sr3.40-25.1 | 1.7.1_sr3.40-25.1 | Apr 21, 2016 | Unspecified vulnerability in Oracle Java SE 8u77 and Java SE Embedded 8u77 allows remote attackers to affect confidentiality via vectors related to JCE. | |
| CVE-2016-3422 | Med | 4.3 | < 1.7.1_sr3.40-25.1 | 1.7.1_sr3.40-25.1 | Apr 21, 2016 | Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77 allows remote attackers to affect availability via vectors related to 2D. | |
| CVE-2016-0687 | Cri | 9.6 | < 1.7.1_sr3.40-25.1 | 1.7.1_sr3.40-25.1 | Apr 21, 2016 | Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77 and Java SE Embedded 8u77 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to the Hotspot sub-component. | |
| CVE-2016-0686 | Cri | 9.6 | < 1.7.1_sr3.40-25.1 | 1.7.1_sr3.40-25.1 | Apr 21, 2016 | Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77 and Java SE Embedded 8u77 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Serialization. | |
| CVE-2015-8540 | Hig | 8.8 | < 1.7.1_sr3.30-21.1 | 1.7.1_sr3.30-21.1 | Apr 14, 2016 | Integer underflow in the png_check_keyword function in pngwutil.c in libpng 0.90 through 0.99, 1.0.x before 1.0.66, 1.1.x and 1.2.x before 1.2.56, 1.3.x and 1.4.x before 1.4.19, and 1.5.x before 1.5.26 allows remote attackers to have unspecified impact via a space character as a | |
| CVE-2015-8472 | Hig | 7.3 | < 1.7.1_sr3.30-21.1 | 1.7.1_sr3.30-21.1 | Jan 21, 2016 | Buffer overflow in the png_set_PLTE function in libpng before 1.0.65, 1.1.x and 1.2.x before 1.2.55, 1.3.x, 1.4.x before 1.4.18, 1.5.x before 1.5.25, and 1.6.x before 1.6.20 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified othe | |
| CVE-2016-0494 | — | < 1.7.1_sr3.30-21.1 | 1.7.1_sr3.30-21.1 | Jan 21, 2016 | Unspecified vulnerability in the Java SE and Java SE Embedded components in Oracle Java SE 6u105, 7u91, and 8u66 and Java SE Embedded 8u65 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D. | ||
| CVE-2016-0483 | — | < 1.7.1_sr3.30-21.1 | 1.7.1_sr3.30-21.1 | Jan 21, 2016 | Unspecified vulnerability in Oracle Java SE 6u105, 7u91, and 8u66; Java SE Embedded 8u65; and JRockit R28.3.8 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to AWT. NOTE: the previous information is from the January 2016 CPU. O | ||
| CVE-2016-0466 | — | < 1.7.1_sr3.30-21.1 | 1.7.1_sr3.30-21.1 | Jan 21, 2016 | Unspecified vulnerability in the Java SE, Java SE Embedded, and JRockit components in Oracle Java SE 6u105, 7u91, and 8u66; Java SE Embedded 8u65; and JRockit R28.3.8 allows remote attackers to affect availability via vectors related to JAXP. | ||
| CVE-2016-0448 | — | < 1.7.1_sr3.30-21.1 | 1.7.1_sr3.30-21.1 | Jan 21, 2016 | Unspecified vulnerability in the Java SE and Java SE Embedded components in Oracle Java SE 6u105, 7u91, and 8u66, and Java SE Embedded 8u65 allows remote authenticated users to affect confidentiality via vectors related to JMX. | ||
| CVE-2016-0402 | — | < 1.7.1_sr3.30-21.1 | 1.7.1_sr3.30-21.1 | Jan 21, 2016 | Unspecified vulnerability in the Java SE and Java SE Embedded components in Oracle Java SE 6u105, 7u91, and 8u66 and Java SE Embedded 8u65 allows remote attackers to affect integrity via unknown vectors related to Networking. | ||
| CVE-2015-7575 | Med | 5.9 | < 1.7.1_sr3.30-21.1 | 1.7.1_sr3.30-21.1 | Jan 9, 2016 | Mozilla Network Security Services (NSS) before 3.20.2, as used in Mozilla Firefox before 43.0.2 and Firefox ESR 38.x before 38.5.2, does not reject MD5 signatures in Server Key Exchange messages in TLS 1.2 Handshake Protocol traffic, which makes it easier for man-in-the-middle at |
- CVE-2015-1931Jan 23, 2020affected < 1.7.1_sr3.10-14.1fixed 1.7.1_sr3.10-14.1
IBM Java Security Components in IBM SDK, Java Technology Edition 8 before SR1 FP10, 7 R1 before SR3 FP10, 7 before SR9 FP10, 6 R1 before SR8 FP7, 6 before SR16 FP7, and 5.0 before SR16 FP13 stores plaintext information in memory dumps, which allows local users to obtain sensitive
- affected < 1.7.1_sr3.30-21.1fixed 1.7.1_sr3.30-21.1
The J9 JVM in IBM SDK, Java Technology Edition 6 before SR16 FP20, 6 R1 before SR8 FP20, 7 before SR9 FP30, and 7 R1 before SR3 FP30 allows remote attackers to obtain sensitive information or inject data by invoking non-public interface methods.
- affected < 1.7.1_sr3.40-25.1fixed 1.7.1_sr3.40-25.1
The com.ibm.rmi.io.SunSerializableFactory class in IBM SDK, Java Technology Edition 6 before SR16 FP25 (6.0.16.25), 6 R1 before SR8 FP25 (6.1.8.25), 7 before SR9 FP40 (7.0.9.40), 7 R1 before SR3 FP40 (7.1.3.40), and 8 before SR3 (8.0.3.0) does not properly deserialize classes in
- affected < 1.7.1_sr3.40-25.1fixed 1.7.1_sr3.40-25.1
The com.ibm.CORBA.iiop.ClientDelegate class in IBM SDK, Java Technology Edition 6 before SR16 FP25 (6.0.16.25), 6 R1 before SR8 FP25 (6.1.8.25), 7 before SR9 FP40 (7.0.9.40), 7 R1 before SR3 FP40 (7.1.3.40), and 8 before SR3 (8.0.3.0) uses the invoke method of the java.lang.refle
- affected < 1.7.1_sr3.40-25.1fixed 1.7.1_sr3.40-25.1
Buffer overflow in the Java Virtual Machine (JVM) in IBM SDK, Java Technology Edition 6 before SR16 FP25 (6.0.16.25), 6 R1 before SR8 FP25 (6.1.8.25), 7 before SR9 FP40 (7.0.9.40), 7 R1 before SR3 FP40 (7.1.3.40), and 8 before SR3 (8.0.3.0) allows remote attackers to execute arbi
- affected < 1.7.1_sr3.40-25.1fixed 1.7.1_sr3.40-25.1
Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Deployment.
- affected < 1.7.1_sr3.40-25.1fixed 1.7.1_sr3.40-25.1
Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to 2D. NOTE: the previous information is from the April 2016 CPU. Oracle has not commented on third-party claims t
- affected < 1.7.1_sr3.40-25.1fixed 1.7.1_sr3.40-25.1
Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to JMX.
- affected < 1.7.1_sr3.40-25.1fixed 1.7.1_sr3.40-25.1
Unspecified vulnerability in Oracle Java SE 8u77 and Java SE Embedded 8u77 allows remote attackers to affect confidentiality via vectors related to JCE.
- affected < 1.7.1_sr3.40-25.1fixed 1.7.1_sr3.40-25.1
Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77 allows remote attackers to affect availability via vectors related to 2D.
- affected < 1.7.1_sr3.40-25.1fixed 1.7.1_sr3.40-25.1
Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77 and Java SE Embedded 8u77 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to the Hotspot sub-component.
- affected < 1.7.1_sr3.40-25.1fixed 1.7.1_sr3.40-25.1
Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77 and Java SE Embedded 8u77 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Serialization.
- affected < 1.7.1_sr3.30-21.1fixed 1.7.1_sr3.30-21.1
Integer underflow in the png_check_keyword function in pngwutil.c in libpng 0.90 through 0.99, 1.0.x before 1.0.66, 1.1.x and 1.2.x before 1.2.56, 1.3.x and 1.4.x before 1.4.19, and 1.5.x before 1.5.26 allows remote attackers to have unspecified impact via a space character as a
- affected < 1.7.1_sr3.30-21.1fixed 1.7.1_sr3.30-21.1
Buffer overflow in the png_set_PLTE function in libpng before 1.0.65, 1.1.x and 1.2.x before 1.2.55, 1.3.x, 1.4.x before 1.4.18, 1.5.x before 1.5.25, and 1.6.x before 1.6.20 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified othe
- CVE-2016-0494Jan 21, 2016affected < 1.7.1_sr3.30-21.1fixed 1.7.1_sr3.30-21.1
Unspecified vulnerability in the Java SE and Java SE Embedded components in Oracle Java SE 6u105, 7u91, and 8u66 and Java SE Embedded 8u65 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D.
- CVE-2016-0483Jan 21, 2016affected < 1.7.1_sr3.30-21.1fixed 1.7.1_sr3.30-21.1
Unspecified vulnerability in Oracle Java SE 6u105, 7u91, and 8u66; Java SE Embedded 8u65; and JRockit R28.3.8 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to AWT. NOTE: the previous information is from the January 2016 CPU. O
- CVE-2016-0466Jan 21, 2016affected < 1.7.1_sr3.30-21.1fixed 1.7.1_sr3.30-21.1
Unspecified vulnerability in the Java SE, Java SE Embedded, and JRockit components in Oracle Java SE 6u105, 7u91, and 8u66; Java SE Embedded 8u65; and JRockit R28.3.8 allows remote attackers to affect availability via vectors related to JAXP.
- CVE-2016-0448Jan 21, 2016affected < 1.7.1_sr3.30-21.1fixed 1.7.1_sr3.30-21.1
Unspecified vulnerability in the Java SE and Java SE Embedded components in Oracle Java SE 6u105, 7u91, and 8u66, and Java SE Embedded 8u65 allows remote authenticated users to affect confidentiality via vectors related to JMX.
- CVE-2016-0402Jan 21, 2016affected < 1.7.1_sr3.30-21.1fixed 1.7.1_sr3.30-21.1
Unspecified vulnerability in the Java SE and Java SE Embedded components in Oracle Java SE 6u105, 7u91, and 8u66 and Java SE Embedded 8u65 allows remote attackers to affect integrity via unknown vectors related to Networking.
- affected < 1.7.1_sr3.30-21.1fixed 1.7.1_sr3.30-21.1
Mozilla Network Security Services (NSS) before 3.20.2, as used in Mozilla Firefox before 43.0.2 and Firefox ESR 38.x before 38.5.2, does not reject MD5 signatures in Server Key Exchange messages in TLS 1.2 Handshake Protocol traffic, which makes it easier for man-in-the-middle at
Page 1 of 4