rpm package
suse/java-1_8_0-ibm&distro=SUSE Enterprise Storage 5
pkg:rpm/suse/java-1_8_0-ibm&distro=SUSE%20Enterprise%20Storage%205
Vulnerabilities (51)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2019-11775 | Hig | 7.4 | < 1.8.0_sr5.40-30.54.1 | 1.8.0_sr5.40-30.54.1 | Jul 30, 2019 | All builds of Eclipse OpenJ9 prior to 0.15 contain a bug where the loop versioner may fail to privatize a value that is pulled out of the loop by versioning - for example if there is a condition that is moved out of the loop that reads a field we may not privatize the value of th | |
| CVE-2019-2816 | Med | 4.8 | < 1.8.0_sr5.40-30.54.1 | 1.8.0_sr5.40-30.54.1 | Jul 23, 2019 | Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Networking). Supported versions that are affected are Java SE: 7u221, 8u212, 11.0.3 and 12.0.1; Java SE Embedded: 8u211. Difficult to exploit vulnerability allows unauthenticated attacker wi | |
| CVE-2019-2786 | Low | 3.4 | < 1.8.0_sr5.40-30.54.1 | 1.8.0_sr5.40-30.54.1 | Jul 23, 2019 | Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Security). Supported versions that are affected are Java SE: 8u212, 11.0.3 and 12.0.1; Java SE Embedded: 8u211. Difficult to exploit vulnerability allows unauthenticated attacker with networ | |
| CVE-2019-2769 | Med | 5.3 | < 1.8.0_sr5.40-30.54.1 | 1.8.0_sr5.40-30.54.1 | Jul 23, 2019 | Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Utilities). Supported versions that are affected are Java SE: 7u221, 8u212, 11.0.3 and 12.0.1; Java SE Embedded: 8u211. Easily exploitable vulnerability allows unauthenticated attacker with | |
| CVE-2019-2766 | Low | 3.1 | < 1.8.0_sr5.40-30.54.1 | 1.8.0_sr5.40-30.54.1 | Jul 23, 2019 | Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Networking). Supported versions that are affected are Java SE: 7u221, 8u212, 11.0.3 and 12.0.1; Java SE Embedded: 8u211. Difficult to exploit vulnerability allows unauthenticated attacker wi | |
| CVE-2019-2762 | Med | 5.3 | < 1.8.0_sr5.40-30.54.1 | 1.8.0_sr5.40-30.54.1 | Jul 23, 2019 | Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Utilities). Supported versions that are affected are Java SE: 7u221, 8u212, 11.0.3 and 12.0.1; Java SE Embedded: 8u211. Easily exploitable vulnerability allows unauthenticated attacker with | |
| CVE-2019-11772 | Cri | 9.8 | < 1.8.0_sr5.40-30.54.1 | 1.8.0_sr5.40-30.54.1 | Jul 17, 2019 | In Eclipse OpenJ9 prior to 0.15, the String.getBytes(int, int, byte[], int) method does not verify that the provided byte array is non-null nor that the provided index is in bounds when compiled by the JIT. This allows arbitrary writes to any 32-bit address or beyond the end of a | |
| CVE-2019-11771 | Hig | 7.8 | < 1.8.0_sr5.40-30.54.1 | 1.8.0_sr5.40-30.54.1 | Jul 17, 2019 | AIX builds of Eclipse OpenJ9 before 0.15.0 contain unused RPATHs which may facilitate code injection and privilege elevation by local users. | |
| CVE-2019-7317 | Med | 5.3 | < 1.8.0_sr5.40-30.54.1 | 1.8.0_sr5.40-30.54.1 | Feb 4, 2019 | png_image_free in png.c in libpng 1.6.x before 1.6.37 has a use-after-free because png_image_free_function is called under png_safe_execute. | |
| CVE-2019-2449 | Low | 3.1 | < 1.8.0_sr5.40-30.54.1 | 1.8.0_sr5.40-30.54.1 | Jan 16, 2019 | Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Deployment). The supported version that is affected is Java SE: 8u192. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Succ | |
| CVE-2018-11212 | Med | 6.5 | < 1.8.0_sr5.40-30.54.1 | 1.8.0_sr5.40-30.54.1 | May 16, 2018 | An issue was discovered in libjpeg 9a and 9d. The alloc_sarray function in jmemmgr.c allows remote attackers to cause a denial of service (divide-by-zero error) via a crafted file. |
- affected < 1.8.0_sr5.40-30.54.1fixed 1.8.0_sr5.40-30.54.1
All builds of Eclipse OpenJ9 prior to 0.15 contain a bug where the loop versioner may fail to privatize a value that is pulled out of the loop by versioning - for example if there is a condition that is moved out of the loop that reads a field we may not privatize the value of th
- affected < 1.8.0_sr5.40-30.54.1fixed 1.8.0_sr5.40-30.54.1
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Networking). Supported versions that are affected are Java SE: 7u221, 8u212, 11.0.3 and 12.0.1; Java SE Embedded: 8u211. Difficult to exploit vulnerability allows unauthenticated attacker wi
- affected < 1.8.0_sr5.40-30.54.1fixed 1.8.0_sr5.40-30.54.1
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Security). Supported versions that are affected are Java SE: 8u212, 11.0.3 and 12.0.1; Java SE Embedded: 8u211. Difficult to exploit vulnerability allows unauthenticated attacker with networ
- affected < 1.8.0_sr5.40-30.54.1fixed 1.8.0_sr5.40-30.54.1
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Utilities). Supported versions that are affected are Java SE: 7u221, 8u212, 11.0.3 and 12.0.1; Java SE Embedded: 8u211. Easily exploitable vulnerability allows unauthenticated attacker with
- affected < 1.8.0_sr5.40-30.54.1fixed 1.8.0_sr5.40-30.54.1
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Networking). Supported versions that are affected are Java SE: 7u221, 8u212, 11.0.3 and 12.0.1; Java SE Embedded: 8u211. Difficult to exploit vulnerability allows unauthenticated attacker wi
- affected < 1.8.0_sr5.40-30.54.1fixed 1.8.0_sr5.40-30.54.1
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Utilities). Supported versions that are affected are Java SE: 7u221, 8u212, 11.0.3 and 12.0.1; Java SE Embedded: 8u211. Easily exploitable vulnerability allows unauthenticated attacker with
- affected < 1.8.0_sr5.40-30.54.1fixed 1.8.0_sr5.40-30.54.1
In Eclipse OpenJ9 prior to 0.15, the String.getBytes(int, int, byte[], int) method does not verify that the provided byte array is non-null nor that the provided index is in bounds when compiled by the JIT. This allows arbitrary writes to any 32-bit address or beyond the end of a
- affected < 1.8.0_sr5.40-30.54.1fixed 1.8.0_sr5.40-30.54.1
AIX builds of Eclipse OpenJ9 before 0.15.0 contain unused RPATHs which may facilitate code injection and privilege elevation by local users.
- affected < 1.8.0_sr5.40-30.54.1fixed 1.8.0_sr5.40-30.54.1
png_image_free in png.c in libpng 1.6.x before 1.6.37 has a use-after-free because png_image_free_function is called under png_safe_execute.
- affected < 1.8.0_sr5.40-30.54.1fixed 1.8.0_sr5.40-30.54.1
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Deployment). The supported version that is affected is Java SE: 8u192. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Succ
- affected < 1.8.0_sr5.40-30.54.1fixed 1.8.0_sr5.40-30.54.1
An issue was discovered in libjpeg 9a and 9d. The alloc_sarray function in jmemmgr.c allows remote attackers to cause a denial of service (divide-by-zero error) via a crafted file.
Page 3 of 3