VYPR

rpm package

suse/java-1_8_0-openjdk&distro=SUSE Linux Enterprise Server 12 SP2

pkg:rpm/suse/java-1_8_0-openjdk&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2

Vulnerabilities (119)

  • CVE-2017-10067HigAug 8, 2017
    affected < 1.8.0.144-27.5.3fixed 1.8.0.144-27.5.3

    Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Security). Supported versions that are affected are Java SE: 6u151, 7u141 and 8u131. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise

  • CVE-2017-10053MedAug 8, 2017
    affected < 1.8.0.144-27.5.3fixed 1.8.0.144-27.5.3

    Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: 2D). Supported versions that are affected are Java SE: 6u151, 7u141 and 8u131; Java SE Embedded: 8u131; JRockit: R28.3.14. Easily exploitable vulnerability allows unauthenticated at

  • CVE-2016-9843CriMay 23, 2017
    affected < 1.8.0.151-27.8.1fixed 1.8.0.151-27.8.1

    The crc32_big function in crc32.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact via vectors involving big-endian CRC calculation.

  • CVE-2016-9842HigMay 23, 2017
    affected < 1.8.0.151-27.8.1fixed 1.8.0.151-27.8.1

    The inflateMark function in inflate.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact via vectors involving left shifts of negative integers.

  • CVE-2016-9841CriMay 23, 2017
    affected < 1.8.0.151-27.8.1fixed 1.8.0.151-27.8.1

    inffast.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic.

  • CVE-2016-9840HigMay 23, 2017
    affected < 1.8.0.151-27.8.1fixed 1.8.0.151-27.8.1

    inftrees.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic.

  • CVE-2017-5461CriMay 11, 2017
    affected < 1.8.0.121-23.4fixed 1.8.0.121-23.4

    Mozilla Network Security Services (NSS) before 3.21.4, 3.22.x through 3.28.x before 3.28.4, 3.29.x before 3.29.5, and 3.30.x before 3.30.1 allows remote attackers to cause a denial of service (out-of-bounds write) or possibly have unspecified other impact by leveraging incorrect

  • CVE-2017-3544LowApr 24, 2017
    affected < 1.8.0.131-26.3fixed 1.8.0.131-26.3

    Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Networking). Supported versions that are affected are Java SE: 6u141, 7u131 and 8u121; Java SE Embedded: 8u121; JRockit: R28.3.13. Difficult to exploit vulnerability allows unauthen

  • CVE-2017-3539LowApr 24, 2017
    affected < 1.8.0.131-26.3fixed 1.8.0.131-26.3

    Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Security). Supported versions that are affected are Java SE: 6u141, 7u131 and 8u121; Java SE Embedded: 8u121. Difficult to exploit vulnerability allows unauthenticated attacker with network

  • CVE-2017-3533LowApr 24, 2017
    affected < 1.8.0.131-26.3fixed 1.8.0.131-26.3

    Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Networking). Supported versions that are affected are Java SE: 6u141, 7u131 and 8u121; Java SE Embedded: 8u121; JRockit: R28.3.13. Difficult to exploit vulnerability allows unauthen

  • CVE-2017-3526MedApr 24, 2017
    affected < 1.8.0.131-26.3fixed 1.8.0.131-26.3

    Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: JAXP). Supported versions that are affected are Java SE: 6u141, 7u131 and 8u121; Java SE Embedded: 8u121; JRockit: R28.3.13. Difficult to exploit vulnerability allows unauthenticate

  • CVE-2017-3514HigApr 24, 2017
    affected < 1.8.0.131-26.3fixed 1.8.0.131-26.3

    Vulnerability in the Java SE component of Oracle Java SE (subcomponent: AWT). Supported versions that are affected are Java SE: 6u141, 7u131 and 8u121. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java

  • CVE-2017-3512HigApr 24, 2017
    affected < 1.8.0.131-26.3fixed 1.8.0.131-26.3

    Vulnerability in the Java SE component of Oracle Java SE (subcomponent: AWT). Supported versions that are affected are Java SE: 7u131 and 8u121. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Su

  • CVE-2017-3511HigApr 24, 2017
    affected < 1.8.0.131-26.3fixed 1.8.0.131-26.3

    Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: JCE). Supported versions that are affected are Java SE: 7u131 and 8u121; Java SE Embedded: 8u121; JRockit: R28.3.13. Difficult to exploit vulnerability allows unauthenticated attack

  • CVE-2017-3509MedApr 24, 2017
    affected < 1.8.0.131-26.3fixed 1.8.0.131-26.3

    Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Networking). Supported versions that are affected are Java SE: 6u141, 7u131 and 8u121; Java SE Embedded: 8u121. Difficult to exploit vulnerability allows unauthenticated attacker with networ

  • CVE-2016-10165HigFeb 3, 2017
    affected < 1.8.0.151-27.8.1fixed 1.8.0.151-27.8.1

    The Type_MLU_Read function in cmstypes.c in Little CMS (aka lcms2) allows remote attackers to obtain sensitive information or cause a denial of service via an image with a crafted ICC profile, which triggers an out-of-bounds heap read.

  • CVE-2017-3289CriJan 27, 2017
    affected < 1.8.0.121-20.1fixed 1.8.0.121-20.1

    Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Hotspot). Supported versions that are affected are Java SE: 7u121 and 8u112; Java SE Embedded: 8u111. Easily exploitable vulnerability allows unauthenticated attacker with network access via

  • CVE-2017-3272CriJan 27, 2017
    affected < 1.8.0.121-20.1fixed 1.8.0.121-20.1

    Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Libraries). Supported versions that are affected are Java SE: 6u131, 7u121 and 8u112; Java SE Embedded: 8u111. Easily exploitable vulnerability allows unauthenticated attacker with network a

  • CVE-2017-3261MedJan 27, 2017
    affected < 1.8.0.121-20.1fixed 1.8.0.121-20.1

    Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Networking). Supported versions that are affected are Java SE: 6u131, 7u121 and 8u112; Java SE Embedded: 8u111. Easily exploitable vulnerability allows unauthenticated attacker with network

  • CVE-2017-3260HigJan 27, 2017
    affected < 1.8.0.121-20.1fixed 1.8.0.121-20.1

    Vulnerability in the Java SE component of Oracle Java SE (subcomponent: AWT). Supported versions that are affected are Java SE: 7u121 and 8u112. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Su

Page 5 of 6