CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2013-5878

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Oracle Java SE 6u65 and 7u45, Java SE Embedded 7u45, and OpenJDK 7 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Security. NOTE: the previous information is from the January 2014 CPU. Oracle has not commented on third-party claims that the Security component does not properly handle null XML namespace (xmlns) attributes during XML document canonicalization, which allows attackers to escape the sandbox.

    Published: 14 Jan 2014
    5
    Medium

    CVE-2013-5884

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Oracle Java SE 5.0u55, 6u65, and 7u45; Java SE Embedded 7u45; and OpenJDK 7 allows remote attackers to affect confidentiality via vectors related to CORBA. NOTE: the previous information is from the January 2014 CPU. Oracle has not commented on third-party claims that the issue is related to an incorrect check for code permissions by CORBA stub factories.

    Published: 14 Jan 2014
    4
    Medium

    CVE-2013-5891

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.33 and earlier and 5.6.13 and earlier allows remote authenticated users to affect availability via unknown vectors related to Partition.

    Published: 14 Jan 2014
    5
    Medium

    CVE-2013-5895

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Oracle Java SE 7u45 and JavaFX 2.2.45 allows remote attackers to affect confidentiality via unknown vectors related to JavaFX.

    Published: 14 Jan 2014
    6.8
    Medium

    CVE-2013-5904

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Oracle Java SE 7u45 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment.

    Published: 14 Jan 2014
    5.1
    Medium

    CVE-2013-5906

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Oracle Java SE 5.0u55, 6u65, and 7u45 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Install, a different vulnerability than CVE-2013-5905.

    Published: 14 Jan 2014
    2.6
    Low

    CVE-2013-5908

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.72 and earlier, 5.5.34 and earlier, and 5.6.14 and earlier allows remote attackers to affect availability via unknown vectors related to Error Handling.

    Published: 14 Jan 2014
    5
    Medium

    CVE-2014-0376

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Oracle Java SE 5.0u55, 6u65, and 7u45; Java SE Embedded 7u45; and OpenJDK 7 allows remote attackers to affect integrity via vectors related to JAXP. NOTE: the previous information is from the January 2014 CPU. Oracle has not commented on third-party claims that the issue is related to an improper check for "code permissions when creating document builder factories."

    Published: 14 Jan 2014
    4
    Medium

    CVE-2014-0386

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.71 and earlier, 5.5.33 and earlier, and 5.6.13 and earlier allows remote authenticated users to affect availability via unknown vectors related to Optimizer.

    Published: 14 Jan 2014
    3.3
    Low

    CVE-2014-0393

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.71 and earlier, 5.5.33 and earlier, and 5.6.13 and earlier allows remote authenticated users to affect integrity via unknown vectors related to InnoDB.

    Published: 14 Jan 2014
    4
    Medium

    CVE-2014-0401

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.72 and earlier, 5.5.34 and earlier, and 5.6.14 and earlier allows remote authenticated users to affect availability via unknown vectors.

    Published: 14 Jan 2014
    4
    Medium

    CVE-2014-0412

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.72 and earlier, 5.5.34 and earlier, and 5.6.14 and earlier allows remote authenticated users to affect availability via unknown vectors related to InnoDB.

    Published: 14 Jan 2014
    10
    Critical

    CVE-2014-0415

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Oracle Java SE 6u65 and 7u45 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment, a different vulnerability than CVE-2013-5889, CVE-2013-5902, CVE-2014-0410, CVE-2014-0418, and CVE-2014-0424.

    Published: 14 Jan 2014
    9.3
    Critical

    CVE-2014-0417

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Oracle Java SE 5.0u55, 6u65, and 7u45; JavaFX 2.2.45; and Java SE Embedded 7u45 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D.

    Published: 14 Jan 2014
    5.5
    Medium

    CVE-2014-0423

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Oracle Java SE 5.0u55, 6u65, and 7u45; JRockit R27.7.7 and R28.2.9; Java SE Embedded 7u45; and OpenJDK 7 allows remote authenticated users to affect confidentiality and availability via unknown vectors related to Beans. NOTE: the previous information is from the January 2014 CPU. Oracle has not commented on third-party claims that this issue is an XML External Entity (XXE) vulnerability in DocumentHandler.java, related to Beans decoding.

    Published: 14 Jan 2014
    2.8
    Low

    CVE-2014-0430

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.6.13 and earlier allows remote authenticated users to affect availability via unknown vectors related to Performance Schema.

    Published: 14 Jan 2014
    5
    Medium

    CVE-2013-5910

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Oracle Java SE 6u65 and 7u45, Java SE Embedded 7u45, and OpenJDK 7 allows remote attackers to affect integrity via unknown vectors related to Security. NOTE: the previous information is from the January 2014 CPU. Oracle has not commented on third-party claims that CanonicalizerBase.java in the XML canonicalizer allows untrusted code to access mutable byte arrays.

    Published: 14 Jan 2014
    6.8
    Medium

    CVE-2013-5860

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.6.14 and earlier allows remote authenticated users to affect availability via vectors related to GIS.

    Published: 14 Jan 2014
    6.8
    Medium

    CVE-2013-5882

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.6.13 and earlier allows remote authenticated users to affect availability via unknown vectors related to Stored Procedures.

    Published: 14 Jan 2014
    5
    Medium

    CVE-2013-5887

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Oracle Java SE 6u65 and 7u45 allows remote attackers to affect availability via unknown vectors related to Deployment.

    Published: 14 Jan 2014
    4.6
    Medium

    CVE-2013-5888

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Oracle Java SE 6u65 and 7u45, when running with GNOME, allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Deployment.

    Published: 14 Jan 2014
    4
    Medium

    CVE-2013-5894

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.6.13 and earlier allows remote authenticated users to affect availability via unknown vectors related to InnoDB.

    Published: 14 Jan 2014
    5
    Medium

    CVE-2013-5896

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Oracle Java SE 5.0u55, 6u65, and 7u45; Java SE Embedded 7u45; and OpenJDK 7 allows remote attackers to affect availability via vectors related to CORBA. NOTE: the previous information is from the January 2014 CPU. Oracle has not commented on third-party claims that com.sun.corba.se and its sub-packages are not included on the restricted package list.

    Published: 14 Jan 2014
    5.1
    Medium

    CVE-2013-5905

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Oracle Java SE 5.0u55, 6u65, and 7u45 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Install, a different vulnerability than CVE-2013-5906.

    Published: 14 Jan 2014
    7.5
    High

    CVE-2014-0373

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Oracle Java SE 5.0u55, 6u65, and 7u45, and OpenJDK 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Serviceability. NOTE: the previous information is from the January 2014 CPU. Oracle has not commented on third-party claims that the issue is related to throwing of an incorrect exception when SnmpStatusException should have been used in the SNMP implementation, which allows attackers to escape the sandbox.

    Published: 14 Jan 2014
    9.3
    Critical

    CVE-2014-0385

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Oracle Java SE 7u45, when installing on OS X, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Install.

    Published: 14 Jan 2014
    7.6
    High

    CVE-2014-0387

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Oracle Java SE 6u65 and Java SE 7u45, when running on Firefox, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment.

    Published: 14 Jan 2014
    9.3
    Critical

    CVE-2014-0408

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Oracle Java SE 7u45, when running on OS X, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Hotspot.

    Published: 14 Jan 2014
    10
    Critical

    CVE-2014-0410

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Oracle Java SE 6u65 and 7u45 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment, a different vulnerability than CVE-2013-5889, CVE-2013-5902, CVE-2014-0415, CVE-2014-0418, and CVE-2014-0424.

    Published: 14 Jan 2014
    10
    Critical

    CVE-2014-0422

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Oracle Java SE 5.0u55, 6u65, and 7u45; Java SE Embedded 7u45; and OpenJDK 7 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to JNDI. NOTE: the previous information is from the January 2014 CPU. Oracle has not commented on third-party claims that the issue is related to missing package access checks in the Naming / JNDI component, which allows attackers to escape the sandbox.

    Published: 14 Jan 2014
    3.5
    Low

    CVE-2014-0427

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.6.13 and earlier allows remote authenticated users to affect availability via vectors related to FTS.

    Published: 14 Jan 2014
    4.3
    Medium

    CVE-2014-0433

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.6.13 and earlier allows remote attackers to affect availability via unknown vectors related to Thread Pooling.

    Published: 14 Jan 2014
    10
    Critical

    CVE-2014-0492

    Last Modified: 11 Apr 2025

    Adobe Flash Player before 11.7.700.260 and 11.8.x and 11.9.x before 12.0.0.38 on Windows and Mac OS X and before 11.2.202.335 on Linux, Adobe AIR before 4.0.0.1390, Adobe AIR SDK before 4.0.0.1390, and Adobe AIR SDK & Compiler before 4.0.0.1390 allow attackers to defeat the ASLR protection mechanism by leveraging an "address leak."

    Published: 14 Jan 2014
    4
    Medium

    CVE-2013-5881

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.6.14 and earlier allows remote authenticated users to affect availability via unknown vectors related to InnoDB, a different vulnerability than CVE-2014-0431.

    Published: 14 Jan 2014
    9.3
    Critical

    CVE-2013-5889

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Oracle Java SE 6u65 and 7u45 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment, a different vulnerability than CVE-2013-5902, CVE-2014-0410, CVE-2014-0415, CVE-2014-0418, and CVE-2014-0424.

    Published: 14 Jan 2014
    9.3
    Critical

    CVE-2013-5893

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Oracle Java SE 7u45 and Java SE Embedded 7u45, and OpenJDK 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries. NOTE: the previous information is from the January 2014 CPU. Oracle has not commented on third-party claims that the issue is related to improper handling of methods in MethodHandles in HotSpot JVM, which allows attackers to escape the sandbox.

    Published: 14 Jan 2014
    4
    Medium

    CVE-2013-5898

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Oracle Java SE 6u65 and 7u45 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Deployment, a different vulnerability than CVE-2014-0375 and CVE-2014-0403.

    Published: 14 Jan 2014
    5
    Medium

    CVE-2013-5899

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Oracle Java SE 6u65 and 7u45 allows remote attackers to affect confidentiality via unknown vectors related to Deployment.

    Published: 14 Jan 2014
    5.1
    Medium

    CVE-2013-5902

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Oracle Java SE 6u65 and 7u45 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment, a different vulnerability than CVE-2013-5889, CVE-2014-0410, CVE-2014-0415, CVE-2014-0418, and CVE-2014-0424.

    Published: 14 Jan 2014
    10
    Critical

    CVE-2013-5907

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Oracle Java SE 5.0u55, 6u65, and 7u45; JRockit R27.7.7 and R28.2.9; Java SE Embedded 7u45; and OpenJDK 7 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D. NOTE: the previous information is from the January 2014 CPU. Oracle has not commented on third-party claims that the issue is due to incorrect input validation in LookupProcessor.cpp in the ICU Layout Engine, which allows attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted font file.

    Published: 14 Jan 2014
    6.8
    Medium

    CVE-2013-6429

    Last Modified: 11 Apr 2025

    The SourceHttpMessageConverter in Spring MVC in Spring Framework before 3.2.5 and 4.0.0.M1 through 4.0.0.RC1 does not disable external entity resolution, which allows remote attackers to read arbitrary files, cause a denial of service, and conduct CSRF attacks via crafted XML, aka an XML External Entity (XXE) issue, and a different vulnerability than CVE-2013-4152 and CVE-2013-7315.

    Published: 14 Jan 2014
    5.4
    Medium

    CVE-2013-6430

    Last Modified: 21 Nov 2024

    The JavaScriptUtils.javaScriptEscape method in web/util/JavaScriptUtils.java in Spring MVC in Spring Framework before 3.2.2 does not properly escape certain characters, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a (1) line separator or (2) paragraph separator Unicode character or (3) left or (4) right angle bracket.

    Published: 14 Jan 2014
    6.8
    Medium

    CVE-2013-6443

    Last Modified: 11 Apr 2025

    CloudForms 3.0 Management Engine before 5.2.1.6 allows remote attackers to bypass the Ruby on Rails protect_from_forgery mechanism and conduct cross-site request forgery (CSRF) attacks via a destructive action in a request.

    Published: 14 Jan 2014
    5
    Medium

    CVE-2014-0368

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Oracle Java SE 5.0u55, 6u65, and 7u45, and Java SE Embedded 7u45, allows remote attackers to affect confidentiality via unknown vectors related to Networking. NOTE: the previous information is from the January 2014 CPU. Oracle has not commented on third-party claims that the issue is related to incorrect permission checks when listening on a socket, which allows attackers to escape the sandbox.

    Published: 14 Jan 2014
    5.8
    Medium

    CVE-2014-0375

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Oracle Java SE 6u65 and 7u45 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Deployment, a different vulnerability than CVE-2013-5898 and CVE-2014-0403.

    Published: 14 Jan 2014
    4.3
    Medium

    CVE-2014-0382

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Oracle Java SE 7u45 and JavaFX 2.2.45 allows remote attackers to affect availability via unknown vectors related to JavaFX.

    Published: 14 Jan 2014
    4
    Medium

    CVE-2014-0402

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.71 and earlier, 5.5.33 and earlier, and 5.6.13 and earlier allows remote authenticated users to affect availability via unknown vectors related to Locking.

    Published: 14 Jan 2014
    5.8
    Medium

    CVE-2014-0403

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Oracle Java SE 6u65 and 7u45 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Deployment, a different vulnerability than CVE-2013-5898 and CVE-2014-0375.

    Published: 14 Jan 2014
    4
    Medium

    CVE-2014-0411

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Oracle Java SE 5.0u55, 6u65, and 7u45; JRockit R27.7.7 and R28.2.9; Java SE Embedded 7u45; and OpenJDK 7 allows remote attackers to affect confidentiality and integrity via vectors related to JSSE. NOTE: the previous information is from the January 2014 CPU. Oracle has not commented on third-party claims that this issue allows remote attackers to obtain sensitive information about encryption keys via a timing discrepancy during the TLS/SSL handshake.

    Published: 14 Jan 2014
    5
    Medium

    CVE-2014-0416

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Oracle Java SE 5.0u55, 6u65, and 7u45; Java SE Embedded 7u45; and OpenJDK 7 allows remote attackers to affect integrity via vectors related to JAAS. NOTE: the previous information is from the January 2014 CPU. Oracle has not commented on third-party claims that the issue is related to how principals are set for the Subject class, which allows attackers to escape the sandbox using deserialization of a crafted Subject instance.

    Published: 14 Jan 2014