Oracle Java SE 6u75, 7u55 and 8u5 fixes an unspecified vulnerability in the Deployment component (CVE-2014-0449). Upstream has CVSSv2 scored this issue as: 5.0/AV:N/AC:L/Au:N/C:P/I:N/A:N
External Reference:
http://www.oracle.com/technetwork/topics/security/cpuapr2014-1972952.html#AppendixJAVA
Oracle Java SE 5.0u75, 6u75, 7u55 and 8u5 fixes an unspecified vulnerability in the 2D component (CVE-2014-2401). Upstream has CVSSv2 scored this issue as: 5.0/AV:N/AC:L/Au:N/C:P/I:N/A:N
External Reference:
http://www.oracle.com/technetwork/topics/security/cpuapr2014-1972952.html#AppendixJAVA
Oracle Java SE 6u75, 7u55 and 8u5 fixes an unspecified vulnerability in the Deployment component (CVE-2014-2428). Upstream has CVSSv2 scored this issue as: 7.6/AV:N/AC:H/Au:N/C:C/I:C/A:C
External Reference:
http://www.oracle.com/technetwork/topics/security/cpuapr2014-1972952.html#AppendixJAVA
Oracle Java SE 6u75, 7u55 and 8u5 fixes an unspecified vulnerability in the Deployment component (CVE-2014-2409). Upstream has CVSSv2 scored this issue as: 6.4/AV:N/AC:L/Au:N/C:P/I:P/A:N
External Reference:
http://www.oracle.com/technetwork/topics/security/cpuapr2014-1972952.html#AppendixJAVA
Oracle Java SE 6u75, 7u55 and 8u5 fixes an unspecified vulnerability in the Deployment component (CVE-2014-2420). Upstream has CVSSv2 scored this issue as: 2.6/AV:N/AC:H/Au:N/C:N/I:P/A:N
External Reference:
http://www.oracle.com/technetwork/topics/security/cpuapr2014-1972952.html#AppendixJAVA
Oracle Java SE 7u55 and 8u5 fixes an unspecified vulnerability in the Deployment component (CVE-2014-0448). Upstream has CVSSv2 scored this issue as: 7.6/AV:N/AC:H/Au:N/C:C/I:C/A:C
External Reference:
http://www.oracle.com/technetwork/topics/security/cpuapr2014-1972952.html#AppendixJAVA
Oracle Java SE 7u55 and 8u5 fixes an unspecified vulnerability in the Libraries component (CVE-2014-0432). Upstream has CVSSv2 scored this issue as: 9.3/AV:N/AC:M/Au:N/C:C/I:C/A:C
External Reference:
http://www.oracle.com/technetwork/topics/security/cpuapr2014-1972952.html#AppendixJAVA
Oracle Java SE 7u55 and 8u5 fixes an unspecified vulnerability in the JavaFX component (CVE-2014-2422). Upstream has CVSSv2 scored this issue as: 6.8/AV:N/AC:M/Au:N/C:P/I:P/A:P
External Reference:
http://www.oracle.com/technetwork/topics/security/cpuapr2014-1972952.html#AppendixJAVA
It was discovered that direct method handles are not properly protected against a certain use case. An untrusted Java application or applet could possibly use this flaw to bypass call hierachies.
It was discovered that ICC profiles were not parsed correctly. An untrusted Java application or applet could possibly use this flaw to cause a denial of service.
It was discovered that JAXP the CharInfo object did not properly prevent access to arbitrary files when a SecurityManager is present. An untrusted Java application or applet could possibly use this flaw to disclose sensitive information.
It was discovered that the JNDI DNS client did not properly randomize the DNS query ID. A remote attacker could exploit this flaw to e.g. perfom DNS spoofing attacks.
It was discovered that Java Sound provider caching mechanism is insecure. An untrusted Java application or applet could possibly use this flaw to bypass Java sandbox restrictions.
It was discovered that the AlgorithmChecker and SignatureAndHashAlgorithm classes did not properly prevent the SIGNATUREPRIMITIVESET set from being modified. An untrusted Java application or applet could possibly use this flaw to alter the content of the SIGNATUREPRIMITIVESET set.
It was discovered that the system logger was not properly protected against using handlers of custom loggers created prior to the system logger. An untrusted Java application or applet could possibly use this flaw to bypass Java sandbox restrictions.
It was discovered that JAXWS incorrectly cached certain data initialized via thread context class loaders. An untrusted Java application or applet could possibly use this flaw to bypass Java sandbox restrictions.
It was discovered that NIO channels were not properly separated across threads. An untrusted Java application or applet could possibly use this flaw to bypass Java sandbox restrictions.
It was discovered that JAXWS incorrectly cached certain data initialized via thread context class loaders. An untrusted Java application or applet could possibly use this flaw to bypass Java sandbox restrictions.
It was discovered that JAXB incorrectly cached certain data initialized via thread context class loaders. An untrusted Java application or applet could possibly use this flaw to bypass Java sandbox restrictions.
It was discovered that the activation framework did not properly protect the default command map. An untrusted Java application or applet could possibly use this flaw to bypass Java sandbox restrictions.
It was discovered that FlavorMaps were not properly seperated between different AppContexts. An untrusted Java application or applet could possibly use this flaw to bypass Java sandbox restrictions.
It was discovered that the AWT toolkit did not properly handle the toolkit threads. An untrusted Java application or applet could possibly use this flaw to bypass Java sandbox restrictions.
It was discovered that the ScriptEngineManager did not properly manage ScriptEngines. An untrusted Java application or applet could possibly use this flaw to bypass Java sandbox restrictions.
It was discovered that MethodHandle did not properly handle variable argument lists when permuting or dropping arguments. An untrusted Java application or applet could possibly use this flaw to bypass Java sandbox restrictions.
It was discovered that the class file parser did not properly parse class files with an invalid BootstrapMethods attribute length. An untrusted Java application or applet could possibly use this flaw to bypass Java sandbox restrictions.
It was discovered that the JPEG decoder did not properly handle certain input streams. An untrusted Java application or applet could possibly use this flaw to trigger a Java Virtual Machine memory corruption.
It was discovered that the System.arraycopy() method has a race condition between verifying source elements and storing them. An untrusted Java application or applet could possibly use this flaw to trigger a Java Virtual Machine memory corruption.
It was discovered that the ServiceLoader did not perform exception handling in a secure manner. An untrusted Java application or applet could possibly use this flaw to bypass security mechanisms and perform operations with full permissions.
It was discovered that certain medialib operations do not properly validate that mlib and raster images correspond to each other. A remote attacker could possibly use this flaw to trigger a Java Virtual Machine memory corruption.
It was discovered that the Security component in OpenJDK could leak some timing information when preforming PKCS#1 unpadding. This could possibly lead to disclosure of some information meant to be protected by encryption.
This fix improves the fix for CVE-2014-0411 (bug 1053010) applied via via Oracle CPU January 2014.