Jrockit
Vendor:
First CVE: Apr 15, 2009 · Active for 17 years
107
Total CVEs
More Total CVEs than 99% of tracked products
11.9
Avg CVEs / Year
Higher CVE frequency than 97% of tracked products
6.0
Avg CVSS
Higher Avg CVSS than 24% of tracked products
0.9%
KEV Rate
Higher KEV Rate than 97% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Jrockit over time
Volume of CVEsAvg CVSS Base Score
First CVE
Apr 15, 2009
17 years ago
Most Recent CVE
Oct 17, 2018
2,840 days ago
CVE Severity & Scoring
Jrockit107 CVEs
12%
56%
29%
All CVEs352,785 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local3 (2.8%)
Network54 (50.5%)
Unknown50 (46.7%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low29 (27.1%)
High28 (26.2%)
Unknown50 (46.7%)
User Interaction
None45 (42.1%)
Unknown50 (46.7%)
Required12 (11.2%)
Privileges Required
Low3 (2.8%)
High0 (0.0%)
None54 (50.5%)
Unknown50 (46.7%)
Top CVEs
Signals from CVEs in this product scope (107 CVEs).
107 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-3427CRITICAL Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to affect confidentiality, integrity, and avai | Apr 21, 2016 | 9.8 | 95 | YES | NO |
CVE-2011-3556HIGH Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7, 6 Update 27 and earlier, 5.0 Update 31 and earlier, 1.4.2_33 and earlier, and J | Oct 19, 2011 | 7.5 | 83 | NO | YES |
The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a server but not on a client, does not properly convey a DHE_EXPORT choice, which allows man-in-the-mi | May 21, 2015 | 3.7 | 76 | NO | YES |
CVE-2014-6593MEDIUM Unspecified vulnerability in Oracle Java SE 5.0u75, 6u85, 7u72, and 8u25; Java SE Embedded 7u71 and 8u6; and JRockit 27.8.4 and 28.3.4 allows remote attackers to affect confidentia | Jan 21, 2015 | 4.0 | 71 | NO | YES |
CVE-2017-3241CRITICAL Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: RMI). Supported versions that are affected are Java SE: 6u131, 7u121 and 8u112; J | Jan 27, 2017 | 9.0 | 52 | NO | YES |
CVE-2015-4748HIGH Unspecified vulnerability in Oracle Java SE 6u95, 7u80, and 8u45; JRockit R28.3.6; and Java SE Embedded 7u75 and Embedded 8u33 allows remote attackers to affect confidentiality, in | Jul 16, 2015 | 7.6 | 48 | NO | NO |
CVE-2014-2421HIGH Unspecified vulnerability in Oracle Java SE 5.0u61, 6u71, 7u51, and 8; JavaFX 2.2.51; and Java SE Embedded 7u51 allows remote attackers to affect confidentiality, integrity, and av | Apr 16, 2014 | 10.0 | 36 | NO | NO |
CVE-2013-5782HIGH Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, JRockit R28.2.8 and earlier, JRockit R27.7.6 and earlier, and Ja | Oct 16, 2013 | 10.0 | 36 | NO | NO |
CVE-2013-5830HIGH Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, JRockit R28.2.8 and earlier, JRockit R27.7.6 and earlier, and Ja | Oct 16, 2013 | 10.0 | 35 | NO | NO |
CVE-2016-0483HIGH Unspecified vulnerability in Oracle Java SE 6u105, 7u91, and 8u66; Java SE Embedded 8u65; and JRockit R28.3.8 allows remote attackers to affect confidentiality, integrity, and avai | Jan 21, 2016 | 10.0 | 34 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (107 CVEs).
CISA KEV
1 CVE
0.9% of CVEs· 97th percentile
Metasploit
3 CVEs
2.8% of CVEs· 97th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
4 CVEs
3.7% of CVEs· 85th percentile
Social Chatter
Signals from CVEs in this product scope (107 CVEs).
Media Mentions
Signals from CVEs in this product scope (107 CVEs).
Top CNAs Publishing CVEs For Jrockit
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| r28.3.9 | 3 | 6.7 | 33.2% | 1 | 0 |
| r28.3.8 | 2 | 7.9 | 9.2% | 0 | 0 |
| r28.3.7 | 4 | 5.0 | 4.7% | 0 | 0 |
| r28.3.6 | 5 | 4.6 | 31.0% | 0 | 1 |
| r28.3.5 | 2 | 4.7 | 3.3% | 0 | 0 |
| r28.3.4 | 3 | 4.8 | 24.2% | 0 | 1 |
| r28.3.3 | 4 | 4.0 | 3.4% | 0 | 0 |
| r28.3.2 | 2 | 4.0 | 3.5% | 0 | 0 |
| r28.3.19 | 4 | 7.0 | 5.1% | 0 | 0 |
| r28.3.18 | 1 | 3.7 | 4.2% | 0 | 0 |
| r28.3.17 | 9 | 5.7 | 6.7% | 0 | 0 |
| r28.3.16 | 11 | 5.3 | 5.0% | 0 | 0 |
| r28.3.15 | 4 | 4.4 | 6.0% | 0 | 1 |
| r28.3.14 | 10 | 6.6 | 3.2% | 0 | 0 |
| r28.3.13 | 5 | 5.9 | 2.2% | 0 | 0 |
| r28.3.12 | 6 | 6.7 | 8.0% | 0 | 1 |
| r28.3.10 | 3 | 4.5 | 3.4% | 0 | 0 |
| r28.3.1 | 7 | 7.6 | 5.7% | 0 | 0 |
| r28.2.9 | 3 | 6.5 | 4.8% | 0 | 0 |
| r28.2.6 | 8 | 5.5 | 4.2% | 0 | 0 |