Openjdk

Vendor:

First CVE: Mar 23, 2009 · Active for 17 years

98
Total CVEs
More Total CVEs than 99% of tracked products
8.9
Avg CVEs / Year
Higher CVE frequency than 95% of tracked products
5.4
Avg CVSS
Higher Avg CVSS than 11% of tracked products
1.0%
KEV Rate
Higher KEV Rate than 96% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Openjdk over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 23, 2009
17 years ago
Most Recent CVE
Jan 16, 2024
920 days ago

CVE Severity & Scoring

Openjdk98 CVEs
All CVEs352,294 CVEs
LowMediumHigh
Attack Vector
Local3 (3.1%)
Network85 (86.7%)
Unknown10 (10.2%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low40 (40.8%)
High48 (49.0%)
Unknown10 (10.2%)
User Interaction
None73 (74.5%)
Unknown10 (10.2%)
Required15 (15.3%)
Privileges Required
Low3 (3.1%)
High0 (0.0%)
None85 (86.7%)
Unknown10 (10.2%)

Top CVEs

Signals from CVEs in this product scope (98 CVEs).

98 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, and OpenJDK 7, allows user-assisted remote attackers to bypass the
Jan 31, 20135.397YESYES
The Apache Xalan Java XSLT library is vulnerable to an integer truncation issue when processing malicious XSLT stylesheets. This can be used to corrupt Java class files generated b
Jul 19, 20227.542NONO
The TLS protocol 1.1 and 1.2 and the DTLS protocol 1.0 and 1.2, as used in OpenSSL, OpenJDK, PolarSSL, and other products, do not properly consider timing side-channel attacks on a
Feb 8, 20132.636NONO
There is a flaw in the xml entity encoding functionality of libxml2 in versions before 2.9.11. An attacker who is able to supply a crafted file to be processed by an application li
May 19, 20218.631NONO
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Serialization). Supported versions that are affected are Java SE: 7u241, 8u231, 11.0.5 and 13.0
Jan 15, 20208.128NONO
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier and 6 Update 45 and earlier; the Oracle JRockit component in Ora
Jun 18, 20137.528NONO
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Oracle Java SE: 7u
Apr 19, 20227.527NONO
Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JSSE). Supported versions that are affected are Java SE: 7u311, 8u301, 11.0.12
Oct 20, 20215.927NONO
Vulnerability in the Java SE product of Oracle Java SE (component: Deployment). The supported version that is affected is Java SE: 8u301. Difficult to exploit vulnerability allows
Oct 20, 20217.526NONO
Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Swing). Supported versions that are affected are Java SE: 7u311, 8u301, 11.0.1
Oct 20, 20215.326NONO

Exploit Exposure

Signals from CVEs in this product scope (98 CVEs).

CISA KEV
1 CVE
1.0% of CVEs· 96th percentile
Metasploit
1 CVE
1.0% of CVEs· 96th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
1.0% of CVEs· 87th percentile

Social Chatter

Signals from CVEs in this product scope (98 CVEs).

Media Mentions

Signals from CVEs in this product scope (98 CVEs).

Top CNAs Publishing CVEs For Openjdk

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
8825.23.9%00
7665.14.5%11
2075.11.5%00
1.8.035.71.3%00
1846.511.0%00
17.0.1155.23.9%00
1.7.053.927.8%00
17235.24.8%00
16.0.216.82.7%00
16.0.145.43.6%00
1.6.053.132.1%00
1665.53.5%00
15.0.416.82.7%00
15.0.345.43.6%00
15.0.245.43.6%00
15.0.145.43.6%00
15124.33.0%00
14195.33.8%00
13.0.816.82.7%00
13.0.745.43.6%00