Openjdk

Vendor:

First CVE: Mar 23, 2009 · Active for 17 years

17
Total CVEs
More Total CVEs than 93% of tracked products
8.5
Avg CVEs / Year
Higher CVE frequency than 94% of tracked products
7.2
Avg CVSS
Higher Avg CVSS than 45% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Openjdk over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 23, 2009
17 years ago
Most Recent CVE
Jan 20, 2011
5,664 days ago

CVE Severity & Scoring

Openjdk17 CVEs
All CVEs352,231 CVEs
MediumHigh
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown17 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown17 (100.0%)
User Interaction
None0 (0.0%)
Unknown17 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown17 (100.0%)

Top CVEs

Signals from CVEs in this product scope (17 CVEs).

17 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
The Java Management Extensions (JMX) implementation in Sun Java SE 6 before Update 15, and OpenJDK, does not properly enforce OpenType checks, which allows context-dependent attack
Aug 10, 200910.029NONO
The Java Web Start framework in IcedTea in OpenJDK before 1.6.0.0-20.b16.fc10 on Fedora 10, and before 1.6.0.0-27.b16.fc11 on Fedora 11, trusts an entire application when at least
Aug 10, 200910.028NONO
Multiple stack-based buffer overflows in the ReadSetOfCurves function in LittleCMS (aka lcms or liblcms) before 1.18beta2, as used in Firefox 3.1beta, OpenJDK, and GIMP, allow cont
Mar 23, 20099.328NONO
Multiple integer overflows in LittleCMS (aka lcms or liblcms) before 1.18beta2, as used in Firefox 3.1beta, OpenJDK, and GIMP, allow context-dependent attackers to execute arbitrar
Mar 23, 20099.328NONO
JDK13Services.getProviders in Sun Java SE 5.0 before Update 20 and 6 before Update 15, and OpenJDK, grants full privileges to instances of unspecified object types, which allows co
Aug 10, 200910.027NONO
The JNLP SecurityManager in IcedTea (IcedTea.so) 1.7 before 1.7.7, 1.8 before 1.8.4, and 1.9 before 1.9.4 for Java OpenJDK returns from the checkPermission method instead of throwi
Jan 20, 20116.823NONO
Sun Java SE 5.0 before Update 20 and 6 before Update 15, and OpenJDK, might allow context-dependent attackers to obtain sensitive information via vectors involving static variables
Aug 10, 20097.822NONO
Sun Java SE 5.0 before Update 22 and 6 before Update 17, and OpenJDK, does not prevent the existence of children of a resurrected ClassLoader, which allows remote attackers to gain
Nov 9, 20097.521NONO
Multiple unspecified vulnerabilities in the Windows Pluggable Look and Feel (PL&F) feature in the Swing implementation in Sun Java SE 5.0 before Update 22 and 6 before Update 17, a
Nov 9, 20097.520NONO
Multiple unspecified vulnerabilities in the Swing implementation in Sun Java SE 5.0 before Update 22 and 6 before Update 17, and OpenJDK, have unknown impact and remote attack vect
Nov 9, 20097.520NONO

Exploit Exposure

Signals from CVEs in this product scope (17 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (17 CVEs).

Media Mentions

Signals from CVEs in this product scope (17 CVEs).

Top CNAs Publishing CVEs For Openjdk

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
614.34.8%00
1.6.0.015.03.0%00