Openjdk
Vendor:
First CVE: Mar 23, 2009 · Active for 17 years
17
Total CVEs
More Total CVEs than 93% of tracked products
8.5
Avg CVEs / Year
Higher CVE frequency than 94% of tracked products
7.2
Avg CVSS
Higher Avg CVSS than 45% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Openjdk over time
Volume of CVEsAvg CVSS Base Score
First CVE
Mar 23, 2009
17 years ago
Most Recent CVE
Jan 20, 2011
5,664 days ago
CVE Severity & Scoring
Openjdk17 CVEs
41%
59%
All CVEs352,231 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown17 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown17 (100.0%)
User Interaction
None0 (0.0%)
Unknown17 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown17 (100.0%)
Top CVEs
Signals from CVEs in this product scope (17 CVEs).
17 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2009-2476HIGH The Java Management Extensions (JMX) implementation in Sun Java SE 6 before Update 15, and OpenJDK, does not properly enforce OpenType checks, which allows context-dependent attack | Aug 10, 2009 | 10.0 | 29 | NO | NO |
CVE-2009-1896HIGH The Java Web Start framework in IcedTea in OpenJDK before 1.6.0.0-20.b16.fc10 on Fedora 10, and before 1.6.0.0-27.b16.fc11 on Fedora 11, trusts an entire application when at least | Aug 10, 2009 | 10.0 | 28 | NO | NO |
CVE-2009-0733HIGH Multiple stack-based buffer overflows in the ReadSetOfCurves function in LittleCMS (aka lcms or liblcms) before 1.18beta2, as used in Firefox 3.1beta, OpenJDK, and GIMP, allow cont | Mar 23, 2009 | 9.3 | 28 | NO | NO |
CVE-2009-0723HIGH Multiple integer overflows in LittleCMS (aka lcms or liblcms) before 1.18beta2, as used in Firefox 3.1beta, OpenJDK, and GIMP, allow context-dependent attackers to execute arbitrar | Mar 23, 2009 | 9.3 | 28 | NO | NO |
CVE-2009-2689HIGH JDK13Services.getProviders in Sun Java SE 5.0 before Update 20 and 6 before Update 15, and OpenJDK, grants full privileges to instances of unspecified object types, which allows co | Aug 10, 2009 | 10.0 | 27 | NO | NO |
CVE-2010-4351MEDIUM The JNLP SecurityManager in IcedTea (IcedTea.so) 1.7 before 1.7.7, 1.8 before 1.8.4, and 1.9 before 1.9.4 for Java OpenJDK returns from the checkPermission method instead of throwi | Jan 20, 2011 | 6.8 | 23 | NO | NO |
CVE-2009-2475HIGH Sun Java SE 5.0 before Update 20 and 6 before Update 15, and OpenJDK, might allow context-dependent attackers to obtain sensitive information via vectors involving static variables | Aug 10, 2009 | 7.8 | 22 | NO | NO |
CVE-2009-3881HIGH Sun Java SE 5.0 before Update 22 and 6 before Update 17, and OpenJDK, does not prevent the existence of children of a resurrected ClassLoader, which allows remote attackers to gain | Nov 9, 2009 | 7.5 | 21 | NO | NO |
CVE-2009-3883HIGH Multiple unspecified vulnerabilities in the Windows Pluggable Look and Feel (PL&F) feature in the Swing implementation in Sun Java SE 5.0 before Update 22 and 6 before Update 17, a | Nov 9, 2009 | 7.5 | 20 | NO | NO |
CVE-2009-3882HIGH Multiple unspecified vulnerabilities in the Swing implementation in Sun Java SE 5.0 before Update 22 and 6 before Update 17, and OpenJDK, have unknown impact and remote attack vect | Nov 9, 2009 | 7.5 | 20 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (17 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (17 CVEs).
Media Mentions
Signals from CVEs in this product scope (17 CVEs).
Top CNAs Publishing CVEs For Openjdk
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 6 | 1 | 4.3 | 4.8% | 0 | 0 |
| 1.6.0.0 | 1 | 5.0 | 3.0% | 0 | 0 |