«
Expand/Collapse
744 items tagged "oracle java"
Related tags:
vulnerability [+],
safer use [+],
java web start [+],
java [+],
stack overflow [+],
overflow vulnerability [+],
integer overflow [+],
user [+],
denial of service [+],
service vulnerability [+],
security [+],
overflow error [+],
integer [+],
environment [+],
code execution [+],
zero day [+],
web [+],
static array [+],
script engine [+],
rhino [+],
private fields [+],
point [+],
opcode [+],
malicious applet [+],
linux security [+],
java webstart [+],
java process [+],
java extension [+],
heap memory [+],
font [+],
debian linux [+],
advisory [+],
start [+],
secunia [+],
ntlm [+],
javascript [+],
oracle [+],
business [+],
zip [+],
zdi [+],
util [+],
update [+],
true [+],
tpti [+],
telus [+],
sun [+],
software development kit [+],
segmentation fault [+],
security advisory [+],
retired [+],
red hat security [+],
red [+],
java vm args [+],
java db [+],
integer overflow vulnerability [+],
icc [+],
francisco amato [+],
debian [+],
d vulnerability [+],
critical patch [+],
applet [+],
advance notification [+],
cve [+],
java runtime environment [+],
remote [+],
information disclosure vulnerability [+],
code [+],
runtime [+],
zero [+],
day [+],
vupen,
vulnerability research,
vulnerabilities,
vuln,
value,
txt,
system clipboard,
system,
stack buffer,
server vulnerability,
sequence description,
security vulnerability,
scrn,
research,
remote security,
profile sequence,
poc,
overflow code,
ntlm authentication,
new java,
midi stream,
memory corruption,
malicious users,
jre,
jfilechooser,
java virtual machine,
java user,
java runtime,
java plugin,
java plug,
java jfilechooser,
java implementation,
java applet tag,
java 2d,
initiative,
hook code,
heap allocation,
glsa,
gentoo linux security,
decompression code,
data,
critical vulnerability,
command line parameters,
clipboard,
byte value,
business march,
buffer overflow vulnerability,
browser policies,
authentication,
arithmetic operation,
activex plugin,
activex
-
-
8:03
»
Packet Storm Security Advisories
Debian Linux Security Advisory 2420-1 - Several vulnerabilities have been discovered in OpenJDK, an implementation of the Oracle Java platform.
-
8:03
»
Packet Storm Security Misc. Files
Debian Linux Security Advisory 2420-1 - Several vulnerabilities have been discovered in OpenJDK, an implementation of the Oracle Java platform.
-
-
21:32
»
Packet Storm Security Advisories
Zero Day Initiative Advisory 12-039 - This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Oracle Java. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the way Java Webstart handles the 'java-vm-args' parameter in the j2se tag within a jnlp file. Due to insufficient sanitation it is possible to add additional double quotes to the commandline argument string used to start a new java process. This can lead to remote code execution under the rights of the current user.
-
21:32
»
Packet Storm Security Recent Files
Zero Day Initiative Advisory 12-039 - This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Oracle Java. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the way Java Webstart handles the 'java-vm-args' parameter in the j2se tag within a jnlp file. Due to insufficient sanitation it is possible to add additional double quotes to the commandline argument string used to start a new java process. This can lead to remote code execution under the rights of the current user.
-
21:32
»
Packet Storm Security Misc. Files
Zero Day Initiative Advisory 12-039 - This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Oracle Java. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the way Java Webstart handles the 'java-vm-args' parameter in the j2se tag within a jnlp file. Due to insufficient sanitation it is possible to add additional double quotes to the commandline argument string used to start a new java process. This can lead to remote code execution under the rights of the current user.
-
21:30
»
Packet Storm Security Advisories
A vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Oracle Java. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the way Java handles True Type Font files. When reading a font file, Java will use the MaxInstructionSize from the maxp table to create a heap memory location to store all the Instruction Definition found in the Font Program 'fpgm' table. However, when Java encounters an IDEF opcode (0x89) in the opcode stream it never checks the size of the MaxInstructionSize which can result in a heap buffer overflow. This can lead to remote code execution under the context of the current process.
-
21:30
»
Packet Storm Security Recent Files
A vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Oracle Java. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the way Java handles True Type Font files. When reading a font file, Java will use the MaxInstructionSize from the maxp table to create a heap memory location to store all the Instruction Definition found in the Font Program 'fpgm' table. However, when Java encounters an IDEF opcode (0x89) in the opcode stream it never checks the size of the MaxInstructionSize which can result in a heap buffer overflow. This can lead to remote code execution under the context of the current process.
-
21:30
»
Packet Storm Security Misc. Files
A vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Oracle Java. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the way Java handles True Type Font files. When reading a font file, Java will use the MaxInstructionSize from the maxp table to create a heap memory location to store all the Instruction Definition found in the Font Program 'fpgm' table. However, when Java encounters an IDEF opcode (0x89) in the opcode stream it never checks the size of the MaxInstructionSize which can result in a heap buffer overflow. This can lead to remote code execution under the context of the current process.
-
21:22
»
Packet Storm Security Advisories
Zero Day Initiative Advisory 12-038 - This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Oracle Java. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within JavaFX, a downloadable Java extension. The JavaFX Jar file is signed by Oracle and can be installed without user interaction. Once installed it is possible to invoke the main method of any trusted class with arbitrary arguments and with a trusted call stack. This can be leveraged to remote code execution under the context of the user.
-
21:22
»
Packet Storm Security Recent Files
Zero Day Initiative Advisory 12-038 - This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Oracle Java. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within JavaFX, a downloadable Java extension. The JavaFX Jar file is signed by Oracle and can be installed without user interaction. Once installed it is possible to invoke the main method of any trusted class with arbitrary arguments and with a trusted call stack. This can be leveraged to remote code execution under the context of the user.
-
21:22
»
Packet Storm Security Misc. Files
Zero Day Initiative Advisory 12-038 - This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Oracle Java. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within JavaFX, a downloadable Java extension. The JavaFX Jar file is signed by Oracle and can be installed without user interaction. Once installed it is possible to invoke the main method of any trusted class with arbitrary arguments and with a trusted call stack. This can be leveraged to remote code execution under the context of the user.
-
-
18:37
»
Packet Storm Security Advisories
PRE-CERT Security Advisory - The function countCENHeaders() in zip_util.c of the java.util.zip implementation contains an off-by-one bug. The bug can be exploited via corrupted ZIP files to cause an endless recursion. The endless recursion results in a segmentation fault of the JVM. Oracle Java SE and IcedTea6 have multiple affected versions.
-
18:33
»
Packet Storm Security Advisories
Red Hat Security Advisory 2012-0139-01 - The Sun 1.6.0 Java release includes the Sun Java 6 Runtime Environment and the Sun Java 6 Software Development Kit. This update fixes several vulnerabilities in the Sun Java 6 Runtime Environment and the Sun Java 6 Software Development Kit. Further information about these flaws can be found on the Oracle Java SE Critical Patch page, listed in the References section. All users of java-1.6.0-sun are advised to upgrade to these updated packages, which provide JDK and JRE 6 Update 31 and resolve these issues. All running instances of Sun Java must be restarted for the update to take effect.
-
-
19:33
»
Packet Storm Security Advisories
A Java Web Start vulnerability exists in Oracle Java. The vulnerability can be exploited by remote unauthenticated attackers to execute arbitrary code on a vulnerable system.
-
19:33
»
Packet Storm Security Recent Files
A Java Web Start vulnerability exists in Oracle Java. The vulnerability can be exploited by remote unauthenticated attackers to execute arbitrary code on a vulnerable system.
-
19:33
»
Packet Storm Security Misc. Files
A Java Web Start vulnerability exists in Oracle Java. The vulnerability can be exploited by remote unauthenticated attackers to execute arbitrary code on a vulnerable system.
-
-
23:03
»
Packet Storm Security Advisories
Secunia Security Advisory - Multiple vulnerabilities have been reported in Oracle Java SE, which can be exploited by malicious people to disclose potentially sensitive information, manipulate certain data, cause a DoS (Denial of Service), and compromise a vulnerable system.
-
-
11:34
»
SecuriTeam
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Oracle Java.
-
Make your website safer. Use external penetration testing service. First report ready in one hour!
-
-
14:14
»
SecuriTeam
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Oracle Java.
-
Make your website safer. Use external penetration testing service. First report ready in one hour!
-
-
22:03
»
Packet Storm Security Advisories
Secunia Security Advisory - Francisco Amato has reported a vulnerability in Oracle Java, which can be exploited by malicious people to conduct spoofing attacks.
-
-
13:34
»
SecuriTeam
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of the Oracle Java Runtime.
-
Make your website safer. Use external penetration testing service. First report ready in one hour!
-
-
11:34
»
SecuriTeam
Oracle Java contains a vulnerability caused by an integer overflow error in the Color Management Module (CMM)
-
Make your website safer. Use external penetration testing service. First report ready in one hour!
-
-
21:14
»
SecuriTeam
Oracle Java Contains a vulnerability caused by an integer overflow error in the Color Management Module (CMM).
-
Make your website safer. Use external penetration testing service. First report ready in one hour!
-
21:14
»
SecuriTeam
Oracle Java contains an integer overflow vulnerability in the Color Management Module (CMM.).
-
Make your website safer. Use external penetration testing service. First report ready in one hour!
-
-
10:34
»
SecuriTeam
Oracle Java contains a vulnerability caused by an integer overflow error in the Color Management Module (CMM).
-
Make your website safer. Use external penetration testing service. First report ready in one hour!
-
10:29
»
SecuriTeam
Oracle Java contains a vulnerability caused by an integer overflow error in the Color Management Module (CMM).
-
Make your website safer. Use external penetration testing service. First report ready in one hour!
-
10:29
»
SecuriTeam
Oracle Java ICC Profile Contains an Integer Overflow and Code Execution Vulnerability.
-
Make your website safer. Use external penetration testing service. First report ready in one hour!
-
-
19:04
»
SecuriTeam
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Oracle Java Runtime.
-
Make your website safer. Use external penetration testing service. First report ready in one hour!
-
18:59
»
SecuriTeam
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of the Oracle Java Runtime running on OSX or Linux.
-
Make your website safer. Use external penetration testing service. First report ready in one hour!
-
18:54
»
SecuriTeam
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Oracle Java.
-
Make your website safer. Use external penetration testing service. First report ready in one hour!
-
-
13:44
»
SecuriTeam
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of the Oracle Java Runtime.
-
Make your website safer. Use external penetration testing service. First report ready in one hour!
-
13:34
»
SecuriTeam
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of the Oracle Java Runtime.
-
Make your website safer. Use external penetration testing service. First report ready in one hour!
-
13:34
»
SecuriTeam
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of the Oracle Java Runtime.
-
Make your website safer. Use external penetration testing service. First report ready in one hour!
-
-
16:20
»
Packet Storm Security Advisories
Zero Day Initiative Advisory 11-307 - This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Oracle Java. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists because Java does not sufficiently verify parameters certain functions. The function MixerSequencer.nAddControllerEventCallback fails to check for negative index numbers before writing user supplied data into a static array. This allows a malicious applet to write user controlled data outside the array boundaries resulting in remote code execution under the context of the current user.
-
16:20
»
Packet Storm Security Recent Files
Zero Day Initiative Advisory 11-307 - This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Oracle Java. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists because Java does not sufficiently verify parameters certain functions. The function MixerSequencer.nAddControllerEventCallback fails to check for negative index numbers before writing user supplied data into a static array. This allows a malicious applet to write user controlled data outside the array boundaries resulting in remote code execution under the context of the current user.
-
16:20
»
Packet Storm Security Misc. Files
Zero Day Initiative Advisory 11-307 - This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Oracle Java. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists because Java does not sufficiently verify parameters certain functions. The function MixerSequencer.nAddControllerEventCallback fails to check for negative index numbers before writing user supplied data into a static array. This allows a malicious applet to write user controlled data outside the array boundaries resulting in remote code execution under the context of the current user.
-
16:15
»
Packet Storm Security Advisories
Zero Day Initiative Advisory 11-306 - This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Oracle Java. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the way Java handles IIOP deserialization. Due to insufficient type checking it is possible to trick java into allowing access to otherwise protected and private fields in built-in objects. This could be used, for example, to disable to security manager normally in place for applets. This leads to remote code execution under the context of the current user.
-
16:15
»
Packet Storm Security Recent Files
Zero Day Initiative Advisory 11-306 - This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Oracle Java. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the way Java handles IIOP deserialization. Due to insufficient type checking it is possible to trick java into allowing access to otherwise protected and private fields in built-in objects. This could be used, for example, to disable to security manager normally in place for applets. This leads to remote code execution under the context of the current user.
-
16:15
»
Packet Storm Security Misc. Files
Zero Day Initiative Advisory 11-306 - This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Oracle Java. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the way Java handles IIOP deserialization. Due to insufficient type checking it is possible to trick java into allowing access to otherwise protected and private fields in built-in objects. This could be used, for example, to disable to security manager normally in place for applets. This leads to remote code execution under the context of the current user.
-
16:15
»
Packet Storm Security Advisories
Zero Day Initiative Advisory 11-305 - This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Oracle Java. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the way Java handles Rhino Javascript errors. The built-in javascript engine in Java fails to perform sufficient sanitation on javascript error objects. The effect is that untrusted code can run in privileged context. This can result in remote code execution under the context of the current user.
-
16:15
»
Packet Storm Security Recent Files
Zero Day Initiative Advisory 11-305 - This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Oracle Java. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the way Java handles Rhino Javascript errors. The built-in javascript engine in Java fails to perform sufficient sanitation on javascript error objects. The effect is that untrusted code can run in privileged context. This can result in remote code execution under the context of the current user.
-
16:15
»
Packet Storm Security Misc. Files
Zero Day Initiative Advisory 11-305 - This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Oracle Java. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the way Java handles Rhino Javascript errors. The built-in javascript engine in Java fails to perform sufficient sanitation on javascript error objects. The effect is that untrusted code can run in privileged context. This can result in remote code execution under the context of the current user.