java-21-amazon-corretto-headless vulnerabilities

Direct Vulnerabilities

Known vulnerabilities in the java-21-amazon-corretto-headless package. This does not include vulnerabilities belonging to this package’s dependencies.

How to fix?

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

Fix for free
VulnerabilityVulnerable Version
  • M
Signed to Unsigned Conversion Error

<1:21.0.6+7-1.amzn2023.1
  • M
Signed to Unsigned Conversion Error

<1:21.0.5+11-1.amzn2023.1
  • M
Integer Overflow or Wraparound

<1:21.0.5+11-1.amzn2023.1
  • M
Uncontrolled Memory Allocation

<1:21.0.5+11-1.amzn2023.1
  • M
Improper Handling of Length Parameter Inconsistency

<1:21.0.5+11-1.amzn2023.1
  • H
Out-of-bounds Read

<1:21.0.4+7-1.amzn2023.1
  • H
Loop with Unreachable Exit Condition ('Infinite Loop')

<1:21.0.4+7-1.amzn2023.1
  • H
CVE-2024-21131

<1:21.0.4+7-1.amzn2023.1
  • H
CVE-2024-21147

<1:21.0.4+7-1.amzn2023.1
  • H
CVE-2024-21140

<1:21.0.4+7-1.amzn2023.1
  • L
Integer Overflow or Wraparound

<1:21.0.3+9-1.amzn2023.1
  • L
Reliance on Reverse DNS Resolution for a Security-Critical Action

<1:21.0.3+9-1.amzn2023.1
  • L
Improper Output Neutralization for Logs

<1:21.0.3+9-1.amzn2023.1
  • L
Out-of-bounds Write

<1:21.0.3+9-1.amzn2023.1
  • H
Improper Input Validation

<1:21.0.2+13-1.amzn2023.1
  • H
Covert Timing Channel

<1:21.0.2+13-1.amzn2023.1
  • H
CVE-2024-20922

<1:21.0.2+13-1.amzn2023.1
  • H
Information Exposure Through Log Files

<1:21.0.2+13-1.amzn2023.1
  • H
CVE-2024-20925

<1:21.0.2+13-1.amzn2023.1
  • H
CVE-2024-20923

<1:21.0.2+13-1.amzn2023.1
  • H
Improper Input Validation

<1:21.0.2+13-1.amzn2023.1
  • H
Integer Overflow or Wraparound

<1:21.0.2+13-1.amzn2023.1
  • M
Out-of-Bounds

<1:21.0.1+12-1.amzn2023.1
  • M
Improper Certificate Validation

<1:21.0.1+12-1.amzn2023.1