java-1.8.0-amazon-corretto vulnerabilities

Direct Vulnerabilities

Known vulnerabilities in the java-1.8.0-amazon-corretto package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • H
Improper Certificate Validation

<1:1.8.0_482.b08-1.amzn2023
  • H
Improper Validation of Specified Type of Input

<1:1.8.0_482.b08-1.amzn2023
  • H
CRLF Injection

<1:1.8.0_482.b08-1.amzn2023
  • H
Key Exchange without Entity Authentication

<1:1.8.0_482.b08-1.amzn2023
  • M
Inappropriate Encoding for Output Context

<1:1.8.0_472.b08-1.amzn2023
  • M
CVE-2025-53066

<1:1.8.0_472.b08-1.amzn2023
  • H
Heap-based Buffer Overflow

<1:1.8.0_462.b08-1.amzn2023
  • H
CVE-2025-30761

<1:1.8.0_462.b08-1.amzn2023
  • H
Missing Required Cryptographic Step

<1:1.8.0_462.b08-1.amzn2023
  • H
Heap-based Buffer Overflow

<1:1.8.0_462.b08-1.amzn2023
  • H
Buffer Overflow

<1:1.8.0_452.b09-2.amzn2023
  • H
Information Exposure

<1:1.8.0_452.b09-2.amzn2023
  • H
Heap-based Buffer Overflow

<1:1.8.0_452.b09-2.amzn2023
  • M
Signed to Unsigned Conversion Error

<1:1.8.0_432.b06-1.amzn2023
  • M
Integer Overflow or Wraparound

<1:1.8.0_432.b06-1.amzn2023
  • M
Improper Handling of Length Parameter Inconsistency

<1:1.8.0_432.b06-1.amzn2023
  • M
Uncontrolled Memory Allocation

<1:1.8.0_432.b06-1.amzn2023
  • H
CVE-2024-21140

<1:1.8.0_422.b05-1.amzn2023
  • H
CVE-2024-21147

<1:1.8.0_422.b05-1.amzn2023
  • H
Out-of-bounds Read

<1:1.8.0_422.b05-1.amzn2023
  • H
CVE-2024-21131

<1:1.8.0_422.b05-1.amzn2023
  • H
Loop with Unreachable Exit Condition ('Infinite Loop')

<1:1.8.0_422.b05-1.amzn2023
  • H
Improper Input Validation

<1:1.8.0_422.b05-1.amzn2023
  • L
ALAS2023-2024-482

<1:1.8.0_402.b06-1.amzn2023
  • L
CVE-2024-21005

<1:1.8.0_412.b08-1.amzn2023
  • L
Out-of-bounds Write

<1:1.8.0_412.b08-1.amzn2023
  • L
Integer Overflow or Wraparound

<1:1.8.0_412.b08-1.amzn2023
  • L
CVE-2024-21004

<1:1.8.0_412.b08-1.amzn2023
  • L
Uncontrolled Memory Allocation

<1:1.8.0_412.b08-1.amzn2023
  • L
Improper Output Neutralization for Logs

<1:1.8.0_412.b08-1.amzn2023
  • L
CVE-2024-21002

<1:1.8.0_412.b08-1.amzn2023
  • L
CVE-2024-21003

<1:1.8.0_412.b08-1.amzn2023
  • H
Covert Timing Channel

<1:1.8.0_402.b08-1.amzn2023
  • H
Improper Input Validation

<1:1.8.0_402.b08-1.amzn2023
  • H
Information Exposure Through Log Files

<1:1.8.0_402.b08-1.amzn2023
  • H
Improper Input Validation

<1:1.8.0_402.b08-1.amzn2023
  • H
Improper Input Validation

<1:1.8.0_402.b08-1.amzn2023
  • H
Integer Overflow or Wraparound

<1:1.8.0_402.b08-1.amzn2023
  • H
Improper Input Validation

<1:1.8.0_402.b06-1.amzn2023
  • H
Integer Overflow or Wraparound

<1:1.8.0_402.b06-1.amzn2023
  • H
Information Exposure Through Log Files

<1:1.8.0_402.b06-1.amzn2023
  • H
Improper Input Validation

<1:1.8.0_402.b06-1.amzn2023
  • H
Covert Timing Channel

<1:1.8.0_402.b06-1.amzn2023
  • H
Improper Input Validation

<1:1.8.0_402.b06-1.amzn2023
  • H
Improper Certificate Validation

<1:1.8.0_392.b08-1.amzn2023
  • H
Deserialization of Untrusted Data

<1:1.8.0_392.b08-1.amzn2023
  • H
Resource Exhaustion

<1:1.8.0_392.b08-1.amzn2023
  • M
Deserialization of Untrusted Data

<1:1.8.0_392.b08-1.amzn2023
  • M
Improper Certificate Validation

<1:1.8.0_392.b08-1.amzn2023
  • M
CVE-2023-22043

<1:1.8.0_382.b05-1.amzn2023
  • M
Directory Traversal

<1:1.8.0_382.b05-1.amzn2023
  • M
Out-of-bounds Read

<1:1.8.0_382.b05-1.amzn2023
  • H
Improper Neutralization of Null Byte or NUL Character

<1:1.8.0_372.b07-1.amzn2023
  • H
Improper Enforcement of Message Integrity During Transmission in a Communication Channel

<1:1.8.0_372.b07-1.amzn2023
  • H
Information Exposure

<1:1.8.0_372.b07-1.amzn2023
  • H
Improper Input Validation

<1:1.8.0_372.b07-1.amzn2023
  • H
Improper Input Validation

<1:1.8.0_372.b07-1.amzn2023
  • H
Improper Neutralization of Null Byte or NUL Character

<1:1.8.0_372.b07-1.amzn2023
  • H
Improperly Implemented Security Check for Standard

<1:1.8.0_372.b07-1.amzn2023