java-1.8.0-openjdk-headless vulnerabilities

Direct Vulnerabilities

Known vulnerabilities in the java-1.8.0-openjdk-headless package. This does not include vulnerabilities belonging to this package’s dependencies.

How to fix?

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

Fix for free
VulnerabilityVulnerable Version
  • M
Loop with Unreachable Exit Condition ('Infinite Loop')

*
  • H
CVE-2024-21147

*
  • M
CVE-2024-21140

*
  • M
Out-of-bounds Read

*
  • M
CVE-2024-21131

*
  • M
Improper Input Validation

*
  • M
Allocation of Resources Without Limits or Throttling

*
  • M
Deserialization of Untrusted Data

*
  • M
Integer Overflow or Wraparound

*
  • M
Allocation of Resources Without Limits or Throttling

*
  • M
Improper Use of Validation Framework

*
  • M
Integer Overflow or Wraparound

*
  • M
Improper Output Neutralization for Logs

*
  • M
Out-of-bounds Write

*
  • M
Uncontrolled Memory Allocation

*
  • M
Integer Overflow or Wraparound

*
  • M
Information Exposure Through Log Files

*
  • M
Improper Input Validation

*
  • M
Improper Input Validation

*
  • M
Improper Input Validation

*
  • H
Covert Timing Channel

*
  • H
Integer Overflow or Wraparound

*
  • M
Improper Certificate Validation

*
  • M
Deserialization of Untrusted Data

*
  • L
Out-of-bounds Read

*
  • M
Directory Traversal

*
  • L
Improper Input Validation

*
  • M
Improperly Implemented Security Check for Standard

*
  • M
Improper Input Validation

*
  • L
Improper Neutralization of Null Byte or NUL Character

*
  • M
Information Exposure

*
  • L
Improper Neutralization of Null Byte or NUL Character

*
  • H
Improper Enforcement of Message Integrity During Transmission in a Communication Channel

*
  • L
Reliance on File Name or Extension of Externally-Supplied File

*
  • M
Deserialization of Untrusted Data

*
  • M
Allocation of Resources Without Limits or Throttling

*
  • M
Resource Exhaustion

*
  • L
Use of Insufficiently Random Values

*
  • L
Integer Coercion Error

*
  • H
Integer Coercion Error

*
  • M
Improper Access Control

*
  • M
Resource Leak

*
  • M
CVE-2017-10176

*
  • M
Covert Timing Channel

*
  • M
Improper Use of Validation Framework

*
  • H
Incorrect Behavior Order: Early Validation

*
  • M
Integer Underflow

*
  • M
Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')

*
  • M
Resource Exhaustion

*
  • M
Loop with Unreachable Exit Condition ('Infinite Loop')

*
  • M
Improper Authorization

*
  • M
Allocation of Resources Without Limits or Throttling

*
  • M
Improper Use of Validation Framework

*
  • M
Uncaught Exception

*
  • M
Improper Cross-boundary Removal of Sensitive Data

*
  • H
CVE-2015-0437

<1:1.8.0.31-1.b13.el6_6
  • H
CVE-2014-6468

<0:1.8.0.25-1.b17.el6
  • H
CVE-2014-6562

<0:1.8.0.25-1.b17.el6
  • C
Untrusted Search Path

<1:1.8.0.191.b12-0.el6_10
  • C
Information Exposure

<1:1.8.0.191.b12-0.el6_10
  • C
Improper Access Control

<1:1.8.0.191.b12-0.el6_10
  • C
Improper Certificate Validation

<1:1.8.0.191.b12-0.el6_10
  • C
Loop with Unreachable Exit Condition ('Infinite Loop')

<1:1.8.0.191.b12-0.el6_10
  • C
Improper Verification of Cryptographic Signature

<1:1.8.0.191.b12-0.el6_10
  • C
Improper Access Control

<1:1.8.0.191.b12-0.el6_10
  • M
Allocation of Resources Without Limits or Throttling

<1:1.8.0.181-3.b13.el6_10
  • H
Sensitive Information Uncleared Before Release

<1:1.8.0.171-8.b10.el6_9
  • C
Allocation of Resources Without Limits or Throttling

<1:1.8.0.171-3.b10.el6_9
  • C
Allocation of Resources Without Limits or Throttling

<1:1.8.0.171-3.b10.el6_9
  • C
CVE-2018-2814

<1:1.8.0.171-3.b10.el6_9
  • C
Allocation of Resources Without Limits or Throttling

<1:1.8.0.171-3.b10.el6_9
  • C
Deserialization of Untrusted Data

<1:1.8.0.171-3.b10.el6_9
  • C
CVE-2018-2800

<1:1.8.0.171-3.b10.el6_9
  • C
Allocation of Resources Without Limits or Throttling

<1:1.8.0.171-3.b10.el6_9
  • C
Improper Verification of Cryptographic Signature

<1:1.8.0.171-3.b10.el6_9
  • C
Allocation of Resources Without Limits or Throttling

<1:1.8.0.171-3.b10.el6_9
  • C
Allocation of Resources Without Limits or Throttling

<1:1.8.0.171-3.b10.el6_9
  • H
Allocation of Resources Without Limits or Throttling

<1:1.8.0.161-3.b14.el6_9
  • H
Unsynchronized Access to Shared Data in a Multithreaded Context

<1:1.8.0.161-3.b14.el6_9
  • H
Untrusted Search Path

<1:1.8.0.161-3.b14.el6_9
  • H
Deserialization of Untrusted Data

<1:1.8.0.161-3.b14.el6_9
  • H
CVE-2018-2582

<1:1.8.0.161-3.b14.el6_9
  • H
Improper Access Control

<1:1.8.0.161-3.b14.el6_9
  • H
Improper Input Validation

<1:1.8.0.161-3.b14.el6_9
  • H
Use After Free

<1:1.8.0.161-3.b14.el6_9
  • H
Allocation of Resources Without Limits or Throttling

<1:1.8.0.161-3.b14.el6_9
  • H
Use of a Broken or Risky Cryptographic Algorithm

<1:1.8.0.161-3.b14.el6_9
  • H
Use of Insufficiently Random Values

<1:1.8.0.161-3.b14.el6_9
  • H
Improper Input Validation

<1:1.8.0.161-3.b14.el6_9
  • H
LDAP Injection

<1:1.8.0.161-3.b14.el6_9
  • H
Use After Free

<1:1.8.0.161-3.b14.el6_9
  • H
Allocation of Resources Without Limits or Throttling

<1:1.8.0.161-3.b14.el6_9
  • C
Allocation of Resources Without Limits or Throttling

<1:1.8.0.151-1.b12.el6_9
  • C
CVE-2017-10355

<1:1.8.0.151-1.b12.el6_9
  • C
Insufficient Verification of Data Authenticity

<1:1.8.0.151-1.b12.el6_9
  • C
Allocation of Resources Without Limits or Throttling

<1:1.8.0.151-1.b12.el6_9
  • C
Use of a Broken or Risky Cryptographic Algorithm

<1:1.8.0.151-1.b12.el6_9
  • C
Allocation of Resources Without Limits or Throttling

<1:1.8.0.151-1.b12.el6_9
  • C
Allocation of Resources Without Limits or Throttling

<1:1.8.0.151-1.b12.el6_9
  • C
CVE-2017-10274

<1:1.8.0.151-1.b12.el6_9
  • C
Allocation of Resources Without Limits or Throttling

<1:1.8.0.151-1.b12.el6_9
  • C
CVE-2017-10346

<1:1.8.0.151-1.b12.el6_9
  • C
CVE-2017-10285

<1:1.8.0.151-1.b12.el6_9
  • C
HTTP Response Splitting

<1:1.8.0.151-1.b12.el6_9
  • C
Allocation of Resources Without Limits or Throttling

<1:1.8.0.151-1.b12.el6_9
  • C
Allocation of Resources Without Limits or Throttling

<1:1.8.0.151-1.b12.el6_9
  • C
CVE-2017-10096

<1:1.8.0.141-2.b16.el6_9
  • C
CVE-2017-10090

<1:1.8.0.141-2.b16.el6_9
  • C
CVE-2017-10067

<1:1.8.0.141-2.b16.el6_9
  • C
Allocation of Resources Without Limits or Throttling

<1:1.8.0.141-2.b16.el6_9
  • C
CVE-2017-10110

<1:1.8.0.141-2.b16.el6_9
  • C
CVE-2017-10101

<1:1.8.0.141-2.b16.el6_9
  • C
Covert Timing Channel

<1:1.8.0.141-2.b16.el6_9
  • C
CVE-2017-10102

<1:1.8.0.141-2.b16.el6_9
  • C
CVE-2017-10193

<1:1.8.0.141-2.b16.el6_9
  • C
CVE-2017-10107

<1:1.8.0.141-2.b16.el6_9
  • C
CVE-2017-10198

<1:1.8.0.141-2.b16.el6_9
  • C
CVE-2017-10078

<1:1.8.0.141-2.b16.el6_9
  • C
CVE-2017-10116

<1:1.8.0.141-2.b16.el6_9
  • C
Allocation of Resources Without Limits or Throttling

<1:1.8.0.141-2.b16.el6_9
  • C
CVE-2017-10081

<1:1.8.0.141-2.b16.el6_9
  • C
CVE-2017-10243

<1:1.8.0.141-2.b16.el6_9
  • C
Allocation of Resources Without Limits or Throttling

<1:1.8.0.141-2.b16.el6_9
  • C
Integer Overflow or Wraparound

<1:1.8.0.141-2.b16.el6_9
  • C
Out-of-Bounds

<1:1.8.0.141-2.b16.el6_9
  • C
CVE-2017-10087

<1:1.8.0.141-2.b16.el6_9
  • C
CVE-2017-10089

<1:1.8.0.141-2.b16.el6_9
  • C
Covert Timing Channel

<1:1.8.0.141-2.b16.el6_9
  • M
Improper Input Validation

<1:1.8.0.131-0.b11.el6_9
  • M
Use of a Broken or Risky Cryptographic Algorithm

<1:1.8.0.131-0.b11.el6_9
  • M
Improper Input Validation

<1:1.8.0.131-0.b11.el6_9
  • M
Allocation of Resources Without Limits or Throttling

<1:1.8.0.131-0.b11.el6_9
  • M
Improper Authentication

<1:1.8.0.131-0.b11.el6_9
  • M
Untrusted Search Path

<1:1.8.0.131-0.b11.el6_9
  • C
Allocation of Resources Without Limits or Throttling

<1:1.8.0.121-0.b13.el6_8
  • C
CVE-2017-3272

<1:1.8.0.121-0.b13.el6_8
  • C
Information Exposure

<1:1.8.0.121-0.b13.el6_8
  • C
Integer Overflow or Wraparound

<1:1.8.0.121-0.b13.el6_8
  • C
CVE-2017-3289

<1:1.8.0.121-0.b13.el6_8
  • C
Deserialization of Untrusted Data

<1:1.8.0.121-0.b13.el6_8
  • C
Improper Input Validation

<1:1.8.0.121-0.b13.el6_8
  • C
Improper Input Validation

<1:1.8.0.121-0.b13.el6_8
  • C
Allocation of Resources Without Limits or Throttling

<1:1.8.0.121-0.b13.el6_8
  • C
Covert Timing Channel

<1:1.8.0.121-0.b13.el6_8
  • C
Improper Input Validation

<1:1.8.0.121-0.b13.el6_8
  • C
CVE-2016-5554

<1:1.8.0.111-0.b15.el6_8
  • C
Access of Resource Using Incompatible Type ('Type Confusion')

<1:1.8.0.111-0.b15.el6_8
  • C
Use of a Broken or Risky Cryptographic Algorithm

<1:1.8.0.111-0.b15.el6_8
  • C
Cleartext Transmission of Sensitive Information

<1:1.8.0.111-0.b15.el6_8
  • C
Improper Input Validation

<1:1.8.0.111-0.b15.el6_8
  • C
Out-of-bounds Read

<1:1.8.0.111-0.b15.el6_8
  • C
Allocation of Resources Without Limits or Throttling

<1:1.8.0.101-3.b13.el6_8
  • C
CVE-2016-3587

<1:1.8.0.101-3.b13.el6_8
  • C
Allocation of Resources Without Limits or Throttling

<1:1.8.0.101-3.b13.el6_8
  • C
CVE-2016-3458

<1:1.8.0.101-3.b13.el6_8
  • C
Integer Overflow or Wraparound

<1:1.8.0.101-3.b13.el6_8
  • C
CVE-2016-3610

<1:1.8.0.101-3.b13.el6_8
  • C
CVE-2016-3606

<1:1.8.0.101-3.b13.el6_8
  • C
CVE-2016-3598

<1:1.8.0.101-3.b13.el6_8
  • C
CVE-2016-3426

<1:1.8.0.91-0.b14.el6_7
  • C
CVE-2016-3427

<1:1.8.0.91-0.b14.el6_7
  • C
CVE-2016-0687

<1:1.8.0.91-0.b14.el6_7
  • C
CVE-2016-3425

<1:1.8.0.91-0.b14.el6_7
  • C
CVE-2016-0686

<1:1.8.0.91-0.b14.el6_7
  • C
CVE-2016-0695

<1:1.8.0.91-0.b14.el6_7
  • M
Integer Overflow or Wraparound

<1:1.8.0.272.b10-0.el6_10
  • H
Improperly Implemented Security Check for Standard

<1:1.8.0.77-0.b03.el6_7
  • M
Improper Certificate Validation

<1:1.8.0.272.b10-0.el6_10
  • M
Cleartext Transmission of Sensitive Information

<1:1.8.0.272.b10-0.el6_10
  • M
CVE-2020-14796

<1:1.8.0.272.b10-0.el6_10
  • M
Allocation of Resources Without Limits or Throttling

<1:1.8.0.272.b10-0.el6_10
  • M
Improper Input Validation

<1:1.8.0.272.b10-0.el6_10
  • H
Improper Data Handling

<1:1.8.0.71-1.b15.el6_7
  • M
Time-of-check Time-of-use (TOCTOU)

<1:1.8.0.272.b10-0.el6_10
  • H
Incorrect Conversion between Numeric Types

<1:1.8.0.71-1.b15.el6_7
  • H
CVE-2016-0402

<1:1.8.0.71-1.b15.el6_7
  • H
CVE-2016-0466

<1:1.8.0.71-1.b15.el6_7
  • H
CVE-2016-0475

<1:1.8.0.71-1.b15.el6_7
  • H
Out-of-bounds Write

<1:1.8.0.71-1.b15.el6_7
  • H
Information Exposure Through Log Files

<1:1.8.0.71-1.b15.el6_7
  • H
Out-of-bounds Read

<1:1.8.0.65-0.b17.el6_7
  • H
CVE-2015-4844

<1:1.8.0.65-0.b17.el6_7
  • H
CVE-2015-4883

<1:1.8.0.65-0.b17.el6_7
  • H
Information Exposure

<1:1.8.0.65-0.b17.el6_7
  • H
CVE-2015-4882

<1:1.8.0.65-0.b17.el6_7
  • H
CVE-2015-4911

<1:1.8.0.65-0.b17.el6_7
  • H
Algorithmic Complexity

<1:1.8.0.65-0.b17.el6_7
  • H
Information Exposure

<1:1.8.0.65-0.b17.el6_7
  • H
Incorrect Conversion between Numeric Types

<1:1.8.0.65-0.b17.el6_7
  • H
CVE-2015-4835

<1:1.8.0.65-0.b17.el6_7
  • H
CVE-2015-4868

<1:1.8.0.65-0.b17.el6_7
  • H
Allocation of Resources Without Limits or Throttling

<1:1.8.0.65-0.b17.el6_7
  • H
CVE-2015-4860

<1:1.8.0.65-0.b17.el6_7
  • H
Improper Initialization

<1:1.8.0.65-0.b17.el6_7
  • H
CVE-2015-4881

<1:1.8.0.65-0.b17.el6_7
  • H
CVE-2015-4903

<1:1.8.0.65-0.b17.el6_7
  • H
Improper Input Validation

<1:1.8.0.65-0.b17.el6_7
  • H
CVE-2015-4872

<1:1.8.0.65-0.b17.el6_7
  • H
Uncaught Exception

<1:1.8.0.262.b10-0.el6_10
  • H
Uncaught Exception

<1:1.8.0.262.b10-0.el6_10
  • H
Out-of-Bounds

<1:1.8.0.262.b10-0.el6_10
  • H
Improper Input Validation

<1:1.8.0.262.b10-0.el6_10
  • H
CVE-2020-14577

<1:1.8.0.262.b10-0.el6_10
  • H
Out-of-Bounds

<1:1.8.0.262.b10-0.el6_10
  • H
CVE-2020-14556

<1:1.8.0.262.b10-0.el6_10
  • H
Improper Certificate Validation

<1:1.8.0.51-0.b16.el6_6
  • H
Out-of-bounds Write

<1:1.8.0.51-0.b16.el6_6
  • H
CVE-2015-2621

<1:1.8.0.51-0.b16.el6_6
  • H
Improper Check for Certificate Revocation

<1:1.8.0.51-0.b16.el6_6
  • H
Access of Resource Using Incompatible Type ('Type Confusion')

<1:1.8.0.51-0.b16.el6_6
  • H
CVE-2015-4733

<1:1.8.0.51-0.b16.el6_6
  • H
Missing Release of Resource after Effective Lifetime

<1:1.8.0.51-0.b16.el6_6
  • H
Covert Timing Channel

<1:1.8.0.51-0.b16.el6_6
  • H
CVE-2015-2590

<1:1.8.0.51-0.b16.el6_6
  • H
Integer Overflow or Wraparound

<1:1.8.0.51-0.b16.el6_6
  • H
Unsynchronized Access to Shared Data in a Multithreaded Context

<1:1.8.0.51-0.b16.el6_6
  • H
Insecure Temporary File

<1:1.8.0.51-0.b16.el6_6
  • H
NULL Pointer Dereference

<1:1.8.0.51-0.b16.el6_6
  • H
CVE-2015-4731

<1:1.8.0.51-0.b16.el6_6
  • H
Use of a Broken or Risky Cryptographic Algorithm

<1:1.8.0.51-0.b16.el6_6
  • H
Use of a Broken or Risky Cryptographic Algorithm

<1:1.8.0.51-0.b16.el6_6
  • H
CVE-2015-0470

<1:1.8.0.45-28.b13.el6_6
  • H
Directory Traversal

<1:1.8.0.45-28.b13.el6_6
  • H
Uncaught Exception

<1:1.8.0.45-28.b13.el6_6
  • H
Off-by-one Error

<1:1.8.0.45-28.b13.el6_6
  • H
Directory Traversal

<1:1.8.0.45-28.b13.el6_6
  • H
CVE-2015-0460

<1:1.8.0.45-28.b13.el6_6
  • H
CVE-2015-0477

<1:1.8.0.45-28.b13.el6_6
  • H
Improperly Implemented Security Check for Standard

<1:1.8.0.45-28.b13.el6_6
  • H
CVE-2014-6549

<1:1.8.0.31-1.b13.el6_6
  • H
Loop with Unreachable Exit Condition ('Infinite Loop')

<1:1.8.0.31-1.b13.el6_6
  • H
CVE-2014-6593

<1:1.8.0.31-1.b13.el6_6
  • H
Out-of-bounds Read

<1:1.8.0.31-1.b13.el6_6
  • H
CVE-2015-0408

<1:1.8.0.31-1.b13.el6_6
  • H
CVE-2015-0407

<1:1.8.0.31-1.b13.el6_6
  • H
NULL Pointer Dereference

<1:1.8.0.31-1.b13.el6_6
  • H
CVE-2015-0395

<1:1.8.0.31-1.b13.el6_6
  • H
CVE-2014-6601

<1:1.8.0.31-1.b13.el6_6
  • H
Insecure Temporary File

<1:1.8.0.31-1.b13.el6_6
  • H
CVE-2015-0412

<1:1.8.0.31-1.b13.el6_6
  • H
Out-of-bounds Read

<1:1.8.0.31-1.b13.el6_6
  • H
Not Failing Securely ('Failing Open')

<1:1.8.0.31-1.b13.el6_6
  • H
CVE-2014-6506

<0:1.8.0.25-1.b17.el6
  • H
Insufficient Verification of Data Authenticity

<0:1.8.0.25-1.b17.el6
  • H
CVE-2014-6504

<0:1.8.0.25-1.b17.el6
  • H
CVE-2014-6502

<0:1.8.0.25-1.b17.el6
  • H
CVE-2014-6511

<0:1.8.0.25-1.b17.el6
  • H
CVE-2014-6517

<0:1.8.0.25-1.b17.el6
  • H
CVE-2014-6519

<0:1.8.0.25-1.b17.el6
  • H
CVE-2014-6531

<0:1.8.0.25-1.b17.el6
  • H
CVE-2014-6457

<0:1.8.0.25-1.b17.el6
  • H
CVE-2014-6558

<0:1.8.0.25-1.b17.el6
  • H
Out-of-Bounds

<1:1.8.0.252.b09-2.el6_10
  • H
Uncaught Exception

<1:1.8.0.252.b09-2.el6_10
  • H
Improper Input Validation

<1:1.8.0.252.b09-2.el6_10
  • H
CVE-2020-2781

<1:1.8.0.252.b09-2.el6_10
  • H
Uncaught Exception

<1:1.8.0.252.b09-2.el6_10
  • H
Uncaught Exception

<1:1.8.0.252.b09-2.el6_10
  • H
Uncaught Exception

<1:1.8.0.252.b09-2.el6_10
  • H
HTTP Response Splitting

<1:1.8.0.252.b09-2.el6_10
  • H
Uncaught Exception

<1:1.8.0.252.b09-2.el6_10
  • H
Incorrect Regular Expression

<1:1.8.0.252.b09-2.el6_10
  • H
Allocation of Resources Without Limits or Throttling

<1:1.8.0.242.b07-1.el6_10
  • H
Use of a Broken or Risky Cryptographic Algorithm

<1:1.8.0.242.b07-1.el6_10
  • H
Encoding Error

<1:1.8.0.242.b07-1.el6_10
  • H
Allocation of Resources Without Limits or Throttling

<1:1.8.0.242.b07-1.el6_10
  • H
Modification of Assumed-Immutable Data (MAID)

<1:1.8.0.242.b07-1.el6_10
  • H
Improper Input Validation

<1:1.8.0.242.b07-1.el6_10
  • H
Allocation of Resources Without Limits or Throttling

<1:1.8.0.242.b07-1.el6_10
  • H
Allocation of Resources Without Limits or Throttling

<1:1.8.0.232.b09-1.el6_10
  • H
Cross-site Scripting (XSS)

<1:1.8.0.232.b09-1.el6_10
  • H
Uncaught Exception

<1:1.8.0.232.b09-1.el6_10
  • H
CVE-2019-2945

<1:1.8.0.232.b09-1.el6_10
  • H
Uncaught Exception

<1:1.8.0.232.b09-1.el6_10
  • H
Uncaught Exception

<1:1.8.0.232.b09-1.el6_10
  • H
Integer Overflow or Wraparound

<1:1.8.0.232.b09-1.el6_10
  • H
Uncaught Exception

<1:1.8.0.232.b09-1.el6_10
  • H
Uncaught Exception

<1:1.8.0.232.b09-1.el6_10
  • H
CVE-2019-2978

<1:1.8.0.232.b09-1.el6_10
  • H
Cross-site Scripting (XSS)

<1:1.8.0.232.b09-1.el6_10
  • H
Insufficiently Protected Credentials

<1:1.8.0.232.b09-1.el6_10
  • H
NULL Pointer Dereference

<1:1.8.0.232.b09-1.el6_10
  • H
Improper Input Validation

<1:1.8.0.232.b09-1.el6_10
  • M
CVE-2019-2762

<1:1.8.0.222.b10-0.el6_10
  • M
Covert Timing Channel

<1:1.8.0.222.b10-0.el6_10
  • M
Allocation of Resources Without Limits or Throttling

<1:1.8.0.222.b10-0.el6_10
  • M
Improper Input Validation

<1:1.8.0.222.b10-0.el6_10
  • M
CVE-2019-2786

<1:1.8.0.222.b10-0.el6_10
  • M
Out-of-Bounds

<1:1.8.0.222.b10-0.el6_10
  • M
Information Exposure

<1:1.8.0.201.b09-1.el6_10
  • H
Out-of-bounds Write

<1:1.8.0.212.b04-0.el6_10
  • H
CVE-2019-2684

<1:1.8.0.212.b04-0.el6_10
  • H
Allocation of Resources Without Limits or Throttling

<1:1.8.0.212.b04-0.el6_10