java-1.8.0-ibm-headless vulnerabilities

Direct Vulnerabilities

Known vulnerabilities in the java-1.8.0-ibm-headless package. This does not include vulnerabilities belonging to this package’s dependencies.

How to fix?

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

Fix for free
VulnerabilityVulnerable Version
  • M
Man-in-the-Middle (MitM)

<1:1.8.0.8.30-2.el8_10
  • M
Out-of-bounds Read

*
  • M
Improper Input Validation

*
  • M
CVE-2024-21131

*
  • M
Resource Exhaustion

<1:1.8.0.8.25-1.el8_10
  • M
Uncontrolled Memory Allocation

*
  • M
Improper Input Validation

<1:1.8.0.8.20-1.el8_9
  • M
Covert Timing Channel

<1:1.8.0.8.20-1.el8_9
  • M
Integer Overflow or Wraparound

<1:1.8.0.8.20-1.el8_9
  • M
Improper Input Validation

<1:1.8.0.8.20-1.el8_9
  • M
Information Exposure Through Log Files

<1:1.8.0.8.20-1.el8_9
  • M
Race Condition

<1:1.8.0.8.15-1.el8_9
  • M
Improper Certificate Validation

<1:1.8.0.8.15-1.el8_9
  • M
Deserialization of Untrusted Data

<1:1.8.0.8.15-1.el8_9
  • H
Deserialization of Untrusted Data

<1:1.8.0.8.5-1.el8_8
  • M
Directory Traversal

<1:1.8.0.8.10-1.el8_8
  • M
Information Exposure

<1:1.8.0.7.15-1.el8_6
  • H
Improper Input Validation

<1:1.8.0.8.5-1.el8_8
  • H
Improperly Implemented Security Check for Standard

<1:1.8.0.8.5-1.el8_8
  • H
Improper Input Validation

<1:1.8.0.8.5-1.el8_8
  • H
Improper Neutralization of Null Byte or NUL Character

<1:1.8.0.8.5-1.el8_8
  • H
Improper Neutralization of Null Byte or NUL Character

<1:1.8.0.8.5-1.el8_8
  • H
Improper Enforcement of Message Integrity During Transmission in a Communication Channel

<1:1.8.0.8.5-1.el8_8
  • L
Reliance on File Name or Extension of Externally-Supplied File

*
  • M
Deserialization of Untrusted Data

*
  • M
Allocation of Resources Without Limits or Throttling

<1:1.8.0.7.20-1.el8_7
  • M
Resource Exhaustion

<1:1.8.0.7.20-1.el8_7
  • M
Use of Insufficiently Random Values

<1:1.8.0.7.20-1.el8_7
  • M
Integer Coercion Error

<1:1.8.0.7.20-1.el8_7
  • M
Unchecked Return Value

<1:1.8.0.7.10-1.el8_6
  • M
Improper Use of Validation Framework

<1:1.8.0.7.10-1.el8_6
  • M
Integer Underflow

<1:1.8.0.7.10-1.el8_6
  • M
Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')

<1:1.8.0.7.10-1.el8_6
  • M
Resource Exhaustion

*
  • M
Integer Overflow or Wraparound

<1:1.8.0.7.5-1.el8_5
  • M
Allocation of Resources Without Limits or Throttling

<1:1.8.0.7.5-1.el8_5
  • M
Improper Use of Validation Framework

<1:1.8.0.7.5-1.el8_5
  • M
Allocation of Resources Without Limits or Throttling

<1:1.8.0.7.5-1.el8_5
  • M
Loop with Unreachable Exit Condition ('Infinite Loop')

*
  • M
Allocation of Resources Without Limits or Throttling

<1:1.8.0.7.5-1.el8_5
  • M
Improper Use of Validation Framework

<1:1.8.0.7.5-1.el8_5
  • M
Deserialization of Untrusted Data

<1:1.8.0.7.5-1.el8_5
  • H
Incorrect Permission Assignment for Critical Resource

<1:1.8.0.7.0-1.el8_5
  • H
CVE-2021-35560

<1:1.8.0.7.0-1.el8_5
  • M
Information Exposure

<1:1.8.0.7.5-1.el8_5
  • H
NULL Pointer Dereference

<1:1.8.0.7.0-1.el8_5
  • H
Allocation of Resources Without Limits or Throttling

<1:1.8.0.7.0-1.el8_5
  • H
Loop with Unreachable Exit Condition ('Infinite Loop')

<1:1.8.0.7.0-1.el8_5
  • H
Improper Input Validation

<1:1.8.0.7.0-1.el8_5
  • M
Allocation of Resources Without Limits or Throttling

<1:1.8.0.7.10-1.el8_6
  • H
Allocation of Resources Without Limits or Throttling

<1:1.8.0.7.0-1.el8_5
  • H
Allocation of Resources Without Limits or Throttling

<1:1.8.0.7.0-1.el8_5
  • M
Use of a Broken or Risky Cryptographic Algorithm

<1:1.8.0.7.5-1.el8_5
  • M
Information Exposure

<1:1.8.0.6.35-1.el8_4
  • M
Improper Verification of Cryptographic Signature

<1:1.8.0.6.35-1.el8_4
  • M
Use of a Broken or Risky Cryptographic Algorithm

<1:1.8.0.7.15-1.el8_6
  • C
Out-of-Bounds

<1:1.8.0.6.25-2.el8_3
  • C
Improper Certificate Validation

<1:1.8.0.6.25-2.el8_3
  • C
Cleartext Transmission of Sensitive Information

<1:1.8.0.6.25-2.el8_3
  • M
CVE-2020-14796

<1:1.8.0.6.20-1.el8_3
  • M
Allocation of Resources Without Limits or Throttling

<1:1.8.0.6.20-1.el8_3
  • M
Improper Input Validation

<1:1.8.0.6.20-1.el8_3
  • C
Time-of-check Time-of-use (TOCTOU)

<1:1.8.0.6.25-2.el8_3
  • H
Information Exposure

<1:1.8.0.6.15-1.el8_2
  • H
Uncaught Exception

<1:1.8.0.6.15-1.el8_2
  • H
Uncaught Exception

<1:1.8.0.6.15-1.el8_2
  • H
Out-of-Bounds

<1:1.8.0.6.15-1.el8_2
  • H
Improper Input Validation

<1:1.8.0.6.15-1.el8_2
  • H
CVE-2020-14577

<1:1.8.0.6.15-1.el8_2
  • H
Out-of-Bounds

<1:1.8.0.6.15-1.el8_2
  • H
CVE-2020-14556

<1:1.8.0.6.15-1.el8_2
  • H
Out-of-Bounds

<1:1.8.0.6.10-1.el8_2
  • C
Uncaught Exception

<1:1.8.0.6.25-2.el8_3
  • H
Improper Input Validation

<1:1.8.0.6.10-1.el8_2
  • H
CVE-2020-2781

<1:1.8.0.6.10-1.el8_2
  • H
Uncaught Exception

<1:1.8.0.6.10-1.el8_2
  • H
Uncaught Exception

<1:1.8.0.6.10-1.el8_2
  • H
Uncaught Exception

<1:1.8.0.6.10-1.el8_2
  • H
HTTP Response Splitting

<1:1.8.0.6.10-1.el8_2
  • H
Uncaught Exception

<1:1.8.0.6.10-1.el8_2
  • H
Incorrect Regular Expression

<1:1.8.0.6.10-1.el8_2
  • H
Allocation of Resources Without Limits or Throttling

<1:1.8.0.6.5-1.el8_1
  • H
Use of a Broken or Risky Cryptographic Algorithm

<1:1.8.0.6.15-1.el8_2
  • H
Encoding Error

<1:1.8.0.6.5-1.el8_1
  • H
Allocation of Resources Without Limits or Throttling

<1:1.8.0.6.5-1.el8_1
  • H
Modification of Assumed-Immutable Data (MAID)

<1:1.8.0.6.5-1.el8_1
  • H
Improper Input Validation

<1:1.8.0.6.15-1.el8_2
  • H
Allocation of Resources Without Limits or Throttling

<1:1.8.0.6.10-1.el8_2
  • M
CVE-2019-2996

<1:1.8.0.6.0-3.el8_1
  • M
Improper Authorization

<1:1.8.0.6.0-3.el8_1
  • M
Allocation of Resources Without Limits or Throttling

<1:1.8.0.6.0-3.el8_1
  • M
Cross-site Scripting (XSS)

<1:1.8.0.6.0-3.el8_1
  • M
Uncaught Exception

<1:1.8.0.6.0-3.el8_1
  • M
CVE-2019-2945

<1:1.8.0.6.0-3.el8_1
  • M
Uncaught Exception

<1:1.8.0.6.0-3.el8_1
  • M
Uncaught Exception

<1:1.8.0.6.0-3.el8_1
  • M
Integer Overflow or Wraparound

<1:1.8.0.6.0-3.el8_1
  • M
Uncaught Exception

<1:1.8.0.6.0-3.el8_1
  • M
Uncaught Exception

<1:1.8.0.6.0-3.el8_1
  • M
CVE-2019-2978

<1:1.8.0.6.0-3.el8_1
  • M
Cross-site Scripting (XSS)

<1:1.8.0.6.0-3.el8_1
  • H
Insufficiently Protected Credentials

<1:1.8.0.6.10-1.el8_2
  • M
NULL Pointer Dereference

<1:1.8.0.6.0-3.el8_1
  • H
Out-of-Bounds

<1:1.8.0.5.40-3.el8_0
  • H
Out-of-Bounds

<1:1.8.0.5.40-3.el8_0
  • H
CVE-2019-2762

<1:1.8.0.5.40-3.el8_0
  • H
Allocation of Resources Without Limits or Throttling

<1:1.8.0.5.40-3.el8_0
  • H
Improper Input Validation

<1:1.8.0.5.40-3.el8_0
  • H
CVE-2019-2786

<1:1.8.0.5.40-3.el8_0
  • H
Resource Exhaustion

<1:1.8.0.5.40-3.el8_0
  • C
Buffer Overflow

<1:1.8.0.5.35-3.el8_0
  • C
Out-of-bounds Read

<1:1.8.0.5.35-3.el8_0
  • C
Information Exposure

<1:1.8.0.5.35-3.el8_0
  • C
CVE-2019-2449

<1:1.8.0.5.35-3.el8_0
  • C
CVE-2019-2697

<1:1.8.0.5.35-3.el8_0
  • C
Improper Input Validation

<1:1.8.0.5.35-3.el8_0
  • C
Divide By Zero

<1:1.8.0.5.35-3.el8_0
  • C
Out-of-bounds Write

<1:1.8.0.5.35-3.el8_0
  • C
CVE-2019-2684

<1:1.8.0.5.35-3.el8_0
  • C
Allocation of Resources Without Limits or Throttling

<1:1.8.0.5.35-3.el8_0