This CPE summary could be partial or incomplete. Please contact us for a detailed listing.

Summary

Detail
Vendor Redhat First view 2014-01-15
Product Enterprise Linux Hpc Node Supplementary Last view 2016-06-03
Version 6.0 Type Os
Update *  
Edition *  
Language *  
Sofware Edition *  
Target Software *  
Target Hardware *  
Other *  
 
CPE Product cpe:2.3:o:redhat:enterprise_linux_hpc_node_supplementary

Activity : Overall

Related : CVE

  Date Alert Description
8.1 2016-06-03 CVE-2016-0376

The com.ibm.rmi.io.SunSerializableFactory class in IBM SDK, Java Technology Edition 6 before SR16 FP25 (6.0.16.25), 6 R1 before SR8 FP25 (6.1.8.25), 7 before SR9 FP40 (7.0.9.40), 7 R1 before SR3 FP40 (7.1.3.40), and 8 before SR3 (8.0.3.0) does not properly deserialize classes in an AccessController doPrivileged block, which allows remote attackers to bypass a sandbox protection mechanism and execute arbitrary code as demonstrated by the readValue method of the com.ibm.rmi.io.ValueHandlerPool.ValueHandlerSingleton class, which implements the javax.rmi.CORBA.ValueHandler interface. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-5456.

8.1 2016-06-03 CVE-2016-0363

The com.ibm.CORBA.iiop.ClientDelegate class in IBM SDK, Java Technology Edition 6 before SR16 FP25 (6.0.16.25), 6 R1 before SR8 FP25 (6.1.8.25), 7 before SR9 FP40 (7.0.9.40), 7 R1 before SR3 FP40 (7.1.3.40), and 8 before SR3 (8.0.3.0) uses the invoke method of the java.lang.reflect.Method class in an AccessController doPrivileged block, which allows remote attackers to call setSecurityManager and bypass a sandbox protection mechanism via vectors related to a Proxy object instance implementing the java.lang.reflect.InvocationHandler interface. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-3009.

5.6 2016-05-24 CVE-2016-0264

Buffer overflow in the Java Virtual Machine (JVM) in IBM SDK, Java Technology Edition 6 before SR16 FP25 (6.0.16.25), 6 R1 before SR8 FP25 (6.1.8.25), 7 before SR9 FP40 (7.0.9.40), 7 R1 before SR3 FP40 (7.1.3.40), and 8 before SR3 (8.0.3.0) allows remote attackers to execute arbitrary code via unspecified vectors.

5.1 2014-01-15 CVE-2014-0418

Unspecified vulnerability in Oracle Java SE 6u65 and 7u45 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment, a different vulnerability than CVE-2013-5889, CVE-2013-5902, CVE-2014-0410, CVE-2014-0415, and CVE-2014-0424.

4.3 2014-01-15 CVE-2014-0382

Unspecified vulnerability in Oracle Java SE 7u45 and JavaFX 2.2.45 allows remote attackers to affect availability via unknown vectors related to JavaFX.

5.1 2014-01-15 CVE-2013-5906

Unspecified vulnerability in Oracle Java SE 5.0u55, 6u65, and 7u45 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Install, a different vulnerability than CVE-2013-5905.

6.8 2014-01-15 CVE-2013-5904

Unspecified vulnerability in Oracle Java SE 7u45 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment.

5 2014-01-15 CVE-2013-5895

Unspecified vulnerability in Oracle Java SE 7u45 and JavaFX 2.2.45 allows remote attackers to affect confidentiality via unknown vectors related to JavaFX.

6.8 2014-01-15 CVE-2013-5870

Unspecified vulnerability in Oracle Java SE 7u45 and JavaFX 2.2.45 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to JavaFX.

CWE : Common Weakness Enumeration

%idName
50% (1) CWE-119 Failure to Constrain Operations within the Bounds of a Memory Buffer
50% (1) CWE-20 Improper Input Validation

Information Assurance Vulnerability Management (IAVM)

id Description
2014-A-0010 Multiple Vulnerabilities in Oracle Java SE
Severity: Category I - VMSKEY: V0043398

Nessus® Vulnerability Scanner

id Description
2017-05-10 Name: The remote Red Hat host is missing one or more security updates.
File: redhat-RHSA-2017-1216.nasl - Type: ACT_GATHER_INFO
2016-08-19 Name: A message queuing service installed on the remote host is affected by multipl...
File: websphere_mq_swg21982566.nasl - Type: ACT_GATHER_INFO
2016-07-19 Name: The remote Red Hat host is missing one or more security updates.
File: redhat-RHSA-2016-1430.nasl - Type: ACT_GATHER_INFO
2016-05-25 Name: The remote SUSE host is missing one or more security updates.
File: suse_SU-2016-1388-1.nasl - Type: ACT_GATHER_INFO
2016-05-24 Name: The remote SUSE host is missing one or more security updates.
File: suse_SU-2016-1379-1.nasl - Type: ACT_GATHER_INFO
2016-05-24 Name: The remote SUSE host is missing one or more security updates.
File: suse_SU-2016-1378-1.nasl - Type: ACT_GATHER_INFO
2016-05-16 Name: The remote SUSE host is missing one or more security updates.
File: suse_SU-2016-1300-1.nasl - Type: ACT_GATHER_INFO
2016-05-16 Name: The remote SUSE host is missing one or more security updates.
File: suse_SU-2016-1299-1.nasl - Type: ACT_GATHER_INFO
2016-05-12 Name: The remote Red Hat host is missing one or more security updates.
File: redhat-RHSA-2016-1039.nasl - Type: ACT_GATHER_INFO
2016-05-12 Name: The remote AIX host has a version of Java SDK installed that is affected by m...
File: aix_java_april2016_advisory.nasl - Type: ACT_GATHER_INFO
2016-05-04 Name: The remote Red Hat host is missing one or more security updates.
File: redhat-RHSA-2016-0716.nasl - Type: ACT_GATHER_INFO
2016-05-03 Name: The remote Red Hat host is missing one or more security updates.
File: redhat-RHSA-2016-0708.nasl - Type: ACT_GATHER_INFO
2016-05-02 Name: The remote Red Hat host is missing one or more security updates.
File: redhat-RHSA-2016-0702.nasl - Type: ACT_GATHER_INFO
2016-05-02 Name: The remote Red Hat host is missing one or more security updates.
File: redhat-RHSA-2016-0701.nasl - Type: ACT_GATHER_INFO
2014-11-08 Name: The remote Red Hat host is missing one or more security updates.
File: redhat-RHSA-2014-0414.nasl - Type: ACT_GATHER_INFO
2014-05-12 Name: The remote host has software installed that is affected by multiple vulnerabi...
File: lotus_notes_9_0_1_fp1.nasl - Type: ACT_GATHER_INFO
2014-05-12 Name: The remote host has software installed that is affected by multiple vulnerabi...
File: lotus_domino_9_0_1_fp1.nasl - Type: ACT_GATHER_INFO
2014-05-12 Name: The remote server is affected by multiple vulnerabilities.
File: domino_9_0_1_fp1.nasl - Type: ACT_GATHER_INFO
2014-01-27 Name: The remote Gentoo host is missing one or more security-related patches.
File: gentoo_GLSA-201401-30.nasl - Type: ACT_GATHER_INFO
2014-01-16 Name: The remote Red Hat host is missing one or more security updates.
File: redhat-RHSA-2014-0030.nasl - Type: ACT_GATHER_INFO
2014-01-15 Name: The remote Unix host contains a programming platform that is potentially affe...
File: oracle_java_cpu_jan_2014_unix.nasl - Type: ACT_GATHER_INFO
2014-01-15 Name: The remote Windows host contains a programming platform that is potentially a...
File: oracle_java_cpu_jan_2014.nasl - Type: ACT_GATHER_INFO