{"cves":[{"id":"CVE-2013-5819","published":"2013-10-16T17:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUnspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60\nand earlier, and Java SE Embedded 7u40 and earlier allows remote attackers\nto affect integrity via unknown vectors related to Deployment, a different\nvulnerability than CVE-2013-5818 and CVE-2013-5831.","ubuntu_description":"","notes":[{"author":"seth-arnold","note":"No \"Deployment\" in openjdk"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html","https://www.cve.org/CVERecord?id=CVE-2013-5819"],"bugs":[""],"patches":{"openjdk-7":[],"openjdk-6":[]},"tags":{},"packages":[{"name":"openjdk-6","source":"https://ubuntu.com/security/cve?package=openjdk-6","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=openjdk-6","debian":"https://tracker.debian.org/pkg/openjdk-6","statuses":[{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"openjdk-7","source":"https://ubuntu.com/security/cve?package=openjdk-7","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=openjdk-7","debian":"https://tracker.debian.org/pkg/openjdk-7","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-5818","published":"2013-10-16T17:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUnspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60\nand earlier, and Java SE Embedded 7u40 and earlier allows remote attackers\nto affect integrity via unknown vectors related to Deployment, a different\nvulnerability than CVE-2013-5819 and CVE-2013-5831.","ubuntu_description":"","notes":[{"author":"seth-arnold","note":"No \"Deployment\" in openjdk"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html","https://www.cve.org/CVERecord?id=CVE-2013-5818"],"bugs":[""],"patches":{"openjdk-7":[],"openjdk-6":[]},"tags":{},"packages":[{"name":"openjdk-6","source":"https://ubuntu.com/security/cve?package=openjdk-6","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=openjdk-6","debian":"https://tracker.debian.org/pkg/openjdk-6","statuses":[{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"openjdk-7","source":"https://ubuntu.com/security/cve?package=openjdk-7","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=openjdk-7","debian":"https://tracker.debian.org/pkg/openjdk-7","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-5812","published":"2013-10-16T17:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUnspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60\nand earlier, and Java SE Embedded 7u40 and earlier allows remote attackers\nto affect confidentiality and availability via unknown vectors related to\nDeployment.","ubuntu_description":"","notes":[{"author":"seth-arnold","note":"No Deployment in openjdk packages"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html","https://www.cve.org/CVERecord?id=CVE-2013-5812"],"bugs":[""],"patches":{"openjdk-7":[],"openjdk-6":[]},"tags":{},"packages":[{"name":"openjdk-6","source":"https://ubuntu.com/security/cve?package=openjdk-6","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=openjdk-6","debian":"https://tracker.debian.org/pkg/openjdk-6","statuses":[{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"openjdk-7","source":"https://ubuntu.com/security/cve?package=openjdk-7","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=openjdk-7","debian":"https://tracker.debian.org/pkg/openjdk-7","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-5810","published":"2013-10-16T17:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUnspecified vulnerability in Oracle Java SE 7u40 and earlier and JavaFX\n2.2.40 and earlier allows remote attackers to affect confidentiality,\nintegrity, and availability via unknown vectors.","ubuntu_description":"","notes":[{"author":"seth-arnold","note":"JavaFX isn't part of OpenJDK"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html","https://www.cve.org/CVERecord?id=CVE-2013-5810"],"bugs":[""],"patches":{"openjdk-7":[],"openjdk-6":[]},"tags":{},"packages":[{"name":"openjdk-6","source":"https://ubuntu.com/security/cve?package=openjdk-6","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=openjdk-6","debian":"https://tracker.debian.org/pkg/openjdk-6","statuses":[{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"openjdk-7","source":"https://ubuntu.com/security/cve?package=openjdk-7","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=openjdk-7","debian":"https://tracker.debian.org/pkg/openjdk-7","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-5806","published":"2013-10-16T17:55:00","updated_at":"2025-05-26T12:48:49.274218+00:00","description":"\nUnspecified vulnerability in Oracle Java SE 7u40 and earlier and Java SE\nEmbedded 7u40 and earlier allows remote attackers to affect\nconfidentiality, integrity, and availability via unknown vectors related to\nSwing, a different vulnerability than CVE-2013-5805.","ubuntu_description":"","notes":[{"author":"seth-arnold","note":"From Debian triage, \"(Specific to MacOS X)\""}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html","https://www.cve.org/CVERecord?id=CVE-2013-5806","https://ubuntu.com/security/notices/USN-2089-1"],"bugs":[""],"patches":{"openjdk-7":[],"openjdk-6":[]},"tags":{},"packages":[{"name":"openjdk-6","source":"https://ubuntu.com/security/cve?package=openjdk-6","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=openjdk-6","debian":"https://tracker.debian.org/pkg/openjdk-6","statuses":[{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"openjdk-7","source":"https://ubuntu.com/security/cve?package=openjdk-7","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=openjdk-7","debian":"https://tracker.debian.org/pkg/openjdk-7","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-2089-1"],"notices":[{"id":"USN-2089-1","title":"OpenJDK 7 vulnerabilities","summary":"Several security issues were fixed in OpenJDK 7.\n","instructions":"This update uses a new upstream release, which includes additional bug\nfixes. After a standard system update you need to restart any Java\napplications or applets to make all the necessary changes.\n","references":[],"published":"2014-01-23T20:58:26.167195","description":"\nSeveral vulnerabilities were discovered in the OpenJDK JRE related to\ninformation disclosure and data integrity. An attacker could exploit these\nto expose sensitive data over the network. (CVE-2013-3829, CVE-2013-5783,\nCVE-2013-5804, CVE-2014-0411)\n\nSeveral vulnerabilities were discovered in the OpenJDK JRE related to\navailability. An attacker could exploit these to cause a denial of service.\n(CVE-2013-4002, CVE-2013-5803, CVE-2013-5823, CVE-2013-5825, CVE-2013-5896,\nCVE-2013-5910)\n\nSeveral vulnerabilities were discovered in the OpenJDK JRE related to data\nintegrity. (CVE-2013-5772, CVE-2013-5774, CVE-2013-5784, CVE-2013-5797,\nCVE-2013-5820, CVE-2014-0376, CVE-2014-0416)\n\nSeveral vulnerabilities were discovered in the OpenJDK JRE related to\ninformation disclosure. An attacker could exploit these to expose sensitive\ndata over the network. (CVE-2013-5778, CVE-2013-5780, CVE-2013-5790,\nCVE-2013-5800, CVE-2013-5840, CVE-2013-5849, CVE-2013-5851, CVE-2013-5884,\nCVE-2014-0368)\n\nSeveral vulnerabilities were discovered in the OpenJDK JRE related to\ninformation disclosure, data integrity and availability. An attacker could\nexploit these to cause a denial of service or expose sensitive data over\nthe network. (CVE-2013-5782, CVE-2013-5802, CVE-2013-5809, CVE-2013-5829,\nCVE-2013-5814, CVE-2013-5817, CVE-2013-5830, CVE-2013-5842, CVE-2013-5850,\nCVE-2013-5878, CVE-2013-5893, CVE-2013-5907, CVE-2014-0373, CVE-2014-0408,\nCVE-2014-0422, CVE-2014-0428)\n\nA vulnerability was discovered in the OpenJDK JRE related to information\ndisclosure and availability. An attacker could exploit this to expose\nsensitive data over the network or cause a denial of service.\n(CVE-2014-0423)\n","is_hidden":false,"release_packages":{"saucy":[{"name":"openjdk-7","version":"7u51-2.4.4-0ubuntu0.13.10.1","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-7-jre-lib","version":"7u51-2.4.4-0ubuntu0.13.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.13.10.1"},{"name":"openjdk-7-jre-zero","version":"7u51-2.4.4-0ubuntu0.13.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.13.10.1"},{"name":"icedtea-7-jre-jamvm","version":"7u51-2.4.4-0ubuntu0.13.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.13.10.1"},{"name":"openjdk-7-jre-headless","version":"7u51-2.4.4-0ubuntu0.13.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.13.10.1"},{"name":"openjdk-7-jre","version":"7u51-2.4.4-0ubuntu0.13.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.13.10.1"}],"quantal":[{"name":"openjdk-7","version":"7u51-2.4.4-0ubuntu0.12.10.2","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-7-jre-zero","version":"7u51-2.4.4-0ubuntu0.12.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.12.10.2"},{"name":"icedtea-7-jre-jamvm","version":"7u51-2.4.4-0ubuntu0.12.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.12.10.2"},{"name":"icedtea-7-jre-cacao","version":"7u51-2.4.4-0ubuntu0.12.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.12.10.2"},{"name":"openjdk-7-jre-lib","version":"7u51-2.4.4-0ubuntu0.12.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.12.10.2"},{"name":"openjdk-7-jre-headless","version":"7u51-2.4.4-0ubuntu0.12.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.12.10.2"},{"name":"openjdk-7-jre","version":"7u51-2.4.4-0ubuntu0.12.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.12.10.2"}],"raring":[{"name":"openjdk-7","version":"7u51-2.4.4-0ubuntu0.13.04.2","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-7-jre-lib","version":"7u51-2.4.4-0ubuntu0.13.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.13.04.2"},{"name":"openjdk-7-jre-zero","version":"7u51-2.4.4-0ubuntu0.13.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.13.04.2"},{"name":"icedtea-7-jre-jamvm","version":"7u51-2.4.4-0ubuntu0.13.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.13.04.2"},{"name":"openjdk-7-jre-headless","version":"7u51-2.4.4-0ubuntu0.13.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.13.04.2"},{"name":"openjdk-7-jre","version":"7u51-2.4.4-0ubuntu0.13.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.13.04.2"}]},"type":"USN","cves_ids":["CVE-2013-5817","CVE-2013-5820","CVE-2013-5823","CVE-2013-5825","CVE-2013-5829","CVE-2013-5830","CVE-2013-5840","CVE-2013-5842","CVE-2013-5849","CVE-2013-5850","CVE-2013-5851","CVE-2013-5878","CVE-2013-5884","CVE-2013-5896","CVE-2013-5907","CVE-2013-5910","CVE-2014-0368","CVE-2014-0373","CVE-2014-0376","CVE-2014-0411","CVE-2014-0416","CVE-2014-0422","CVE-2014-0423","CVE-2014-0428","CVE-2014-0408","CVE-2013-5806","CVE-2013-5800","CVE-2013-5805","CVE-2013-5893","CVE-2013-3829","CVE-2013-4002","CVE-2013-5772","CVE-2013-5774","CVE-2013-5778","CVE-2013-5780","CVE-2013-5782","CVE-2013-5783","CVE-2013-5784","CVE-2013-5790","CVE-2013-5797","CVE-2013-5802","CVE-2013-5803","CVE-2013-5804","CVE-2013-5809","CVE-2013-5814"]}]},{"id":"CVE-2013-5805","published":"2013-10-16T17:55:00","updated_at":"2025-05-26T12:48:49.274218+00:00","description":"\nUnspecified vulnerability in Oracle Java SE 7u40 and earlier and Java SE\nEmbedded 7u40 and earlier allows remote attackers to affect\nconfidentiality, integrity, and availability via unknown vectors related to\nSwing, a different vulnerability than CVE-2013-5806.","ubuntu_description":"","notes":[{"author":"seth-arnold","note":"From Debian triage, \"(Specific to MacOS X)\""}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html","https://www.cve.org/CVERecord?id=CVE-2013-5805","https://ubuntu.com/security/notices/USN-2089-1"],"bugs":[""],"patches":{"openjdk-7":[],"openjdk-6":[]},"tags":{},"packages":[{"name":"openjdk-6","source":"https://ubuntu.com/security/cve?package=openjdk-6","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=openjdk-6","debian":"https://tracker.debian.org/pkg/openjdk-6","statuses":[{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"openjdk-7","source":"https://ubuntu.com/security/cve?package=openjdk-7","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=openjdk-7","debian":"https://tracker.debian.org/pkg/openjdk-7","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-2089-1"],"notices":[{"id":"USN-2089-1","title":"OpenJDK 7 vulnerabilities","summary":"Several security issues were fixed in OpenJDK 7.\n","instructions":"This update uses a new upstream release, which includes additional bug\nfixes. After a standard system update you need to restart any Java\napplications or applets to make all the necessary changes.\n","references":[],"published":"2014-01-23T20:58:26.167195","description":"\nSeveral vulnerabilities were discovered in the OpenJDK JRE related to\ninformation disclosure and data integrity. An attacker could exploit these\nto expose sensitive data over the network. (CVE-2013-3829, CVE-2013-5783,\nCVE-2013-5804, CVE-2014-0411)\n\nSeveral vulnerabilities were discovered in the OpenJDK JRE related to\navailability. An attacker could exploit these to cause a denial of service.\n(CVE-2013-4002, CVE-2013-5803, CVE-2013-5823, CVE-2013-5825, CVE-2013-5896,\nCVE-2013-5910)\n\nSeveral vulnerabilities were discovered in the OpenJDK JRE related to data\nintegrity. (CVE-2013-5772, CVE-2013-5774, CVE-2013-5784, CVE-2013-5797,\nCVE-2013-5820, CVE-2014-0376, CVE-2014-0416)\n\nSeveral vulnerabilities were discovered in the OpenJDK JRE related to\ninformation disclosure. An attacker could exploit these to expose sensitive\ndata over the network. (CVE-2013-5778, CVE-2013-5780, CVE-2013-5790,\nCVE-2013-5800, CVE-2013-5840, CVE-2013-5849, CVE-2013-5851, CVE-2013-5884,\nCVE-2014-0368)\n\nSeveral vulnerabilities were discovered in the OpenJDK JRE related to\ninformation disclosure, data integrity and availability. An attacker could\nexploit these to cause a denial of service or expose sensitive data over\nthe network. (CVE-2013-5782, CVE-2013-5802, CVE-2013-5809, CVE-2013-5829,\nCVE-2013-5814, CVE-2013-5817, CVE-2013-5830, CVE-2013-5842, CVE-2013-5850,\nCVE-2013-5878, CVE-2013-5893, CVE-2013-5907, CVE-2014-0373, CVE-2014-0408,\nCVE-2014-0422, CVE-2014-0428)\n\nA vulnerability was discovered in the OpenJDK JRE related to information\ndisclosure and availability. An attacker could exploit this to expose\nsensitive data over the network or cause a denial of service.\n(CVE-2014-0423)\n","is_hidden":false,"release_packages":{"saucy":[{"name":"openjdk-7","version":"7u51-2.4.4-0ubuntu0.13.10.1","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-7-jre-lib","version":"7u51-2.4.4-0ubuntu0.13.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.13.10.1"},{"name":"openjdk-7-jre-zero","version":"7u51-2.4.4-0ubuntu0.13.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.13.10.1"},{"name":"icedtea-7-jre-jamvm","version":"7u51-2.4.4-0ubuntu0.13.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.13.10.1"},{"name":"openjdk-7-jre-headless","version":"7u51-2.4.4-0ubuntu0.13.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.13.10.1"},{"name":"openjdk-7-jre","version":"7u51-2.4.4-0ubuntu0.13.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.13.10.1"}],"quantal":[{"name":"openjdk-7","version":"7u51-2.4.4-0ubuntu0.12.10.2","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-7-jre-zero","version":"7u51-2.4.4-0ubuntu0.12.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.12.10.2"},{"name":"icedtea-7-jre-jamvm","version":"7u51-2.4.4-0ubuntu0.12.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.12.10.2"},{"name":"icedtea-7-jre-cacao","version":"7u51-2.4.4-0ubuntu0.12.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.12.10.2"},{"name":"openjdk-7-jre-lib","version":"7u51-2.4.4-0ubuntu0.12.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.12.10.2"},{"name":"openjdk-7-jre-headless","version":"7u51-2.4.4-0ubuntu0.12.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.12.10.2"},{"name":"openjdk-7-jre","version":"7u51-2.4.4-0ubuntu0.12.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.12.10.2"}],"raring":[{"name":"openjdk-7","version":"7u51-2.4.4-0ubuntu0.13.04.2","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-7-jre-lib","version":"7u51-2.4.4-0ubuntu0.13.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.13.04.2"},{"name":"openjdk-7-jre-zero","version":"7u51-2.4.4-0ubuntu0.13.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.13.04.2"},{"name":"icedtea-7-jre-jamvm","version":"7u51-2.4.4-0ubuntu0.13.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.13.04.2"},{"name":"openjdk-7-jre-headless","version":"7u51-2.4.4-0ubuntu0.13.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.13.04.2"},{"name":"openjdk-7-jre","version":"7u51-2.4.4-0ubuntu0.13.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.13.04.2"}]},"type":"USN","cves_ids":["CVE-2013-5817","CVE-2013-5820","CVE-2013-5823","CVE-2013-5825","CVE-2013-5829","CVE-2013-5830","CVE-2013-5840","CVE-2013-5842","CVE-2013-5849","CVE-2013-5850","CVE-2013-5851","CVE-2013-5878","CVE-2013-5884","CVE-2013-5896","CVE-2013-5907","CVE-2013-5910","CVE-2014-0368","CVE-2014-0373","CVE-2014-0376","CVE-2014-0411","CVE-2014-0416","CVE-2014-0422","CVE-2014-0423","CVE-2014-0428","CVE-2014-0408","CVE-2013-5806","CVE-2013-5800","CVE-2013-5805","CVE-2013-5893","CVE-2013-3829","CVE-2013-4002","CVE-2013-5772","CVE-2013-5774","CVE-2013-5778","CVE-2013-5780","CVE-2013-5782","CVE-2013-5783","CVE-2013-5784","CVE-2013-5790","CVE-2013-5797","CVE-2013-5802","CVE-2013-5803","CVE-2013-5804","CVE-2013-5809","CVE-2013-5814"]}]},{"id":"CVE-2013-5801","published":"2013-10-16T17:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUnspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60\nand earlier, Java SE 5.0u51 and earlier, and Java SE Embedded 7u40 and\nearlier allows remote attackers to affect confidentiality via unknown\nvectors related to 2D.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"Oracle java"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html","https://www.cve.org/CVERecord?id=CVE-2013-5801"],"bugs":[""],"patches":{"openjdk-7":[]},"tags":{},"packages":[{"name":"openjdk-7","source":"https://ubuntu.com/security/cve?package=openjdk-7","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=openjdk-7","debian":"https://tracker.debian.org/pkg/openjdk-7","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-5793","published":"2013-10-16T17:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUnspecified vulnerability in Oracle MySQL Server 5.6.12 and earlier allows\nremote authenticated users to affect availability via unknown vectors\nrelated to InnoDB, a different vulnerability than CVE-2013-5786.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"mysql-cluster-7.0 not supported per Ubuntu Server team"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html","https://www.cve.org/CVERecord?id=CVE-2013-5793"],"bugs":[""],"patches":{"mysql-dfsg-5.1":[],"mysql-5.5":[],"mysql-cluster-7.0":[]},"tags":{},"packages":[{"name":"mysql-5.5","source":"https://ubuntu.com/security/cve?package=mysql-5.5","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=mysql-5.5","debian":"https://tracker.debian.org/pkg/mysql-5.5","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"mysql-cluster-7.0","source":"https://ubuntu.com/security/cve?package=mysql-cluster-7.0","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=mysql-cluster-7.0","debian":"https://tracker.debian.org/pkg/mysql-cluster-7.0","statuses":[{"release_codename":"lucid","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mysql-dfsg-5.1","source":"https://ubuntu.com/security/cve?package=mysql-dfsg-5.1","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=mysql-dfsg-5.1","debian":"https://tracker.debian.org/pkg/mysql-dfsg-5.1","statuses":[{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-5789","published":"2013-10-16T15:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUnspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60\nand earlier, and Java SE Embedded 7u40 and earlier allows remote attackers\nto affect confidentiality, integrity, and availability via unknown vectors\nrelated to Deployment, a different vulnerability than CVE-2013-5787,\nCVE-2013-5824, CVE-2013-5832, and CVE-2013-5852.","ubuntu_description":"","notes":[{"author":"seth-arnold","note":"From Debian's triage, \"(Deployment components not part of OpenJDK,\nonly present in Oracle Java)\""}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html","https://www.cve.org/CVERecord?id=CVE-2013-5789"],"bugs":[""],"patches":{"openjdk-7":[],"openjdk-6":[]},"tags":{},"packages":[{"name":"openjdk-6","source":"https://ubuntu.com/security/cve?package=openjdk-6","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=openjdk-6","debian":"https://tracker.debian.org/pkg/openjdk-6","statuses":[{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"openjdk-7","source":"https://ubuntu.com/security/cve?package=openjdk-7","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=openjdk-7","debian":"https://tracker.debian.org/pkg/openjdk-7","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-5788","published":"2013-10-16T15:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUnspecified vulnerability in Oracle Java SE 7u40 and earlier and Java SE\nEmbedded 7u40 and earlier allows remote attackers to affect\nconfidentiality, integrity, and availability via unknown vectors related to\nDeployment.","ubuntu_description":"","notes":[{"author":"seth-arnold","note":"From Debian's triage, \"(Deployment components not part of OpenJDK,\nonly present in Oracle Java)\""}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html","https://www.cve.org/CVERecord?id=CVE-2013-5788"],"bugs":[""],"patches":{"openjdk-7":[],"openjdk-6":[]},"tags":{},"packages":[{"name":"openjdk-6","source":"https://ubuntu.com/security/cve?package=openjdk-6","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=openjdk-6","debian":"https://tracker.debian.org/pkg/openjdk-6","statuses":[{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"openjdk-7","source":"https://ubuntu.com/security/cve?package=openjdk-7","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=openjdk-7","debian":"https://tracker.debian.org/pkg/openjdk-7","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-5787","published":"2013-10-16T15:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUnspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60\nand earlier, and Java SE Embedded 7u40 and earlier allows remote attackers\nto affect confidentiality, integrity, and availability via unknown vectors\nrelated to Deployment, a different vulnerability than CVE-2013-5789,\nCVE-2013-5824, CVE-2013-5832, and CVE-2013-5852.","ubuntu_description":"","notes":[{"author":"seth-arnold","note":"From Debian's triage, \"(Deployment components not part of OpenJDK,\nonly present in Oracle Java)\""}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html","https://www.cve.org/CVERecord?id=CVE-2013-5787"],"bugs":[""],"patches":{"openjdk-7":[],"openjdk-6":[]},"tags":{},"packages":[{"name":"openjdk-6","source":"https://ubuntu.com/security/cve?package=openjdk-6","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=openjdk-6","debian":"https://tracker.debian.org/pkg/openjdk-6","statuses":[{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"openjdk-7","source":"https://ubuntu.com/security/cve?package=openjdk-7","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=openjdk-7","debian":"https://tracker.debian.org/pkg/openjdk-7","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-5786","published":"2013-10-16T15:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUnspecified vulnerability in Oracle MySQL Server 5.6.12 and earlier allows\nremote authenticated users to affect availability via unknown vectors\nrelated to InnoDB, a different vulnerability than CVE-2013-5793.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"mysql-cluster-7.0 not supported per Ubuntu Server team"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html","https://www.cve.org/CVERecord?id=CVE-2013-5786"],"bugs":[""],"patches":{"mysql-dfsg-5.1":[],"mysql-5.5":[],"mysql-cluster-7.0":[]},"tags":{},"packages":[{"name":"mysql-5.5","source":"https://ubuntu.com/security/cve?package=mysql-5.5","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=mysql-5.5","debian":"https://tracker.debian.org/pkg/mysql-5.5","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"mysql-cluster-7.0","source":"https://ubuntu.com/security/cve?package=mysql-cluster-7.0","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=mysql-cluster-7.0","debian":"https://tracker.debian.org/pkg/mysql-cluster-7.0","statuses":[{"release_codename":"lucid","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mysql-dfsg-5.1","source":"https://ubuntu.com/security/cve?package=mysql-dfsg-5.1","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=mysql-dfsg-5.1","debian":"https://tracker.debian.org/pkg/mysql-dfsg-5.1","statuses":[{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-5777","published":"2013-10-16T15:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUnspecified vulnerability in the Java SE and JavaFX components in Oracle\nJava SE 7u40 and earlier and JavaFX 2.2.40 and earlier allows remote\nattackers to affect confidentiality, integrity, and availability via\nunknown vectors, a different vulnerability than CVE-2013-5775.","ubuntu_description":"","notes":[{"author":"seth-arnold","note":"OpenJDK doesn't contain JavaFX"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html","https://www.cve.org/CVERecord?id=CVE-2013-5777"],"bugs":[""],"patches":{"openjdk-7":[],"openjdk-6":[]},"tags":{},"packages":[{"name":"openjdk-6","source":"https://ubuntu.com/security/cve?package=openjdk-6","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=openjdk-6","debian":"https://tracker.debian.org/pkg/openjdk-6","statuses":[{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"openjdk-7","source":"https://ubuntu.com/security/cve?package=openjdk-7","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=openjdk-7","debian":"https://tracker.debian.org/pkg/openjdk-7","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-5776","published":"2013-10-16T15:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUnspecified vulnerability in the Java SE and Java SE Embedded components in\nOracle Java SE Java SE 7u40 and earlier, Java SE 6u60 and earlier, and Java\nSE Embedded 7u40 and earlier allows remote attackers to affect integrity\nvia unknown vectors related to Deployment.","ubuntu_description":"","notes":[{"author":"seth-arnold","note":"From Debian's triage, \"(Deployment components not part of OpenJDK,\nonly present in Oracle Java)\""}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html","https://www.cve.org/CVERecord?id=CVE-2013-5776"],"bugs":[""],"patches":{"openjdk-7":[],"openjdk-6":[]},"tags":{},"packages":[{"name":"openjdk-6","source":"https://ubuntu.com/security/cve?package=openjdk-6","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=openjdk-6","debian":"https://tracker.debian.org/pkg/openjdk-6","statuses":[{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"openjdk-7","source":"https://ubuntu.com/security/cve?package=openjdk-7","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=openjdk-7","debian":"https://tracker.debian.org/pkg/openjdk-7","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-5775","published":"2013-10-16T15:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUnspecified vulnerability in the Java SE and JavaFX components in Oracle\nJava SE 7u40 and earlier and JavaFX 2.2.40 and earlier allows remote\nattackers to affect confidentiality, integrity, and availability via\nunknown vectors, a different vulnerability than CVE-2013-5777.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"Oracle Java"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html","https://www.cve.org/CVERecord?id=CVE-2013-5775"],"bugs":[""],"patches":{"openjdk-7":[],"openjdk-6":[]},"tags":{},"packages":[{"name":"openjdk-6","source":"https://ubuntu.com/security/cve?package=openjdk-6","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=openjdk-6","debian":"https://tracker.debian.org/pkg/openjdk-6","statuses":[{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"openjdk-7","source":"https://ubuntu.com/security/cve?package=openjdk-7","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=openjdk-7","debian":"https://tracker.debian.org/pkg/openjdk-7","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-5770","published":"2013-10-16T15:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUnspecified vulnerability in the MySQL Server component in Oracle MySQL\n5.6.11 and earlier allows remote authenticated users to affect availability\nvia unknown vectors related to Locking.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"mysql-cluster-7.0 not supported per Ubuntu Server team"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html","https://www.cve.org/CVERecord?id=CVE-2013-5770"],"bugs":[""],"patches":{"mysql-dfsg-5.1":[],"mysql-5.5":[],"mysql-cluster-7.0":[]},"tags":{},"packages":[{"name":"mysql-5.5","source":"https://ubuntu.com/security/cve?package=mysql-5.5","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=mysql-5.5","debian":"https://tracker.debian.org/pkg/mysql-5.5","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"mysql-cluster-7.0","source":"https://ubuntu.com/security/cve?package=mysql-cluster-7.0","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=mysql-cluster-7.0","debian":"https://tracker.debian.org/pkg/mysql-cluster-7.0","statuses":[{"release_codename":"lucid","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mysql-dfsg-5.1","source":"https://ubuntu.com/security/cve?package=mysql-dfsg-5.1","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=mysql-dfsg-5.1","debian":"https://tracker.debian.org/pkg/mysql-dfsg-5.1","statuses":[{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-5767","published":"2013-10-16T15:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUnspecified vulnerability in the MySQL Server component in Oracle MySQL\n5.6.12 and earlier allows remote authenticated users to affect availability\nvia unknown vectors related to Optimizer.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"mysql-cluster-7.0 not supported per Ubuntu Server team"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html","https://www.cve.org/CVERecord?id=CVE-2013-5767"],"bugs":[""],"patches":{"mysql-dfsg-5.1":[],"mysql-5.5":[],"mysql-cluster-7.0":[]},"tags":{},"packages":[{"name":"mysql-5.5","source":"https://ubuntu.com/security/cve?package=mysql-5.5","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=mysql-5.5","debian":"https://tracker.debian.org/pkg/mysql-5.5","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"mysql-cluster-7.0","source":"https://ubuntu.com/security/cve?package=mysql-cluster-7.0","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=mysql-cluster-7.0","debian":"https://tracker.debian.org/pkg/mysql-cluster-7.0","statuses":[{"release_codename":"lucid","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mysql-dfsg-5.1","source":"https://ubuntu.com/security/cve?package=mysql-dfsg-5.1","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=mysql-dfsg-5.1","debian":"https://tracker.debian.org/pkg/mysql-dfsg-5.1","statuses":[{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-3792","published":"2013-10-16T15:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUnspecified vulnerability in the Oracle VM VirtualBox component in Oracle\nVirtualization VirtualBox prior to 3.2.18, 4.0.20, 4.1.28, and 4.2.18\nallows local users to affect availability via unknown vectors related to\nCore.","ubuntu_description":"","notes":[{"author":"seth-arnold","note":"Felix Geyer reports only Raring is affected"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.virtualbox.org/ticket/11863","https://www.cve.org/CVERecord?id=CVE-2013-3792"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=715327"],"patches":{"virtualbox-ose":[],"virtualbox":[]},"tags":{},"packages":[{"name":"virtualbox","source":"https://ubuntu.com/security/cve?package=virtualbox","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=virtualbox","debian":"https://tracker.debian.org/pkg/virtualbox","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"4.2.10-dfsg-0ubuntu2.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.2.16","component":null,"pocket":"security"}]},{"name":"virtualbox-ose","source":"https://ubuntu.com/security/cve?package=virtualbox-ose","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=virtualbox-ose","debian":"https://tracker.debian.org/pkg/virtualbox-ose","statuses":[{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-5851","published":"2013-10-16T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUnspecified vulnerability in Oracle Java SE 7u40 and earlier and Java SE\nEmbedded 7u40 and earlier allows remote attackers to affect confidentiality\nvia vectors related to JAXP.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"no 2.3 update as of 2013/12/20. 2.4/armhf needs to be fixed"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html","https://ubuntu.com/security/notices/USN-2033-1","https://ubuntu.com/security/notices/USN-2089-1","https://www.cve.org/CVERecord?id=CVE-2013-5851"],"bugs":[""],"patches":{"openjdk-7":[],"openjdk-6":[]},"tags":{},"packages":[{"name":"openjdk-6","source":"https://ubuntu.com/security/cve?package=openjdk-6","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=openjdk-6","debian":"https://tracker.debian.org/pkg/openjdk-6","statuses":[{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"openjdk-7","source":"https://ubuntu.com/security/cve?package=openjdk-7","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=openjdk-7","debian":"https://tracker.debian.org/pkg/openjdk-7","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"7u51-2.4.4-0ubuntu0.12.04.2","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"7u51-2.4.4-0ubuntu0.12.10.2","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"7u51-2.4.4-0ubuntu0.13.04.2","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"7u51-2.4.4-0ubuntu0.13.10.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-2089-1","USN-2033-1"],"notices":[{"id":"USN-2089-1","title":"OpenJDK 7 vulnerabilities","summary":"Several security issues were fixed in OpenJDK 7.\n","instructions":"This update uses a new upstream release, which includes additional bug\nfixes. After a standard system update you need to restart any Java\napplications or applets to make all the necessary changes.\n","references":[],"published":"2014-01-23T20:58:26.167195","description":"\nSeveral vulnerabilities were discovered in the OpenJDK JRE related to\ninformation disclosure and data integrity. An attacker could exploit these\nto expose sensitive data over the network. (CVE-2013-3829, CVE-2013-5783,\nCVE-2013-5804, CVE-2014-0411)\n\nSeveral vulnerabilities were discovered in the OpenJDK JRE related to\navailability. An attacker could exploit these to cause a denial of service.\n(CVE-2013-4002, CVE-2013-5803, CVE-2013-5823, CVE-2013-5825, CVE-2013-5896,\nCVE-2013-5910)\n\nSeveral vulnerabilities were discovered in the OpenJDK JRE related to data\nintegrity. (CVE-2013-5772, CVE-2013-5774, CVE-2013-5784, CVE-2013-5797,\nCVE-2013-5820, CVE-2014-0376, CVE-2014-0416)\n\nSeveral vulnerabilities were discovered in the OpenJDK JRE related to\ninformation disclosure. An attacker could exploit these to expose sensitive\ndata over the network. (CVE-2013-5778, CVE-2013-5780, CVE-2013-5790,\nCVE-2013-5800, CVE-2013-5840, CVE-2013-5849, CVE-2013-5851, CVE-2013-5884,\nCVE-2014-0368)\n\nSeveral vulnerabilities were discovered in the OpenJDK JRE related to\ninformation disclosure, data integrity and availability. An attacker could\nexploit these to cause a denial of service or expose sensitive data over\nthe network. (CVE-2013-5782, CVE-2013-5802, CVE-2013-5809, CVE-2013-5829,\nCVE-2013-5814, CVE-2013-5817, CVE-2013-5830, CVE-2013-5842, CVE-2013-5850,\nCVE-2013-5878, CVE-2013-5893, CVE-2013-5907, CVE-2014-0373, CVE-2014-0408,\nCVE-2014-0422, CVE-2014-0428)\n\nA vulnerability was discovered in the OpenJDK JRE related to information\ndisclosure and availability. An attacker could exploit this to expose\nsensitive data over the network or cause a denial of service.\n(CVE-2014-0423)\n","is_hidden":false,"release_packages":{"saucy":[{"name":"openjdk-7","version":"7u51-2.4.4-0ubuntu0.13.10.1","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-7-jre-lib","version":"7u51-2.4.4-0ubuntu0.13.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.13.10.1"},{"name":"openjdk-7-jre-zero","version":"7u51-2.4.4-0ubuntu0.13.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.13.10.1"},{"name":"icedtea-7-jre-jamvm","version":"7u51-2.4.4-0ubuntu0.13.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.13.10.1"},{"name":"openjdk-7-jre-headless","version":"7u51-2.4.4-0ubuntu0.13.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.13.10.1"},{"name":"openjdk-7-jre","version":"7u51-2.4.4-0ubuntu0.13.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.13.10.1"}],"quantal":[{"name":"openjdk-7","version":"7u51-2.4.4-0ubuntu0.12.10.2","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-7-jre-zero","version":"7u51-2.4.4-0ubuntu0.12.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.12.10.2"},{"name":"icedtea-7-jre-jamvm","version":"7u51-2.4.4-0ubuntu0.12.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.12.10.2"},{"name":"icedtea-7-jre-cacao","version":"7u51-2.4.4-0ubuntu0.12.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.12.10.2"},{"name":"openjdk-7-jre-lib","version":"7u51-2.4.4-0ubuntu0.12.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.12.10.2"},{"name":"openjdk-7-jre-headless","version":"7u51-2.4.4-0ubuntu0.12.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.12.10.2"},{"name":"openjdk-7-jre","version":"7u51-2.4.4-0ubuntu0.12.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.12.10.2"}],"raring":[{"name":"openjdk-7","version":"7u51-2.4.4-0ubuntu0.13.04.2","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-7-jre-lib","version":"7u51-2.4.4-0ubuntu0.13.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.13.04.2"},{"name":"openjdk-7-jre-zero","version":"7u51-2.4.4-0ubuntu0.13.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.13.04.2"},{"name":"icedtea-7-jre-jamvm","version":"7u51-2.4.4-0ubuntu0.13.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.13.04.2"},{"name":"openjdk-7-jre-headless","version":"7u51-2.4.4-0ubuntu0.13.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.13.04.2"},{"name":"openjdk-7-jre","version":"7u51-2.4.4-0ubuntu0.13.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.13.04.2"}]},"type":"USN","cves_ids":["CVE-2013-5817","CVE-2013-5820","CVE-2013-5823","CVE-2013-5825","CVE-2013-5829","CVE-2013-5830","CVE-2013-5840","CVE-2013-5842","CVE-2013-5849","CVE-2013-5850","CVE-2013-5851","CVE-2013-5878","CVE-2013-5884","CVE-2013-5896","CVE-2013-5907","CVE-2013-5910","CVE-2014-0368","CVE-2014-0373","CVE-2014-0376","CVE-2014-0411","CVE-2014-0416","CVE-2014-0422","CVE-2014-0423","CVE-2014-0428","CVE-2014-0408","CVE-2013-5806","CVE-2013-5800","CVE-2013-5805","CVE-2013-5893","CVE-2013-3829","CVE-2013-4002","CVE-2013-5772","CVE-2013-5774","CVE-2013-5778","CVE-2013-5780","CVE-2013-5782","CVE-2013-5783","CVE-2013-5784","CVE-2013-5790","CVE-2013-5797","CVE-2013-5802","CVE-2013-5803","CVE-2013-5804","CVE-2013-5809","CVE-2013-5814"]},{"id":"USN-2033-1","title":"OpenJDK 6 vulnerabilities","summary":"Several security issues were fixed in OpenJDK 6.\n","instructions":"This update uses a new upstream release, which includes additional bug\nfixes. After a standard system update you need to restart any Java\napplications or applets to make all the necessary changes.\n","references":[],"published":"2013-11-21T22:49:43.174863","description":"Several vulnerabilities were discovered in the OpenJDK JRE related to\ninformation disclosure and data integrity. An attacker could exploit these\nto expose sensitive data over the network. (CVE-2013-3829, CVE-2013-5783,\nCVE-2013-5804)\n\nSeveral vulnerabilities were discovered in the OpenJDK JRE related to\navailability. An attacker could exploit these to cause a denial of service.\n(CVE-2013-4002, CVE-2013-5803, CVE-2013-5823, CVE-2013-5825)\n\nSeveral vulnerabilities were discovered in the OpenJDK JRE related to data\nintegrity. (CVE-2013-5772, CVE-2013-5774, CVE-2013-5784, CVE-2013-5797,\nCVE-2013-5820)\n\nSeveral vulnerabilities were discovered in the OpenJDK JRE related to\ninformation disclosure. An attacker could exploit these to expose sensitive\ndata over the network. (CVE-2013-5778, CVE-2013-5780, CVE-2013-5790,\nCVE-2013-5840, CVE-2013-5849, CVE-2013-5851)\n\nSeveral vulnerabilities were discovered in the OpenJDK JRE related to\ninformation disclosure, data integrity and availability. An attacker could\nexploit these to cause a denial of service or expose sensitive data over\nthe network. (CVE-2013-5782, CVE-2013-5802, CVE-2013-5809, CVE-2013-5829,\nCVE-2013-5814, CVE-2013-5817, CVE-2013-5830, CVE-2013-5842, CVE-2013-5850)\n","is_hidden":false,"release_packages":{"precise":[{"name":"openjdk-6","version":"6b27-1.12.6-1ubuntu0.12.04.4","description":"Open Source Java implementation","is_source":true},{"name":"icedtea-6-jre-cacao","version":"6b27-1.12.6-1ubuntu0.12.04.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.6-1ubuntu0.12.04.4"},{"name":"icedtea-6-jre-jamvm","version":"6b27-1.12.6-1ubuntu0.12.04.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.6-1ubuntu0.12.04.4"},{"name":"openjdk-6-jre","version":"6b27-1.12.6-1ubuntu0.12.04.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.6-1ubuntu0.12.04.4"},{"name":"openjdk-6-jre-headless","version":"6b27-1.12.6-1ubuntu0.12.04.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.6-1ubuntu0.12.04.4"},{"name":"openjdk-6-jre-zero","version":"6b27-1.12.6-1ubuntu0.12.04.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.6-1ubuntu0.12.04.4"},{"name":"openjdk-6-jre-lib","version":"6b27-1.12.6-1ubuntu0.12.04.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.6-1ubuntu0.12.04.4"}],"lucid":[{"name":"openjdk-6","version":"6b27-1.12.6-1ubuntu0.10.04.4","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-6-jre-headless","version":"6b27-1.12.6-1ubuntu0.10.04.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.6-1ubuntu0.10.04.4"},{"name":"openjdk-6-jre-lib","version":"6b27-1.12.6-1ubuntu0.10.04.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.6-1ubuntu0.10.04.4"},{"name":"icedtea-6-jre-cacao","version":"6b27-1.12.6-1ubuntu0.10.04.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.6-1ubuntu0.10.04.4"},{"name":"openjdk-6-jre","version":"6b27-1.12.6-1ubuntu0.10.04.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.6-1ubuntu0.10.04.4"},{"name":"openjdk-6-jre-zero","version":"6b27-1.12.6-1ubuntu0.10.04.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.6-1ubuntu0.10.04.4"}]},"type":"USN","cves_ids":["CVE-2013-3829","CVE-2013-4002","CVE-2013-5772","CVE-2013-5774","CVE-2013-5778","CVE-2013-5780","CVE-2013-5782","CVE-2013-5783","CVE-2013-5784","CVE-2013-5790","CVE-2013-5797","CVE-2013-5802","CVE-2013-5803","CVE-2013-5804","CVE-2013-5809","CVE-2013-5814","CVE-2013-5817","CVE-2013-5820","CVE-2013-5823","CVE-2013-5825","CVE-2013-5829","CVE-2013-5830","CVE-2013-5840","CVE-2013-5842","CVE-2013-5849","CVE-2013-5850","CVE-2013-5851"]}]},{"id":"CVE-2013-5850","published":"2013-10-16T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUnspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60\nand earlier, Java SE 5.0u51 and earlier, and Java SE Embedded 7u40 and\nearlier allows remote attackers to affect confidentiality, integrity, and\navailability via unknown vectors related to Libraries, a different\nvulnerability than CVE-2013-5842.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"no 2.3 update as of 2013/12/20. 2.4/armhf needs to be fixed\nIcedTea 2.3.x security not available yet\nIcedTea 1.12.x security not available. Upstream seems to be focusing\non 1.11 (1.11.4 was released with fixes) for openjdk-6."}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html","https://ubuntu.com/security/notices/USN-2033-1","https://ubuntu.com/security/notices/USN-2089-1","https://www.cve.org/CVERecord?id=CVE-2013-5850"],"bugs":[""],"patches":{"openjdk-7":[],"openjdk-6":[]},"tags":{},"packages":[{"name":"openjdk-6","source":"https://ubuntu.com/security/cve?package=openjdk-6","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=openjdk-6","debian":"https://tracker.debian.org/pkg/openjdk-6","statuses":[{"release_codename":"lucid","status":"released","description":"6b27-1.12.6-1ubuntu0.10.04.4","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"6b27-1.12.6-1ubuntu0.12.04.4","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"6b27-1.12.6-1ubuntu0.12.10.4","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"6b27-1.12.6-1ubuntu0.13.04.4","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"6b27-1.12.6-1ubuntu2.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"}]},{"name":"openjdk-7","source":"https://ubuntu.com/security/cve?package=openjdk-7","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=openjdk-7","debian":"https://tracker.debian.org/pkg/openjdk-7","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"7u51-2.4.4-0ubuntu0.12.04.2","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"7u51-2.4.4-0ubuntu0.12.10.2","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"7u51-2.4.4-0ubuntu0.13.04.2","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"7u51-2.4.4-0ubuntu0.13.10.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-2089-1","USN-2033-1"],"notices":[{"id":"USN-2089-1","title":"OpenJDK 7 vulnerabilities","summary":"Several security issues were fixed in OpenJDK 7.\n","instructions":"This update uses a new upstream release, which includes additional bug\nfixes. After a standard system update you need to restart any Java\napplications or applets to make all the necessary changes.\n","references":[],"published":"2014-01-23T20:58:26.167195","description":"\nSeveral vulnerabilities were discovered in the OpenJDK JRE related to\ninformation disclosure and data integrity. An attacker could exploit these\nto expose sensitive data over the network. (CVE-2013-3829, CVE-2013-5783,\nCVE-2013-5804, CVE-2014-0411)\n\nSeveral vulnerabilities were discovered in the OpenJDK JRE related to\navailability. An attacker could exploit these to cause a denial of service.\n(CVE-2013-4002, CVE-2013-5803, CVE-2013-5823, CVE-2013-5825, CVE-2013-5896,\nCVE-2013-5910)\n\nSeveral vulnerabilities were discovered in the OpenJDK JRE related to data\nintegrity. (CVE-2013-5772, CVE-2013-5774, CVE-2013-5784, CVE-2013-5797,\nCVE-2013-5820, CVE-2014-0376, CVE-2014-0416)\n\nSeveral vulnerabilities were discovered in the OpenJDK JRE related to\ninformation disclosure. An attacker could exploit these to expose sensitive\ndata over the network. (CVE-2013-5778, CVE-2013-5780, CVE-2013-5790,\nCVE-2013-5800, CVE-2013-5840, CVE-2013-5849, CVE-2013-5851, CVE-2013-5884,\nCVE-2014-0368)\n\nSeveral vulnerabilities were discovered in the OpenJDK JRE related to\ninformation disclosure, data integrity and availability. An attacker could\nexploit these to cause a denial of service or expose sensitive data over\nthe network. (CVE-2013-5782, CVE-2013-5802, CVE-2013-5809, CVE-2013-5829,\nCVE-2013-5814, CVE-2013-5817, CVE-2013-5830, CVE-2013-5842, CVE-2013-5850,\nCVE-2013-5878, CVE-2013-5893, CVE-2013-5907, CVE-2014-0373, CVE-2014-0408,\nCVE-2014-0422, CVE-2014-0428)\n\nA vulnerability was discovered in the OpenJDK JRE related to information\ndisclosure and availability. An attacker could exploit this to expose\nsensitive data over the network or cause a denial of service.\n(CVE-2014-0423)\n","is_hidden":false,"release_packages":{"saucy":[{"name":"openjdk-7","version":"7u51-2.4.4-0ubuntu0.13.10.1","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-7-jre-lib","version":"7u51-2.4.4-0ubuntu0.13.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.13.10.1"},{"name":"openjdk-7-jre-zero","version":"7u51-2.4.4-0ubuntu0.13.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.13.10.1"},{"name":"icedtea-7-jre-jamvm","version":"7u51-2.4.4-0ubuntu0.13.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.13.10.1"},{"name":"openjdk-7-jre-headless","version":"7u51-2.4.4-0ubuntu0.13.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.13.10.1"},{"name":"openjdk-7-jre","version":"7u51-2.4.4-0ubuntu0.13.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.13.10.1"}],"quantal":[{"name":"openjdk-7","version":"7u51-2.4.4-0ubuntu0.12.10.2","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-7-jre-zero","version":"7u51-2.4.4-0ubuntu0.12.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.12.10.2"},{"name":"icedtea-7-jre-jamvm","version":"7u51-2.4.4-0ubuntu0.12.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.12.10.2"},{"name":"icedtea-7-jre-cacao","version":"7u51-2.4.4-0ubuntu0.12.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.12.10.2"},{"name":"openjdk-7-jre-lib","version":"7u51-2.4.4-0ubuntu0.12.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.12.10.2"},{"name":"openjdk-7-jre-headless","version":"7u51-2.4.4-0ubuntu0.12.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.12.10.2"},{"name":"openjdk-7-jre","version":"7u51-2.4.4-0ubuntu0.12.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.12.10.2"}],"raring":[{"name":"openjdk-7","version":"7u51-2.4.4-0ubuntu0.13.04.2","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-7-jre-lib","version":"7u51-2.4.4-0ubuntu0.13.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.13.04.2"},{"name":"openjdk-7-jre-zero","version":"7u51-2.4.4-0ubuntu0.13.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.13.04.2"},{"name":"icedtea-7-jre-jamvm","version":"7u51-2.4.4-0ubuntu0.13.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.13.04.2"},{"name":"openjdk-7-jre-headless","version":"7u51-2.4.4-0ubuntu0.13.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.13.04.2"},{"name":"openjdk-7-jre","version":"7u51-2.4.4-0ubuntu0.13.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.13.04.2"}]},"type":"USN","cves_ids":["CVE-2013-5817","CVE-2013-5820","CVE-2013-5823","CVE-2013-5825","CVE-2013-5829","CVE-2013-5830","CVE-2013-5840","CVE-2013-5842","CVE-2013-5849","CVE-2013-5850","CVE-2013-5851","CVE-2013-5878","CVE-2013-5884","CVE-2013-5896","CVE-2013-5907","CVE-2013-5910","CVE-2014-0368","CVE-2014-0373","CVE-2014-0376","CVE-2014-0411","CVE-2014-0416","CVE-2014-0422","CVE-2014-0423","CVE-2014-0428","CVE-2014-0408","CVE-2013-5806","CVE-2013-5800","CVE-2013-5805","CVE-2013-5893","CVE-2013-3829","CVE-2013-4002","CVE-2013-5772","CVE-2013-5774","CVE-2013-5778","CVE-2013-5780","CVE-2013-5782","CVE-2013-5783","CVE-2013-5784","CVE-2013-5790","CVE-2013-5797","CVE-2013-5802","CVE-2013-5803","CVE-2013-5804","CVE-2013-5809","CVE-2013-5814"]},{"id":"USN-2033-1","title":"OpenJDK 6 vulnerabilities","summary":"Several security issues were fixed in OpenJDK 6.\n","instructions":"This update uses a new upstream release, which includes additional bug\nfixes. After a standard system update you need to restart any Java\napplications or applets to make all the necessary changes.\n","references":[],"published":"2013-11-21T22:49:43.174863","description":"Several vulnerabilities were discovered in the OpenJDK JRE related to\ninformation disclosure and data integrity. An attacker could exploit these\nto expose sensitive data over the network. (CVE-2013-3829, CVE-2013-5783,\nCVE-2013-5804)\n\nSeveral vulnerabilities were discovered in the OpenJDK JRE related to\navailability. An attacker could exploit these to cause a denial of service.\n(CVE-2013-4002, CVE-2013-5803, CVE-2013-5823, CVE-2013-5825)\n\nSeveral vulnerabilities were discovered in the OpenJDK JRE related to data\nintegrity. (CVE-2013-5772, CVE-2013-5774, CVE-2013-5784, CVE-2013-5797,\nCVE-2013-5820)\n\nSeveral vulnerabilities were discovered in the OpenJDK JRE related to\ninformation disclosure. An attacker could exploit these to expose sensitive\ndata over the network. (CVE-2013-5778, CVE-2013-5780, CVE-2013-5790,\nCVE-2013-5840, CVE-2013-5849, CVE-2013-5851)\n\nSeveral vulnerabilities were discovered in the OpenJDK JRE related to\ninformation disclosure, data integrity and availability. An attacker could\nexploit these to cause a denial of service or expose sensitive data over\nthe network. (CVE-2013-5782, CVE-2013-5802, CVE-2013-5809, CVE-2013-5829,\nCVE-2013-5814, CVE-2013-5817, CVE-2013-5830, CVE-2013-5842, CVE-2013-5850)\n","is_hidden":false,"release_packages":{"precise":[{"name":"openjdk-6","version":"6b27-1.12.6-1ubuntu0.12.04.4","description":"Open Source Java implementation","is_source":true},{"name":"icedtea-6-jre-cacao","version":"6b27-1.12.6-1ubuntu0.12.04.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.6-1ubuntu0.12.04.4"},{"name":"icedtea-6-jre-jamvm","version":"6b27-1.12.6-1ubuntu0.12.04.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.6-1ubuntu0.12.04.4"},{"name":"openjdk-6-jre","version":"6b27-1.12.6-1ubuntu0.12.04.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.6-1ubuntu0.12.04.4"},{"name":"openjdk-6-jre-headless","version":"6b27-1.12.6-1ubuntu0.12.04.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.6-1ubuntu0.12.04.4"},{"name":"openjdk-6-jre-zero","version":"6b27-1.12.6-1ubuntu0.12.04.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.6-1ubuntu0.12.04.4"},{"name":"openjdk-6-jre-lib","version":"6b27-1.12.6-1ubuntu0.12.04.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.6-1ubuntu0.12.04.4"}],"lucid":[{"name":"openjdk-6","version":"6b27-1.12.6-1ubuntu0.10.04.4","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-6-jre-headless","version":"6b27-1.12.6-1ubuntu0.10.04.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.6-1ubuntu0.10.04.4"},{"name":"openjdk-6-jre-lib","version":"6b27-1.12.6-1ubuntu0.10.04.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.6-1ubuntu0.10.04.4"},{"name":"icedtea-6-jre-cacao","version":"6b27-1.12.6-1ubuntu0.10.04.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.6-1ubuntu0.10.04.4"},{"name":"openjdk-6-jre","version":"6b27-1.12.6-1ubuntu0.10.04.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.6-1ubuntu0.10.04.4"},{"name":"openjdk-6-jre-zero","version":"6b27-1.12.6-1ubuntu0.10.04.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.6-1ubuntu0.10.04.4"}]},"type":"USN","cves_ids":["CVE-2013-3829","CVE-2013-4002","CVE-2013-5772","CVE-2013-5774","CVE-2013-5778","CVE-2013-5780","CVE-2013-5782","CVE-2013-5783","CVE-2013-5784","CVE-2013-5790","CVE-2013-5797","CVE-2013-5802","CVE-2013-5803","CVE-2013-5804","CVE-2013-5809","CVE-2013-5814","CVE-2013-5817","CVE-2013-5820","CVE-2013-5823","CVE-2013-5825","CVE-2013-5829","CVE-2013-5830","CVE-2013-5840","CVE-2013-5842","CVE-2013-5849","CVE-2013-5850","CVE-2013-5851"]}]}],"offset":66800,"limit":20,"total_results":79316}