CVE-2014-0376

Unspecified vulnerability in Oracle Java SE 5.0u55, 6u65, and 7u45; Java SE Embedded 7u45; and OpenJDK 7 allows remote attackers to affect integrity via vectors related to JAXP.  NOTE: the previous information is from the January 2014 CPU. Oracle has not commented on third-party claims that the issue is related to an improper check for "code permissions when creating document builder factories."
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:N/I:P/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 81%
Affected Products (NVD)
VendorProductVersion
oraclejdk
1.7.0
oraclejre
1.7.0
oraclejdk
1.6.0
oraclejre
1.6.0
oraclejdk
1.5.0
oraclejre
1.5.0
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
openjdk-6
lucid
Fixed 6b30-1.13.1-1ubuntu2~0.10.04.1
released
precise
Fixed 6b30-1.13.1-1ubuntu2~0.12.04.1
released
quantal
Fixed 6b30-1.13.1-1ubuntu2~0.12.10.1
released
raring
ignored
saucy
Fixed 6b30-1.13.1-1ubuntu2~0.13.10.1
released
openjdk-7
lucid
dne
precise
Fixed 7u51-2.4.4-0ubuntu0.12.04.2
released
quantal
Fixed 7u51-2.4.4-0ubuntu0.12.10.2
released
raring
Fixed 7u51-2.4.4-0ubuntu0.13.04.2
released
saucy
Fixed 7u51-2.4.4-0ubuntu0.13.10.1
released
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
java-1_7_0-openjdk
suse enterprise sap 12 SP5
1.7.0.231-43.27.2
fixed
suse enterprise server 12 SP2
1.7.0.111-33.1
fixed
suse enterprise server 12 SP5
1.7.0.231-43.27.2
fixed
java-1_7_0-openjdk-demo
suse enterprise sap 12 SP5
1.7.0.231-43.27.2
fixed
suse enterprise server 12 SP2
1.7.0.111-33.1
fixed
suse enterprise server 12 SP5
1.7.0.231-43.27.2
fixed
java-1_7_0-openjdk-devel
suse enterprise sap 12 SP5
1.7.0.231-43.27.2
fixed
suse enterprise server 12 SP2
1.7.0.111-33.1
fixed
suse enterprise server 12 SP5
1.7.0.231-43.27.2
fixed
java-1_7_0-openjdk-headless
suse enterprise sap 12 SP5
1.7.0.231-43.27.2
fixed
suse enterprise server 12 SP2
1.7.0.111-33.1
fixed
suse enterprise server 12 SP5
1.7.0.231-43.27.2
fixed
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
java-1.5.0-ibm
RHEL 6
1:1.5.0.16.5-1jpp.1.el6_5
fixed
java-1.5.0-ibm-demo
RHEL 6
1:1.5.0.16.5-1jpp.1.el6_5
fixed
java-1.5.0-ibm-devel
RHEL 6
1:1.5.0.16.5-1jpp.1.el6_5
fixed
java-1.5.0-ibm-javacomm
RHEL 6
1:1.5.0.16.5-1jpp.1.el6_5
fixed
java-1.5.0-ibm-jdbc
RHEL 6
1:1.5.0.16.5-1jpp.1.el6_5
fixed
java-1.5.0-ibm-plugin
RHEL 6
1:1.5.0.16.5-1jpp.1.el6_5
fixed
java-1.5.0-ibm-src
RHEL 6
1:1.5.0.16.5-1jpp.1.el6_5
fixed
java-1.6.0-ibm
RHEL 6
1:1.6.0.15.1-1jpp.1.el6_5
fixed
java-1.6.0-ibm-demo
RHEL 6
1:1.6.0.15.1-1jpp.1.el6_5
fixed
java-1.6.0-ibm-devel
RHEL 6
1:1.6.0.15.1-1jpp.1.el6_5
fixed
java-1.6.0-ibm-javacomm
RHEL 6
1:1.6.0.15.1-1jpp.1.el6_5
fixed
java-1.6.0-ibm-jdbc
RHEL 6
1:1.6.0.15.1-1jpp.1.el6_5
fixed
java-1.6.0-ibm-plugin
RHEL 6
1:1.6.0.15.1-1jpp.1.el6_5
fixed
java-1.6.0-ibm-src
RHEL 6
1:1.6.0.15.1-1jpp.1.el6_5
fixed
java-1.6.0-openjdk
RHEL 6
1:1.6.0.0-3.1.13.1.el6_5
fixed
java-1.6.0-openjdk-demo
RHEL 6
1:1.6.0.0-3.1.13.1.el6_5
fixed
java-1.6.0-openjdk-devel
RHEL 6
1:1.6.0.0-3.1.13.1.el6_5
fixed
java-1.6.0-openjdk-javadoc
RHEL 6
1:1.6.0.0-3.1.13.1.el6_5
fixed
java-1.6.0-openjdk-src
RHEL 6
1:1.6.0.0-3.1.13.1.el6_5
fixed
java-1.7.0-ibm
RHEL 6
1:1.7.0.6.1-1jpp.1.el6_5
fixed
java-1.7.0-ibm-demo
RHEL 6
1:1.7.0.6.1-1jpp.1.el6_5
fixed
java-1.7.0-ibm-devel
RHEL 6
1:1.7.0.6.1-1jpp.1.el6_5
fixed
java-1.7.0-ibm-jdbc
RHEL 6
1:1.7.0.6.1-1jpp.1.el6_5
fixed
java-1.7.0-ibm-plugin
RHEL 6
1:1.7.0.6.1-1jpp.1.el6_5
fixed
java-1.7.0-ibm-src
RHEL 6
1:1.7.0.6.1-1jpp.1.el6_5
fixed
java-1.7.0-openjdk
RHEL 6
1:1.7.0.51-2.4.4.1.el6_5
fixed
java-1.7.0-openjdk-demo
RHEL 6
1:1.7.0.51-2.4.4.1.el6_5
fixed
java-1.7.0-openjdk-devel
RHEL 6
1:1.7.0.51-2.4.4.1.el6_5
fixed
java-1.7.0-openjdk-javadoc
RHEL 6
1:1.7.0.51-2.4.4.1.el6_5
fixed
java-1.7.0-openjdk-src
RHEL 6
1:1.7.0.51-2.4.4.1.el6_5
fixed
java-1.7.0-oracle
RHEL 6
1:1.7.0.51-1jpp.1.el6_5
fixed
java-1.7.0-oracle-devel
RHEL 6
1:1.7.0.51-1jpp.1.el6_5
fixed
java-1.7.0-oracle-javafx
RHEL 6
1:1.7.0.51-1jpp.1.el6_5
fixed
java-1.7.0-oracle-jdbc
RHEL 6
1:1.7.0.51-1jpp.1.el6_5
fixed
java-1.7.0-oracle-plugin
RHEL 6
1:1.7.0.51-1jpp.1.el6_5
fixed
java-1.7.0-oracle-src
RHEL 6
1:1.7.0.51-1jpp.1.el6_5
fixed
java-1.7.1-ibm
RHEL 7
1:1.7.1.1.0-1jpp.2.el7_0
fixed
java-1.7.1-ibm-demo
RHEL 7
1:1.7.1.1.0-1jpp.2.el7_0
fixed
java-1.7.1-ibm-devel
RHEL 7
1:1.7.1.1.0-1jpp.2.el7_0
fixed
java-1.7.1-ibm-jdbc
RHEL 7
1:1.7.1.1.0-1jpp.2.el7_0
fixed
java-1.7.1-ibm-plugin
RHEL 7
1:1.7.1.1.0-1jpp.2.el7_0
fixed
java-1.7.1-ibm-src
RHEL 7
1:1.7.1.1.0-1jpp.2.el7_0
fixed
References