National Vulnerability Database

National Vulnerability Database

National Vulnerability

CVE-2014-0368 Detail


Unspecified vulnerability in Oracle Java SE 5.0u55, 6u65, and 7u45, and Java SE Embedded 7u45, allows remote attackers to affect confidentiality via unknown vectors related to Networking. NOTE: the previous information is from the January 2014 CPU. Oracle has not commented on third-party claims that the issue is related to incorrect permission checks when listening on a socket, which allows attackers to escape the sandbox.

Source:  MITRE      Last Modified:  01/15/2014

Evaluator Description

Per: "Applies to client deployment of Java only. This vulnerability can be exploited only through sandboxed Java Web Start applications and sandboxed Java applets."

Quick Info

CVE Dictionary Entry:
Original release date:
Last revised:


CVSS Severity (version 2.0):
CVSS v2 Base Score:
(AV:N/AC:L/Au:N/C:P/I:N/A:N) (legend)
Impact Subscore:
Exploitability Subscore:
CVSS Version 2 Metrics:
Access Vector:
Network exploitable
Access Complexity:
Not required to exploit
Impact Type:
Allows unauthorized disclosure of information

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving NIST webspace. We have provided these links to other web sites because they may have information that would be of interest to you. No inferences should be drawn on account of other sites being referenced, or not, from this page. There may be other web sites that are more appropriate for your purpose. NIST does not necessarily endorse the views expressed, or concur with the facts presented on these sites. Further, NIST does not endorse any commercial products that may be mentioned on these sites. Please address comments about this page to

Hyperlink Resource Type Source Name External Source MISC External Source SUSE SUSE-SU-2014:0246 External Source SUSE SUSE-SU-2014:0266 External Source SUSE SUSE-SU-2014:0451 External Source SUSE openSUSE-SU-2014:0174 External Source SUSE openSUSE-SU-2014:0177 External Source SUSE openSUSE-SU-2014:0180 External Source HP SSRT101454 External Source HP HPSBUX02973 External Source REDHAT RHSA-2014:0026 External Source REDHAT RHSA-2014:0027 External Source REDHAT RHSA-2014:0030 External Source REDHAT RHSA-2014:0097 External Source REDHAT RHSA-2014:0134 External Source REDHAT RHSA-2014:0135 External Source REDHAT RHSA-2014:0136 External Source SECUNIA 59235 External Source SECUNIA 59339 Vendor Advisory External Source CONFIRM External Source BID 64758 External Source BID 64930 External Source SECTRACK 1029608 External Source UBUNTU USN-2089-1 External Source UBUNTU USN-2124-1 External Source CONFIRM External Source REDHAT RHSA-2014:0414 External Source CONFIRM External Source CONFIRM

Technical Details

Vulnerability Type (View All)

Change History 4 change records found - show changes