U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

CVE-2014-4263 Detail

Description

Unspecified vulnerability in Oracle Java SE 5.0u65, 6u75, 7u60, and 8u5, and JRockit R27.8.2 and R28.3.2, allows remote attackers to affect confidentiality and integrity via unknown vectors related to "Diffie-Hellman key agreement."


Evaluator Description

Per: http://www.oracle.com/technetwork/topics/security/cpujul2014-1972956.html "Applies to Diffie-Hellman key agreement in client and server deployment of Java."

Metrics

NVD enrichment efforts reference publicly available information to associate vector strings. CVSS information contributed by other sources is also displayed.
CVSS 4.0 Severity and Vector Strings:

NIST CVSS score
NIST: NVD
N/A
NVD assessment not yet provided.

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving NIST webspace. We have provided these links to other web sites because they may have information that would be of interest to you. No inferences should be drawn on account of other sites being referenced, or not, from this page. There may be other web sites that are more appropriate for your purpose. NIST does not necessarily endorse the views expressed, or concur with the facts presented on these sites. Further, NIST does not endorse any commercial products that may be mentioned on these sites. Please address comments about this page to [email protected].

URL Source(s) Tag(s)
http://lists.opensuse.org/opensuse-security-announce/2015-02/msg00026.html CVE, Oracle
http://lists.opensuse.org/opensuse-security-announce/2015-02/msg00033.html CVE, Oracle
http://lists.opensuse.org/opensuse-security-announce/2015-02/msg00036.html CVE, Oracle
http://marc.info/?l=bugtraq&m=140852886808946&w=2 CVE, Oracle
http://marc.info/?l=bugtraq&m=140852974709252&w=2 CVE, Oracle
http://rhn.redhat.com/errata/RHSA-2015-0264.html CVE, Oracle
http://seclists.org/fulldisclosure/2014/Dec/23 CVE, Oracle
http://secunia.com/advisories/58830 CVE, Oracle
http://secunia.com/advisories/59404 CVE, Oracle
http://secunia.com/advisories/59503 CVE, Oracle
http://secunia.com/advisories/59680 CVE, Oracle
http://secunia.com/advisories/59924 CVE, Oracle
http://secunia.com/advisories/59985 CVE, Oracle
http://secunia.com/advisories/59986 CVE, Oracle
http://secunia.com/advisories/59987 CVE, Oracle
http://secunia.com/advisories/60002 CVE, Oracle
http://secunia.com/advisories/60031 CVE, Oracle
http://secunia.com/advisories/60032 CVE, Oracle
http://secunia.com/advisories/60081 CVE, Oracle
http://secunia.com/advisories/60129 CVE, Oracle
http://secunia.com/advisories/60180 CVE, Oracle
http://secunia.com/advisories/60245 CVE, Oracle
http://secunia.com/advisories/60317 CVE, Oracle
http://secunia.com/advisories/60326 CVE, Oracle
http://secunia.com/advisories/60335 CVE, Oracle
http://secunia.com/advisories/60485 CVE, Oracle
http://secunia.com/advisories/60497 CVE, Oracle
http://secunia.com/advisories/60622 CVE, Oracle
http://secunia.com/advisories/60812 CVE, Oracle
http://secunia.com/advisories/60817 CVE, Oracle
http://secunia.com/advisories/60831 CVE, Oracle
http://secunia.com/advisories/60839 CVE, Oracle
http://secunia.com/advisories/60846 CVE, Oracle
http://secunia.com/advisories/60890 CVE, Oracle
http://secunia.com/advisories/61215 CVE, Oracle
http://secunia.com/advisories/61254 CVE, Oracle
http://secunia.com/advisories/61264 CVE, Oracle
http://secunia.com/advisories/61278 CVE, Oracle
http://secunia.com/advisories/61293 CVE, Oracle
http://secunia.com/advisories/61294 CVE, Oracle
http://secunia.com/advisories/61469 CVE, Oracle
http://secunia.com/advisories/61577 CVE, Oracle
http://secunia.com/advisories/61640 CVE, Oracle
http://secunia.com/advisories/61846 CVE, Oracle
http://secunia.com/advisories/62314 CVE, Oracle
http://secunia.com/advisories/62319 CVE, Oracle
http://security.gentoo.org/glsa/glsa-201502-12.xml CVE, Oracle
http://www-01.ibm.com/support/docview.wss?uid=swg21680334 CVE, Oracle
http://www-01.ibm.com/support/docview.wss?uid=swg21681379 CVE, Oracle
http://www-01.ibm.com/support/docview.wss?uid=swg21681966 CVE, Oracle
http://www-01.ibm.com/support/docview.wss?uid=swg21683338 CVE, Oracle
http://www-01.ibm.com/support/docview.wss?uid=swg21683429 CVE, Oracle
http://www-01.ibm.com/support/docview.wss?uid=swg21683438 CVE, Oracle
http://www-01.ibm.com/support/docview.wss?uid=swg21683484 CVE, Oracle
http://www-01.ibm.com/support/docview.wss?uid=swg21685121 CVE, Oracle
http://www-01.ibm.com/support/docview.wss?uid=swg21685122 CVE, Oracle
http://www-01.ibm.com/support/docview.wss?uid=swg21685178 CVE, Oracle
http://www-01.ibm.com/support/docview.wss?uid=swg21685242 CVE, Oracle
http://www-01.ibm.com/support/docview.wss?uid=swg21686142 CVE, Oracle
http://www-01.ibm.com/support/docview.wss?uid=swg21686383 CVE, Oracle
http://www-01.ibm.com/support/docview.wss?uid=swg21686824 CVE, Oracle
http://www-01.ibm.com/support/docview.wss?uid=swg21688893 CVE, Oracle
http://www-01.ibm.com/support/docview.wss?uid=swg21689593 CVE, Oracle
http://www-01.ibm.com/support/docview.wss?uid=swg21691089 CVE, Oracle
http://www-947.ibm.com/support/entry/portal/docdisplay?lndocid=MIGR-5096529 CVE, Oracle
http://www.debian.org/security/2014/dsa-2980 CVE, Oracle
http://www.debian.org/security/2014/dsa-2987 CVE, Oracle
http://www.ibm.com/support/docview.wss?uid=swg21681644 CVE, Oracle
http://www.ibm.com/support/docview.wss?uid=swg21683518 CVE, Oracle
http://www.oracle.com/technetwork/topics/security/cpujul2014-1972956.html CVE, Oracle Vendor Advisory 
http://www.securityfocus.com/archive/1/534161/100/0/threaded CVE, Oracle
http://www.securityfocus.com/bid/68636 CVE, Oracle
http://www.securitytracker.com/id/1030577 CVE, Oracle
http://www.vmware.com/security/advisories/VMSA-2014-0012.html CVE, Oracle
https://access.redhat.com/errata/RHSA-2014:0902 CVE, Oracle
https://access.redhat.com/errata/RHSA-2014:0908 CVE, Oracle
https://exchange.xforce.ibmcloud.com/vulnerabilities/94606 CVE, Oracle
https://kc.mcafee.com/corporate/index?page=content&id=SB10083 CVE, Oracle
https://www.ibm.com/support/docview.wss?uid=swg21680418 CVE, Oracle

Weakness Enumeration

CWE-ID CWE Name Source
NVD-CWE-noinfo Insufficient Information cwe source acceptance level NIST  

Known Affected Software Configurations Switch to CPE 2.2

CPEs loading, please wait.

Denotes Vulnerable Software
Are we missing a CPE here? Please let us know.

Change History

23 change records found show changes

Quick Info

CVE Dictionary Entry:
CVE-2014-4263
NVD Published Date:
07/17/2014
NVD Last Modified:
04/12/2025
Source:
Oracle