Common Vulnerabilities and Exposures
- September 2026 CVEs
- August 2026 CVEs
- July 2026 CVEs
- April 2026 CVEs
- January 2026 CVEs
- October 2025 CVEs
- July 2025 CVEs
- April 2025 CVEs
- January 2025 CVEs
- October 2024 CVEs
- July 2024 CVEs
- April 2024 CVEs
- January 2024 CVEs
- October 2023 CVEs
- July 2023 CVEs
- April 2023 CVEs
- January 2023 CVEs
- October 2022 CVEs
- July 2022 CVEs
- April 2022 CVEs
- January 2022 CVEs
- October 2021 CVEs
- July 2021 CVEs
- April 2021 CVEs
- January 2021 CVEs
- October 2020 CVEs
- July 2020 CVEs
- April 2020 CVEs
- January 2020 CVEs
- October 2019 CVEs
- July 2019 CVEs
- April 2019 CVEs
- January 2019 CVEs
- October 2018 CVEs
- July 2018 CVEs
- April 2018 CVEs
- January 2018 CVEs
- October 2017 CVEs
- July 2017 CVEs
- April 2017 CVEs
- January 2017 CVEs
- October 2016 CVEs
- July 2016 CVEs
- April 2016 CVEs
- January 2016 CVEs
This page provides a list of common vulnerabilities and exposures (CVE) fixed in Azul Zulu Builds of OpenJDK since July 2014. The CVEs fixed in earlier releases are not included in the list.
CVEs are addressed in quarterly CPU (Critical Patch Update) releases and in in-between CSPU (Critical Security Patch Update) releases. The list of CVEs fixed in a specific Azul Zulu release matches up with the CVEs fixed in the corresponding release of OpenJDK. You can filter the list by CVE ID, Azul Zulu version, and/or JDK version. A CVE can carry a note that says how the vulnerability applies. Such a CVE has a marker next to its ID; move the pointer over the marker to read the note.
The data used on this page, is also available in JSON format.
No CVEs match the selected filters.
September 2026 CVEs
| September 2026 | Back to Top | ||
|---|---|---|---|
| The September 2026 Critical Security Patch Update (CSPU) for Azul Zulu Builds of OpenJDK, released September 15, 2026, is a limited, Azul-specific release that applies only to Azul Zulu FIPS bundles. It does not apply to any other Zulu packages or to any non-Zulu packages. | |||
| Azul Zulu Build of OpenJDK | |||
| CVE | Base Score | CPU | PSU |
| CVE-2026-8763 Note 1: Affects only FIPS-enabled Azul Zulu SA bundles (for example, Zulu Gov). Non-FIPS bundles are not affected. | 7.1 | ||
| 8.95.0.302 8u503-b01 | 8.96.0.302 8u504-b01 | ||
| 11.89.302 11.0.31.0.201+1 | 11.90.302 11.0.32.1+1 | ||
| 17.67.302 17.0.19.0.201+1 | 17.68.302 17.0.20.1+1 | ||
| 21.51.302 21.0.11.0.201+1 | 21.52.302 21.0.12.1+1 | ||
| 25.35.302 25.0.3.0.201+1 | 25.36.302 25.0.4.1.1+1 | ||
| CVE-2026-8798 Note 1: Affects only FIPS-enabled Azul Zulu SA bundles (for example, Zulu Gov). Non-FIPS bundles are not affected. | 5.9 | ||
| 8.95.0.302 8u503-b01 | 8.96.0.302 8u504-b01 | ||
| 11.89.302 11.0.31.0.201+1 | 11.90.302 11.0.32.1+1 | ||
| 17.67.302 17.0.19.0.201+1 | 17.68.302 17.0.20.1+1 | ||
| 21.51.302 21.0.11.0.201+1 | 21.52.302 21.0.12.1+1 | ||
| 25.35.302 25.0.3.0.201+1 | 25.36.302 25.0.4.1.1+1 | ||
| CVE-2026-13505 Note 1: Affects only FIPS-enabled Azul Zulu SA bundles (for example, Zulu Gov). Non-FIPS bundles are not affected. | 5.9 | ||
| 8.95.0.302 8u503-b01 | 8.96.0.302 8u504-b01 | ||
| 11.89.302 11.0.31.0.201+1 | 11.90.302 11.0.32.1+1 | ||
| 17.67.302 17.0.19.0.201+1 | 17.68.302 17.0.20.1+1 | ||
| 21.51.302 21.0.11.0.201+1 | 21.52.302 21.0.12.1+1 | ||
| 25.35.302 25.0.3.0.201+1 | 25.36.302 25.0.4.1.1+1 | ||
| CVE-2026-13506 Note 1: Affects only FIPS-enabled Azul Zulu SA bundles (for example, Zulu Gov). Non-FIPS bundles are not affected. | 5.9 | ||
| 8.95.0.302 8u503-b01 | 8.96.0.302 8u504-b01 | ||
| 11.89.302 11.0.31.0.201+1 | 11.90.302 11.0.32.1+1 | ||
| 17.67.302 17.0.19.0.201+1 | 17.68.302 17.0.20.1+1 | ||
| 21.51.302 21.0.11.0.201+1 | 21.52.302 21.0.12.1+1 | ||
| 25.35.302 25.0.3.0.201+1 | 25.36.302 25.0.4.1.1+1 | ||
| CVE-2026-13586 Note 1: Affects only FIPS-enabled Azul Zulu SA bundles (for example, Zulu Gov). Non-FIPS bundles are not affected. | 5.9 | ||
| 8.95.0.302 8u503-b01 | 8.96.0.302 8u504-b01 | ||
| 11.89.302 11.0.31.0.201+1 | 11.90.302 11.0.32.1+1 | ||
| 17.67.302 17.0.19.0.201+1 | 17.68.302 17.0.20.1+1 | ||
| 21.51.302 21.0.11.0.201+1 | 21.52.302 21.0.12.1+1 | ||
| 25.35.302 25.0.3.0.201+1 | 25.36.302 25.0.4.1.1+1 | ||
| CVE-2026-14682 Note 1: Affects only FIPS-enabled Azul Zulu SA bundles (for example, Zulu Gov). Non-FIPS bundles are not affected. | 5.9 | ||
| 8.95.0.302 8u503-b01 | 8.96.0.302 8u504-b01 | ||
| 11.89.302 11.0.31.0.201+1 | 11.90.302 11.0.32.1+1 | ||
| 17.67.302 17.0.19.0.201+1 | 17.68.302 17.0.20.1+1 | ||
| 21.51.302 21.0.11.0.201+1 | 21.52.302 21.0.12.1+1 | ||
| 25.35.302 25.0.3.0.201+1 | 25.36.302 25.0.4.1.1+1 | ||
| CVE-2026-58059 Note 1: Affects only FIPS-enabled Azul Zulu SA bundles (for example, Zulu Gov). Non-FIPS bundles are not affected. | 5.9 | ||
| 8.95.0.302 8u503-b01 | 8.96.0.302 8u504-b01 | ||
| 11.89.302 11.0.31.0.201+1 | 11.90.302 11.0.32.1+1 | ||
| 17.67.302 17.0.19.0.201+1 | 17.68.302 17.0.20.1+1 | ||
| 21.51.302 21.0.11.0.201+1 | 21.52.302 21.0.12.1+1 | ||
| 25.35.302 25.0.3.0.201+1 | 25.36.302 25.0.4.1.1+1 | ||
| CVE-2026-58060 Note 1: Affects only FIPS-enabled Azul Zulu SA bundles (for example, Zulu Gov). Non-FIPS bundles are not affected. | 5.9 | ||
| 8.95.0.302 8u503-b01 | 8.96.0.302 8u504-b01 | ||
| 11.89.302 11.0.31.0.201+1 | 11.90.302 11.0.32.1+1 | ||
| 17.67.302 17.0.19.0.201+1 | 17.68.302 17.0.20.1+1 | ||
| 21.51.302 21.0.11.0.201+1 | 21.52.302 21.0.12.1+1 | ||
| 25.35.302 25.0.3.0.201+1 | 25.36.302 25.0.4.1.1+1 | ||
| CVE-2026-58061 Note 1: Affects only FIPS-enabled Azul Zulu SA bundles (for example, Zulu Gov). Non-FIPS bundles are not affected. | 5.9 | ||
| 8.95.0.302 8u503-b01 | 8.96.0.302 8u504-b01 | ||
| 11.89.302 11.0.31.0.201+1 | 11.90.302 11.0.32.1+1 | ||
| 17.67.302 17.0.19.0.201+1 | 17.68.302 17.0.20.1+1 | ||
| 21.51.302 21.0.11.0.201+1 | 21.52.302 21.0.12.1+1 | ||
| 25.35.302 25.0.3.0.201+1 | 25.36.302 25.0.4.1.1+1 | ||
| CVE-2026-58062 Note 1: Affects only FIPS-enabled Azul Zulu SA bundles (for example, Zulu Gov). Non-FIPS bundles are not affected. | 7.1 | ||
| 8.95.0.302 8u503-b01 | 8.96.0.302 8u504-b01 | ||
| 11.89.302 11.0.31.0.201+1 | 11.90.302 11.0.32.1+1 | ||
| 17.67.302 17.0.19.0.201+1 | 17.68.302 17.0.20.1+1 | ||
| 21.51.302 21.0.11.0.201+1 | 21.52.302 21.0.12.1+1 | ||
| 25.35.302 25.0.3.0.201+1 | 25.36.302 25.0.4.1.1+1 | ||
| CVE-2026-58063 Note 1: Affects only FIPS-enabled Azul Zulu SA bundles (for example, Zulu Gov). Non-FIPS bundles are not affected. | 3.7 | ||
| 8.95.0.302 8u503-b01 | 8.96.0.302 8u504-b01 | ||
| 11.89.302 11.0.31.0.201+1 | 11.90.302 11.0.32.1+1 | ||
| 17.67.302 17.0.19.0.201+1 | 17.68.302 17.0.20.1+1 | ||
| 21.51.302 21.0.11.0.201+1 | 21.52.302 21.0.12.1+1 | ||
| 25.35.302 25.0.3.0.201+1 | 25.36.302 25.0.4.1.1+1 | ||
August 2026 CVEs
| August 2026 | Back to Top | ||
|---|---|---|---|
| The August 2026 release is the first monthly update release delivering Java Critical Security Patch Updates (CSPU). | |||
| Azul Zulu Build of OpenJDK | |||
| CVE | Base Score | CSPU for CPU | CSPU for PSU |
| CVE-2026-60589 Note 2: This vulnerability can only be exploited by supplying data to APIs in the specified Component such as through a web service. | 3.7 | ||
| 6.81.0.204 6b183 | — | ||
| 7.87.0.204 7u513-b01 | — | ||
| 8.95.0.204 8u503-b01 | 8.96.0.205 8u504-b01 | ||
| 11.89.204 11.0.31.0.201+1 | 11.90.205 11.0.32.1+1 | ||
| 17.67.204 17.0.19.0.201+1 | 17.68.203 17.0.20.1+1 | ||
| 21.51.204 21.0.11.0.201+1 | 21.52.203 21.0.12.1+1 | ||
| 25.35.204 25.0.3.0.201+1 | 25.36.205 25.0.4.1+1 | ||
| — | 26.32.203 26.0.2.1+1 | ||
| CVE-2026-61308 Note 1: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. | 6.8 | ||
| 6.81.0.204 6b183 | — | ||
| 7.87.0.204 7u513-b01 | — | ||
| 8.95.0.204 8u503-b01 | 8.96.0.205 8u504-b01 | ||
| 11.89.204 11.0.31.0.201+1 | 11.90.205 11.0.32.1+1 | ||
| 17.67.204 17.0.19.0.201+1 | 17.68.203 17.0.20.1+1 | ||
| 21.51.204 21.0.11.0.201+1 | 21.52.203 21.0.12.1+1 | ||
| 25.35.204 25.0.3.0.201+1 | 25.36.205 25.0.4.1+1 | ||
| — | 26.32.203 26.0.2.1+1 | ||
| CVE-2026-70907 Note 2: This vulnerability can only be exploited by supplying data to APIs in the specified Component such as through a web service. | 5.3 | ||
| 8.95.0.204 8u503-b01 | 8.96.0.205 8u504-b01 | ||
| 11.89.204 11.0.31.0.201+1 | 11.90.205 11.0.32.1+1 | ||
| 17.67.204 17.0.19.0.201+1 | 17.68.203 17.0.20.1+1 | ||
| 21.51.204 21.0.11.0.201+1 | 21.52.203 21.0.12.1+1 | ||
| 25.35.204 25.0.3.0.201+1 | 25.36.205 25.0.4.1+1 | ||
| — | 26.32.203 26.0.2.1+1 | ||
| CVE-2026-70906 Note 1: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. | 7.5 | ||
| 25.35.204 25.0.3.0.201+1 | 25.36.205 25.0.4.1+1 | ||
| — | 26.32.203 26.0.2.1+1 | ||
| CVE-2026-62574 This CVE is not applicable to Azul Core. It is listed here for comparison with other Java implementations which may contain this CVE. Note 1: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. | 7.8 | — | |
July 2026 CVEs
| July 2026 | Back to Top | ||
|---|---|---|---|
| July 2026 Quarterly Update Release | |||
| Azul Zulu Build of OpenJDK | |||
| CVE | Base Score | CPU | PSU |
| CVE-2026-41254 Note 1: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. | 7.5 | ||
| 6.81.0.14 6b181 | — | ||
| 7.87.0.14 7u511-b01 | — | ||
| 8.95.0.14 8u501-b01 | 8.96.0.19 8u502-b07 | ||
| 11.89.14 11.0.31.0.101+1 | 11.90.19 11.0.32+9 | ||
| 17.67.14 17.0.19.0.101+1 | 17.68.17 17.0.20+8 | ||
| 21.51.14 21.0.11.0.101+1 | 21.52.15 21.0.12+8 | ||
| 25.35.12 25.0.3.0.101+1 | 25.36.15 25.0.4+7 | ||
| — | 26.32.13 26.0.2+10 | ||
| CVE-2026-47010 Note 1: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. | 3.7 | ||
| 6.81.0.14 6b181 | — | ||
| 7.87.0.14 7u511-b01 | — | ||
| 8.95.0.14 8u501-b01 | 8.96.0.19 8u502-b07 | ||
| 11.89.14 11.0.31.0.101+1 | 11.90.19 11.0.32+9 | ||
| 17.67.14 17.0.19.0.101+1 | 17.68.17 17.0.20+8 | ||
| 21.51.14 21.0.11.0.101+1 | 21.52.15 21.0.12+8 | ||
| 25.35.12 25.0.3.0.101+1 | 25.36.15 25.0.4+7 | ||
| — | 26.32.13 26.0.2+10 | ||
| CVE-2026-47027 Note 1: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. | 5.3 | ||
| 6.81.0.14 6b181 | — | ||
| 7.87.0.14 7u511-b01 | — | ||
| 8.95.0.14 8u501-b01 | 8.96.0.19 8u502-b07 | ||
| 11.89.14 11.0.31.0.101+1 | 11.90.19 11.0.32+9 | ||
| 17.67.14 17.0.19.0.101+1 | 17.68.17 17.0.20+8 | ||
| 21.51.14 21.0.11.0.101+1 | 21.52.15 21.0.12+8 | ||
| 25.35.12 25.0.3.0.101+1 | 25.36.15 25.0.4+7 | ||
| — | 26.32.13 26.0.2+10 | ||
| CVE-2026-47059 Note 3: This vulnerability applies to Java deployments that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). | 3.7 | ||
| 6.81.0.14 6b181 | — | ||
| 7.87.0.14 7u511-b01 | — | ||
| 8.95.0.14 8u501-b01 | 8.96.0.19 8u502-b07 | ||
| 11.89.14 11.0.31.0.101+1 | 11.90.19 11.0.32+9 | ||
| 17.67.14 17.0.19.0.101+1 | 17.68.17 17.0.20+8 | ||
| 21.51.14 21.0.11.0.101+1 | 21.52.15 21.0.12+8 | ||
| 25.35.12 25.0.3.0.101+1 | 25.36.15 25.0.4+7 | ||
| — | 26.32.13 26.0.2+10 | ||
| CVE-2026-47063 Note 1: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. | 7.5 | ||
| 6.81.0.14 6b181 | — | ||
| 7.87.0.14 7u511-b01 | — | ||
| 8.95.0.14 8u501-b01 | 8.96.0.19 8u502-b07 | ||
| 11.89.14 11.0.31.0.101+1 | 11.90.19 11.0.32+9 | ||
| 17.67.14 17.0.19.0.101+1 | 17.68.17 17.0.20+8 | ||
| 21.51.14 21.0.11.0.101+1 | 21.52.15 21.0.12+8 | ||
| 25.35.12 25.0.3.0.101+1 | 25.36.15 25.0.4+7 | ||
| — | 26.32.13 26.0.2+10 | ||
| CVE-2026-60147 Note 1: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. | 6.5 | ||
| 6.81.0.14 6b181 | — | ||
| 7.87.0.14 7u511-b01 | — | ||
| 8.95.0.14 8u501-b01 | 8.96.0.19 8u502-b07 | ||
| 11.89.14 11.0.31.0.101+1 | 11.90.19 11.0.32+9 | ||
| 17.67.14 17.0.19.0.101+1 | 17.68.17 17.0.20+8 | ||
| 21.51.14 21.0.11.0.101+1 | 21.52.15 21.0.12+8 | ||
| 25.35.12 25.0.3.0.101+1 | 25.36.15 25.0.4+7 | ||
| — | 26.32.13 26.0.2+10 | ||
| CVE-2026-46968 Note 2: This vulnerability can only be exploited by supplying data to APIs in the specified Component without using Untrusted Java code, such as through a web service. | 5.9 | ||
| 8.95.0.14 8u501-b01 | 8.96.0.19 8u502-b07 | ||
| 11.89.14 11.0.31.0.101+1 | 11.90.19 11.0.32+9 | ||
| 17.67.14 17.0.19.0.101+1 | 17.68.17 17.0.20+8 | ||
| 21.51.14 21.0.11.0.101+1 | 21.52.15 21.0.12+8 | ||
| 25.35.12 25.0.3.0.101+1 | 25.36.15 25.0.4+7 | ||
| — | 26.32.13 26.0.2+10 | ||
| CVE-2026-47013 Note 1: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. | 5.3 | ||
| 8.95.0.14 8u501-b01 | 8.96.0.19 8u502-b07 | ||
| 11.89.14 11.0.31.0.101+1 | 11.90.19 11.0.32+9 | ||
| 17.67.14 17.0.19.0.101+1 | 17.68.17 17.0.20+8 | ||
| 21.51.14 21.0.11.0.101+1 | 21.52.15 21.0.12+8 | ||
| 25.35.12 25.0.3.0.101+1 | 25.36.15 25.0.4+7 | ||
| — | 26.32.13 26.0.2+10 | ||
| CVE-2026-47021 Note 1: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. | 5.3 | ||
| 8.95.0.14 8u501-b01 | 8.96.0.19 8u502-b07 | ||
| 11.89.14 11.0.31.0.101+1 | 11.90.19 11.0.32+9 | ||
| 17.67.14 17.0.19.0.101+1 | 17.68.17 17.0.20+8 | ||
| 21.51.14 21.0.11.0.101+1 | 21.52.15 21.0.12+8 | ||
| 25.35.12 25.0.3.0.101+1 | 25.36.15 25.0.4+7 | ||
| — | 26.32.13 26.0.2+10 | ||
| CVE-2026-47030 Note 3: This vulnerability applies to Java deployments that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). | 3.1 | ||
| 8.95.0.14 8u501-b01 | 8.96.0.19 8u502-b07 | ||
| 11.89.14 11.0.31.0.101+1 | 11.90.19 11.0.32+9 | ||
| 17.67.14 17.0.19.0.101+1 | 17.68.17 17.0.20+8 | ||
| 21.51.14 21.0.11.0.101+1 | 21.52.15 21.0.12+8 | ||
| 25.35.12 25.0.3.0.101+1 | 25.36.15 25.0.4+7 | ||
| — | 26.32.13 26.0.2+10 | ||
| CVE-2026-47034 Note 3: This vulnerability applies to Java deployments that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). | 3.1 | ||
| 8.95.0.14 8u501-b01 | 8.96.0.19 8u502-b07 | ||
| 11.89.14 11.0.31.0.101+1 | 11.90.19 11.0.32+9 | ||
| 17.67.14 17.0.19.0.101+1 | 17.68.17 17.0.20+8 | ||
| 21.51.14 21.0.11.0.101+1 | 21.52.15 21.0.12+8 | ||
| 25.35.12 25.0.3.0.101+1 | 25.36.15 25.0.4+7 | ||
| — | 26.32.13 26.0.2+10 | ||
| CVE-2026-47035 Note 3: This vulnerability applies to Java deployments that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). | 3.1 | ||
| 8.95.0.14 8u501-b01 | 8.96.0.19 8u502-b07 | ||
| 11.89.14 11.0.31.0.101+1 | 11.90.19 11.0.32+9 | ||
| 17.67.14 17.0.19.0.101+1 | 17.68.17 17.0.20+8 | ||
| 21.51.14 21.0.11.0.101+1 | 21.52.15 21.0.12+8 | ||
| 25.35.12 25.0.3.0.101+1 | 25.36.15 25.0.4+7 | ||
| — | 26.32.13 26.0.2+10 | ||
| CVE-2026-60164 Note 3: This vulnerability applies to Java deployments that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). | 3.1 | ||
| 8.95.0.14 8u501-b01 | 8.96.0.19 8u502-b07 | ||
| 11.89.14 11.0.31.0.101+1 | 11.90.19 11.0.32+9 | ||
| 17.67.14 17.0.19.0.101+1 | 17.68.17 17.0.20+8 | ||
| 21.51.14 21.0.11.0.101+1 | 21.52.15 21.0.12+8 | ||
| 25.35.12 25.0.3.0.101+1 | 25.36.15 25.0.4+7 | ||
| — | 26.32.13 26.0.2+10 | ||
| CVE-2026-60166 Note 3: This vulnerability applies to Java deployments that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). | 3.1 | ||
| 8.95.0.14 8u501-b01 | 8.96.0.19 8u502-b07 | ||
| 11.89.14 11.0.31.0.101+1 | 11.90.19 11.0.32+9 | ||
| 17.67.14 17.0.19.0.101+1 | 17.68.17 17.0.20+8 | ||
| 21.51.14 21.0.11.0.101+1 | 21.52.15 21.0.12+8 | ||
| 25.35.12 25.0.3.0.101+1 | 25.36.15 25.0.4+7 | ||
| — | 26.32.13 26.0.2+10 | ||
| CVE-2026-46917 Note 2: This vulnerability can only be exploited by supplying data to APIs in the specified Component without using Untrusted Java code, such as through a web service. | 5.3 | ||
| 11.89.14 11.0.31.0.101+1 | 11.90.19 11.0.32+9 | ||
| 17.67.14 17.0.19.0.101+1 | 17.68.17 17.0.20+8 | ||
| 21.51.14 21.0.11.0.101+1 | 21.52.15 21.0.12+8 | ||
| 25.35.12 25.0.3.0.101+1 | 25.36.15 25.0.4+7 | ||
| — | 26.32.13 26.0.2+10 | ||
| CVE-2026-60165 Note 3: This vulnerability applies to Java deployments that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). | 3.1 | ||
| 11.89.14 11.0.31.0.101+1 | 11.90.19 11.0.32+9 | ||
| 17.67.14 17.0.19.0.101+1 | 17.68.17 17.0.20+8 | ||
| 21.51.14 21.0.11.0.101+1 | 21.52.15 21.0.12+8 | ||
| 25.35.12 25.0.3.0.101+1 | 25.36.15 25.0.4+7 | ||
| — | 26.32.13 26.0.2+10 | ||
| CVE-2026-47057 Note 1: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. | 7.5 | ||
| 8.95.0.14 8u501-b01 | 8.96.0.19 8u502-b07 | ||
| 11.89.14 11.0.31.0.101+1 | 11.90.19 11.0.32+9 | ||
| CVE-2026-47058 Note 1: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. | 7.4 | ||
| 8.95.0.14 8u501-b01 | 8.96.0.19 8u502-b07 | ||
| 11.89.14 11.0.31.0.101+1 | 11.90.19 11.0.32+9 | ||
| CVE-2026-60526 This CVE is not applicable to Azul Core. It is listed here for comparison with other Java implementations which may contain this CVE. Note 1: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. | 6.7 | — | |
| CVE-2026-62574 This CVE is not applicable to Azul Core. It is listed here for comparison with other Java implementations which may contain this CVE. | 7.8 | — | |
April 2026 CVEs
| April 2026 | Back to Top | ||
|---|---|---|---|
| April 2026 Quarterly Update Release | |||
| Azul Zulu Build of OpenJDK | |||
| CVE | Base Score | CPU | PSU |
| CVE-2026-22007 Note 2: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. | 2.9 | ||
| 6.79.0.14 6b179 | — | ||
| 7.85.0.12 7u501-b01 | — | ||
| 8.93.0.18 8u491-b01 | 8.94.0.17 8u492-b09 | ||
| 11.87.18 11.0.30.0.101+1 | 11.88.17 11.0.31+11 | ||
| 17.65.18 17.0.18.0.101+1 | 17.66.19 17.0.19+10 | ||
| 21.49.18 21.0.10.0.101+1 | 21.50.19 21.0.11+10 | ||
| 25.33.16 25.0.2.0.101+1 | 25.34.17 25.0.3+9 | ||
| — | 26.30.11 26.0.1+8 | ||
| CVE-2026-22013 Note 1: This vulnerability applies to Java deployments, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). | 5.3 | ||
| 6.79.0.14 6b179 | — | ||
| 7.85.0.12 7u501-b01 | — | ||
| 8.93.0.18 8u491-b01 | 8.94.0.17 8u492-b09 | ||
| 11.87.18 11.0.30.0.101+1 | 11.88.17 11.0.31+11 | ||
| 17.65.18 17.0.18.0.101+1 | 17.66.19 17.0.19+10 | ||
| 21.49.18 21.0.10.0.101+1 | 21.50.19 21.0.11+10 | ||
| 25.33.16 25.0.2.0.101+1 | 25.34.17 25.0.3+9 | ||
| — | 26.30.11 26.0.1+8 | ||
| CVE-2026-22016 Note 2: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. | 7.5 | ||
| 6.79.0.14 6b179 | — | ||
| 7.85.0.12 7u501-b01 | — | ||
| 8.93.0.18 8u491-b01 | 8.94.0.17 8u492-b09 | ||
| 11.87.18 11.0.30.0.101+1 | 11.88.17 11.0.31+11 | ||
| 17.65.18 17.0.18.0.101+1 | 17.66.19 17.0.19+10 | ||
| 21.49.18 21.0.10.0.101+1 | 21.50.19 21.0.11+10 | ||
| 25.33.16 25.0.2.0.101+1 | 25.34.17 25.0.3+9 | ||
| — | 26.30.11 26.0.1+8 | ||
| CVE-2026-22021 Note 2: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. | 5.3 | ||
| 6.79.0.14 6b179 | — | ||
| 7.85.0.12 7u501-b01 | — | ||
| 8.93.0.18 8u491-b01 | 8.94.0.17 8u492-b09 | ||
| 11.87.18 11.0.30.0.101+1 | 11.88.17 11.0.31+11 | ||
| 17.65.18 17.0.18.0.101+1 | 17.66.19 17.0.19+10 | ||
| 21.49.18 21.0.10.0.101+1 | 21.50.19 21.0.11+10 | ||
| 25.33.16 25.0.2.0.101+1 | 25.34.17 25.0.3+9 | ||
| — | 26.30.11 26.0.1+8 | ||
| CVE-2026-23865 Note 2: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. | 5.3 | ||
| 6.79.0.14 6b179 | — | ||
| 7.85.0.12 7u501-b01 | — | ||
| 8.93.0.18 8u491-b01 | 8.94.0.17 8u492-b09 | ||
| 11.87.18 11.0.30.0.101+1 | 11.88.17 11.0.31+11 | ||
| 17.65.18 17.0.18.0.101+1 | 17.66.19 17.0.19+10 | ||
| 21.49.18 21.0.10.0.101+1 | 21.50.19 21.0.11+10 | ||
| 25.33.16 25.0.2.0.101+1 | 25.34.17 25.0.3+9 | ||
| — | 26.30.11 26.0.1+8 | ||
| CVE-2026-34268 Note 2: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. | 2.9 | ||
| 6.79.0.14 6b179 | — | ||
| 7.85.0.12 7u501-b01 | — | ||
| 8.93.0.18 8u491-b01 | 8.94.0.17 8u492-b09 | ||
| 11.87.18 11.0.30.0.101+1 | 11.88.17 11.0.31+11 | ||
| 17.65.18 17.0.18.0.101+1 | 17.66.19 17.0.19+10 | ||
| 21.49.18 21.0.10.0.101+1 | 21.50.19 21.0.11+10 | ||
| 25.33.16 25.0.2.0.101+1 | 25.34.17 25.0.3+9 | ||
| — | 26.30.11 26.0.1+8 | ||
| CVE-2026-22018 Note 2: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. | 3.7 | ||
| 7.85.0.12 7u501-b01 | — | ||
| 8.93.0.18 8u491-b01 | 8.94.0.17 8u492-b09 | ||
| 11.87.18 11.0.30.0.101+1 | 11.88.17 11.0.31+11 | ||
| 17.65.18 17.0.18.0.101+1 | 17.66.19 17.0.19+10 | ||
| 21.49.18 21.0.10.0.101+1 | 21.50.19 21.0.11+10 | ||
| 25.33.16 25.0.2.0.101+1 | 25.34.17 25.0.3+9 | ||
| — | 26.30.11 26.0.1+8 | ||
| CVE-2026-20652 Note 1: This vulnerability applies to Java deployments, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). Note 3: The patch for CVE-2026-20652 also addresses CVE-2025-43457, CVE-2026-20608, CVE-2026-20635, CVE-2026-20636, CVE-2026-20644, and CVE-2026-20676. | 7.5 | ||
| 8.93.0.18 8u491-b01 | 8.94.0.17 8u492-b09 | ||
| 11.87.18 11.0.30.0.101+1 | 11.88.17 11.0.31+11 | ||
| 17.65.18 17.0.18.0.101+1 | 17.66.19 17.0.19+10 | ||
| 21.49.18 21.0.10.0.101+1 | 21.50.19 21.0.11+10 | ||
| 25.33.16 25.0.2.0.101+1 | 25.34.17 25.0.3+9 | ||
| — | 26.30.11 26.0.1+8 | ||
| CVE-2026-34282 Note 2: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. | 7.5 | ||
| 11.87.18 11.0.30.0.101+1 | 11.88.17 11.0.31+11 | ||
| 17.65.18 17.0.18.0.101+1 | 17.66.19 17.0.19+10 | ||
| 21.49.18 21.0.10.0.101+1 | 21.50.19 21.0.11+10 | ||
| 25.33.16 25.0.2.0.101+1 | 25.34.17 25.0.3+9 | ||
| — | 26.30.11 26.0.1+8 | ||
| CVE-2026-22008 Note 1: This vulnerability applies to Java deployments, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). | 3.7 | ||
| 25.33.16 25.0.2.0.101+1 | 25.34.17 25.0.3+9 | ||
| — | 26.30.11 26.0.1+8 | ||
| CVE-2026-22003 This CVE is not applicable to Azul Core. It is listed here for comparison with other Java implementations which may contain this CVE. Note 1: This vulnerability applies to Java deployments, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). | 6 | — | |
January 2026 CVEs
| January 2026 | Back to Top | ||
|---|---|---|---|
| January 2026 Quarterly Update Release | |||
| Azul Zulu Build of OpenJDK | |||
| CVE | Base Score | CPU | PSU |
| CVE-2026-21925 Note 2: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. | 4.8 | ||
| 6.77.0.12 6b177 | — | ||
| 7.83.0.12 7u491-b01 | — | ||
| 8.91.0.12 8u481-b01 | 8.92.0.19 8u482-b08 | ||
| 11.85.12 11.0.29.0.101+1 | 11.86.19 11.0.30+7 | ||
| 17.63.12 17.0.17.0.101+1 | 17.64.15 17.0.18+8 | ||
| 21.47.14 21.0.9.0.101+1 | 21.48.15 21.0.10+7 | ||
| 25.31.14 25.0.1.0.101+1 | 25.32.17 25.0.2+10 | ||
| CVE-2026-21932 Note 1: This vulnerability applies to Java deployments, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). | 7.4 | ||
| 6.77.0.12 6b177 | — | ||
| 7.83.0.12 7u491-b01 | — | ||
| 8.91.0.12 8u481-b01 | 8.92.0.19 8u482-b08 | ||
| 11.85.12 11.0.29.0.101+1 | 11.86.19 11.0.30+7 | ||
| 17.63.12 17.0.17.0.101+1 | 17.64.15 17.0.18+8 | ||
| 21.47.14 21.0.9.0.101+1 | 21.48.15 21.0.10+7 | ||
| 25.31.14 25.0.1.0.101+1 | 25.32.17 25.0.2+10 | ||
| CVE-2026-21933 Note 2: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. | 6.1 | ||
| 6.77.0.12 6b177 | — | ||
| 7.83.0.12 7u491-b01 | — | ||
| 8.91.0.12 8u481-b01 | 8.92.0.19 8u482-b08 | ||
| 11.85.12 11.0.29.0.101+1 | 11.86.19 11.0.30+7 | ||
| 17.63.12 17.0.17.0.101+1 | 17.64.15 17.0.18+8 | ||
| 21.47.14 21.0.9.0.101+1 | 21.48.15 21.0.10+7 | ||
| 25.31.14 25.0.1.0.101+1 | 25.32.17 25.0.2+10 | ||
| CVE-2026-21945 Note 1: This vulnerability applies to Java deployments, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). | 7.5 | ||
| 6.77.0.12 6b177 | — | ||
| 7.83.0.12 7u491-b01 | — | ||
| 8.91.0.12 8u481-b01 | 8.92.0.19 8u482-b08 | ||
| 11.85.12 11.0.29.0.101+1 | 11.86.19 11.0.30+7 | ||
| 17.63.12 17.0.17.0.101+1 | 17.64.15 17.0.18+8 | ||
| 21.47.14 21.0.9.0.101+1 | 21.48.15 21.0.10+7 | ||
| 25.31.14 25.0.1.0.101+1 | 25.32.17 25.0.2+10 | ||
| CVE-2025-6021 Note 1: This vulnerability applies to Java deployments, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). | 5.9 | ||
| 8.91.0.12 8u481-b01 | 8.92.0.19 8u482-b08 | ||
| 11.85.12 11.0.29.0.101+1 | 11.86.19 11.0.30+7 | ||
| 17.63.12 17.0.17.0.101+1 | 17.64.15 17.0.18+8 | ||
| 21.47.14 21.0.9.0.101+1 | 21.48.15 21.0.10+7 | ||
| 25.31.14 25.0.1.0.101+1 | 25.32.17 25.0.2+10 | ||
| CVE-2025-6052 Note 1: This vulnerability applies to Java deployments, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). | 3.7 | ||
| 8.91.0.12 8u481-b01 | 8.92.0.19 8u482-b08 | ||
| 11.85.12 11.0.29.0.101+1 | 11.86.19 11.0.30+7 | ||
| 17.63.12 17.0.17.0.101+1 | 17.64.15 17.0.18+8 | ||
| 21.47.14 21.0.9.0.101+1 | 21.48.15 21.0.10+7 | ||
| 25.31.14 25.0.1.0.101+1 | 25.32.17 25.0.2+10 | ||
| CVE-2025-7425 Note 1: This vulnerability applies to Java deployments, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). | 7.5 | ||
| 8.91.0.12 8u481-b01 | 8.92.0.19 8u482-b08 | ||
| 11.85.12 11.0.29.0.101+1 | 11.86.19 11.0.30+7 | ||
| 17.63.12 17.0.17.0.101+1 | 17.64.15 17.0.18+8 | ||
| 21.47.14 21.0.9.0.101+1 | 21.48.15 21.0.10+7 | ||
| 25.31.14 25.0.1.0.101+1 | 25.32.17 25.0.2+10 | ||
| CVE-2026-21947 Note 1: This vulnerability applies to Java deployments, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). | 3.1 | ||
| 8.91.0.12 8u481-b01 | 8.92.0.19 8u482-b08 | ||
| 11.85.12 11.0.29.0.101+1 | 11.86.19 11.0.30+7 | ||
| 17.63.12 17.0.17.0.101+1 | 17.64.15 17.0.18+8 | ||
| 21.47.14 21.0.9.0.101+1 | 21.48.15 21.0.10+7 | ||
| 25.31.14 25.0.1.0.101+1 | 25.32.17 25.0.2+10 | ||
| CVE-2025-43368 Note 1: This vulnerability applies to Java deployments, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). | 7.5 | ||
| 8.91.0.12 8u481-b01 | 8.92.0.19 8u482-b08 | ||
| 11.85.12 11.0.29.0.101+1 | 11.86.19 11.0.30+7 | ||
| 17.63.12 17.0.17.0.101+1 | 17.64.15 17.0.18+8 | ||
| 21.47.14 21.0.9.0.101+1 | 21.48.15 21.0.10+7 | ||
| 25.31.14 25.0.1.0.101+1 | 25.32.17 25.0.2+10 | ||
| CVE-2025-47219 Note 2: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. | 3.1 | ||
| 8.91.0.12 8u481-b01 | 8.92.0.19 8u482-b08 | ||
| 11.85.12 11.0.29.0.101+1 | 11.86.19 11.0.30+7 | ||
| 17.63.12 17.0.17.0.101+1 | 17.64.15 17.0.18+8 | ||
| 21.47.14 21.0.9.0.101+1 | 21.48.15 21.0.10+7 | ||
| 25.31.14 25.0.1.0.101+1 | 25.32.17 25.0.2+10 | ||
| CVE-2025-12183 This CVE is not applicable to Azul Core. It is listed here for comparison with other Java implementations which may contain this CVE. Note 3: Azul Zulu Mission Control 9.1.1 is affected and is being updated and released separately. | 5.4 | — | |
October 2025 CVEs
| October 2025 | Back to Top | ||
|---|---|---|---|
| October 2025 Quarterly Update Release | |||
| Azul Zulu Build of OpenJDK | |||
| CVE | Base Score | CPU | PSU |
| CVE-2025-53057 Note 2: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. | 5.9 | ||
| 6.75.0.14 6b175 | — | ||
| 7.81.0.12 7u481-b01 | — | ||
| 8.89.0.14 8u471-b01 | 8.90.0.19 8u472-b08 | ||
| 11.83.12 11.0.28.0.101+1 | 11.84.17 11.0.29+7 | ||
| 17.61.12 17.0.16.0.101+1 | 17.62.17 17.0.17+10 | ||
| 21.45.14 21.0.8.0.101+1 | 21.46.19 21.0.9+10 | ||
| 25.29.12 25.0.0.0.101+1 | 25.30.17 25.0.1+8 | ||
| CVE-2025-53066 Note 2: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. | 7.5 | ||
| 6.75.0.14 6b175 | — | ||
| 7.81.0.12 7u481-b01 | — | ||
| 8.89.0.14 8u471-b01 | 8.90.0.19 8u472-b08 | ||
| 11.83.12 11.0.28.0.101+1 | 11.84.17 11.0.29+7 | ||
| 17.61.12 17.0.16.0.101+1 | 17.62.17 17.0.17+10 | ||
| 21.45.14 21.0.8.0.101+1 | 21.46.19 21.0.9+10 | ||
| 25.29.12 25.0.0.0.101+1 | 25.30.17 25.0.1+8 | ||
| CVE-2025-31257 Note 1: This vulnerability applies to Java deployments, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). | 7.5 | ||
| 8.89.0.14 8u471-b01 | 8.90.0.19 8u472-b08 | ||
| 11.83.12 11.0.28.0.101+1 | 11.84.17 11.0.29+7 | ||
| 17.61.12 17.0.16.0.101+1 | 17.62.17 17.0.17+10 | ||
| 21.45.14 21.0.8.0.101+1 | 21.46.19 21.0.9+10 | ||
| 25.29.12 25.0.0.0.101+1 | 25.30.17 25.0.1+8 | ||
| CVE-2025-61748 Note 2: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. | 3.7 | ||
| 21.45.14 21.0.8.0.101+1 | 21.46.19 21.0.9+10 | ||
| 25.29.12 25.0.0.0.101+1 | 25.30.17 25.0.1+8 | ||
| CVE-2025-61755 This CVE is not applicable to Azul Core. It is listed here for comparison with other Java implementations which may contain this CVE. | 3.7 | — | |
July 2025 CVEs
| July 2025 | Back to Top | ||
|---|---|---|---|
| July 2025 Quarterly Update Release | |||
| Azul Zulu Build of OpenJDK | |||
| CVE | Base Score | CPU | PSU |
| CVE-2025-30749 Note 1: This vulnerability applies to Java deployments, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). | 8.1 | ||
| 7.79.0.14 7u471-b01 | — | ||
| 8.87.0.16 8u461-b01 | 8.88.0.19 8u462-b08 | ||
| 11.81.16 11.0.27.0.101+1 | 11.82.19 11.0.28+6 | ||
| 17.59.16 17.0.15.0.101+1 | 17.60.17 17.0.16+8 | ||
| 21.43.16 21.0.7.0.101+1 | 21.44.17 21.0.8+9 | ||
| — | 24.32.13 24.0.2+11 | ||
| CVE-2025-50106 Note 2: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. | 8.1 | ||
| 7.79.0.14 7u471-b01 | — | ||
| 8.87.0.16 8u461-b01 | 8.88.0.19 8u462-b08 | ||
| 11.81.16 11.0.27.0.101+1 | 11.82.19 11.0.28+6 | ||
| 17.59.16 17.0.15.0.101+1 | 17.60.17 17.0.16+8 | ||
| 21.43.16 21.0.7.0.101+1 | 21.44.17 21.0.8+9 | ||
| — | 24.32.13 24.0.2+11 | ||
| CVE-2025-24855 Note 1: This vulnerability applies to Java deployments, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). | 7.5 | ||
| 8.87.0.16 8u461-b01 | 8.88.0.19 8u462-b08 | ||
| 11.81.16 11.0.27.0.101+1 | 11.82.19 11.0.28+6 | ||
| 17.59.16 17.0.15.0.101+1 | 17.60.17 17.0.16+8 | ||
| 21.43.16 21.0.7.0.101+1 | 21.44.17 21.0.8+9 | ||
| — | 24.32.13 24.0.2+11 | ||
| CVE-2025-27113 Note 1: This vulnerability applies to Java deployments, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). | 7.5 | ||
| 8.87.0.16 8u461-b01 | 8.88.0.19 8u462-b08 | ||
| 11.81.16 11.0.27.0.101+1 | 11.82.19 11.0.28+6 | ||
| 17.59.16 17.0.15.0.101+1 | 17.60.17 17.0.16+8 | ||
| 21.43.16 21.0.7.0.101+1 | 21.44.17 21.0.8+9 | ||
| — | 24.32.13 24.0.2+11 | ||
| CVE-2025-30754 Note 1: This vulnerability applies to Java deployments, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). | 4.8 | ||
| 8.87.0.16 8u461-b01 | 8.88.0.19 8u462-b08 | ||
| 11.81.16 11.0.27.0.101+1 | 11.82.19 11.0.28+6 | ||
| 17.59.16 17.0.15.0.101+1 | 17.60.17 17.0.16+8 | ||
| 21.43.16 21.0.7.0.101+1 | 21.44.17 21.0.8+9 | ||
| — | 24.32.13 24.0.2+11 | ||
| CVE-2025-50059 Note 1: This vulnerability applies to Java deployments, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). | 8.6 | ||
| 11.81.16 11.0.27.0.101+1 | 11.82.19 11.0.28+6 | ||
| 17.59.16 17.0.15.0.101+1 | 17.60.17 17.0.16+8 | ||
| 21.43.16 21.0.7.0.101+1 | 21.44.17 21.0.8+9 | ||
| — | 24.32.13 24.0.2+11 | ||
| CVE-2025-30761 Note 2: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. | 5.9 | ||
| 8.87.0.16 8u461-b01 | 8.88.0.19 8u462-b08 | ||
| 11.81.16 11.0.27.0.101+1 | 11.82.19 11.0.28+6 | ||
| CVE-2025-23166 This CVE is not applicable to Azul Core. It is listed here for comparison with other Java implementations which may contain this CVE. | 7.5 | — | |
| CVE-2025-30752 This CVE is not applicable to Azul Core. It is listed here for comparison with other Java implementations which may contain this CVE. | 3.7 | — | |
| CVE-2025-50063 This CVE is not applicable to Azul Core. It is listed here for comparison with other Java implementations which may contain this CVE. | 7.3 | — | |
| CVE-2025-50065 This CVE is not applicable to Azul Core. It is listed here for comparison with other Java implementations which may contain this CVE. | 3.7 | — | |
April 2025 CVEs
| April 2025 | Back to Top | ||
|---|---|---|---|
| April 2025 Quarterly Update Release | |||
| Azul Zulu Build of OpenJDK | |||
| CVE | Base Score | CPU | PSU |
| CVE-2025-21587 Note 2: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. | 7.4 | ||
| 6.71.0.16 6b171 | — | ||
| 7.77.0.14 7u461-b01 | — | ||
| 8.85.0.22 8u451-b02 | 8.86.0.25 8u452-b08 | ||
| 11.79.18 11.0.26.0.101+2 | 11.80.21 11.0.27+6 | ||
| 17.57.18 17.0.14.0.101+2 | 17.58.21 17.0.15+6 | ||
| 21.41.18 21.0.6.0.101+2 | 21.42.19 21.0.7+6 | ||
| — | 24.30.11 24.0.1+9 | ||
| CVE-2025-30698 Note 1: This vulnerability applies to Java deployments, typically in clients, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). | 5.6 | ||
| 6.71.0.16 6b171 | — | ||
| 7.77.0.14 7u461-b01 | — | ||
| 8.85.0.22 8u451-b02 | 8.86.0.25 8u452-b08 | ||
| 11.79.18 11.0.26.0.101+2 | 11.80.21 11.0.27+6 | ||
| 17.57.18 17.0.14.0.101+2 | 17.58.21 17.0.15+6 | ||
| 21.41.18 21.0.6.0.101+2 | 21.42.19 21.0.7+6 | ||
| — | 24.30.11 24.0.1+9 | ||
| CVE-2025-30691 Note 2: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. | 4.8 | ||
| 8.85.0.22 8u451-b02 | 8.86.0.25 8u452-b08 | ||
| 11.79.18 11.0.26.0.101+2 | 11.80.21 11.0.27+6 | ||
| 17.57.18 17.0.14.0.101+2 | 17.58.21 17.0.15+6 | ||
| 21.41.18 21.0.6.0.101+2 | 21.42.19 21.0.7+6 | ||
| — | 24.30.11 24.0.1+9 | ||
| CVE-2024-47606 Note 1: This vulnerability applies to Java deployments, typically in clients, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). | 7.5 | ||
| 8.85.0.22 8u451-b02 | 8.86.0.25 8u452-b08 | ||
| 11.79.18 11.0.26.0.101+2 | 11.80.21 11.0.27+6 | ||
| 17.57.18 17.0.14.0.101+2 | 17.58.21 17.0.15+6 | ||
| 21.41.18 21.0.6.0.101+2 | 21.42.19 21.0.7+6 | ||
| — | 24.30.11 24.0.1+9 | ||
| CVE-2024-54534 Note 1: This vulnerability applies to Java deployments, typically in clients, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). | 7.5 | ||
| 8.85.0.22 8u451-b02 | 8.86.0.25 8u452-b08 | ||
| 11.79.18 11.0.26.0.101+2 | 11.80.21 11.0.27+6 | ||
| 17.57.18 17.0.14.0.101+2 | 17.58.21 17.0.15+6 | ||
| 21.41.18 21.0.6.0.101+2 | 21.42.19 21.0.7+6 | ||
| — | 24.30.11 24.0.1+9 | ||
| CVE-2025-23083 This CVE is not applicable to Azul Core. It is listed here for comparison with other Java implementations which may contain this CVE. | 7.7 | — | |
January 2025 CVEs
| January 2025 | Back to Top | ||
|---|---|---|---|
| January 2025 Quarterly Update Release | |||
| Azul Zulu Build of OpenJDK | |||
| CVE | Base Score | CPU | PSU |
| CVE-2025-21502 Note 1: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. | 4.8 | ||
| 11.77.14 11.0.25.0.101+1 | 11.78.15 11.0.26+4 | ||
| 17.55.14 17.0.13.0.101+1 | 17.56.15 17.0.14+7 | ||
| 21.39.14 21.0.5.0.101+1 | 21.40.17 21.0.6+7 | ||
| — | 23.32.11 23.0.2+7 | ||
| CVE-2025-0509 This CVE is not applicable to Azul Core. It is listed here for comparison with other Java implementations which may contain this CVE. | 7.3 | — | |
October 2024 CVEs
| October 2024 | Back to Top | ||
|---|---|---|---|
| October 2024 Quarterly Update Release | |||
| Azul Zulu Build of OpenJDK | |||
| CVE | Base Score | CPU | PSU |
| CVE-2024-21208 Note 1: This vulnerability applies to Java deployments, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). | 3.7 | ||
| 6.67.0.12 6b167 | — | ||
| 7.73.0.14 7u441-b02 | — | ||
| 8.81.0.12 8u431-b01 | 8.82.0.21 8u432-b06 | ||
| 11.75.12 11.0.24.0.101+1 | 11.76.21 11.0.25+9 | ||
| 17.53.12 17.0.12.0.101+1 | 17.54.21 17.0.13+11 | ||
| 21.37.12 21.0.4.0.101+1 | 21.38.21 21.0.5+11 | ||
| — | 23.30.13 23.0.1+11 | ||
| CVE-2024-21210 Note 2: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. | 3.7 | ||
| 6.67.0.12 6b167 | — | ||
| 7.73.0.14 7u441-b02 | — | ||
| 8.81.0.12 8u431-b01 | 8.82.0.21 8u432-b06 | ||
| 11.75.12 11.0.24.0.101+1 | 11.76.21 11.0.25+9 | ||
| 17.53.12 17.0.12.0.101+1 | 17.54.21 17.0.13+11 | ||
| 21.37.12 21.0.4.0.101+1 | 21.38.21 21.0.5+11 | ||
| — | 23.30.13 23.0.1+11 | ||
| CVE-2024-21217 Note 2: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. | 3.7 | ||
| 6.67.0.12 6b167 | — | ||
| 7.73.0.14 7u441-b02 | — | ||
| 8.81.0.12 8u431-b01 | 8.82.0.21 8u432-b06 | ||
| 11.75.12 11.0.24.0.101+1 | 11.76.21 11.0.25+9 | ||
| 17.53.12 17.0.12.0.101+1 | 17.54.21 17.0.13+11 | ||
| 21.37.12 21.0.4.0.101+1 | 21.38.21 21.0.5+11 | ||
| — | 23.30.13 23.0.1+11 | ||
| CVE-2024-21235 Note 2: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. | 4.8 | ||
| 6.67.0.12 6b167 | — | ||
| 7.73.0.14 7u441-b02 | — | ||
| 8.81.0.12 8u431-b01 | 8.82.0.21 8u432-b06 | ||
| 11.75.12 11.0.24.0.101+1 | 11.76.21 11.0.25+9 | ||
| 17.53.12 17.0.12.0.101+1 | 17.54.21 17.0.13+11 | ||
| 21.37.12 21.0.4.0.101+1 | 21.38.21 21.0.5+11 | ||
| — | 23.30.13 23.0.1+11 | ||
| CVE-2024-25062 Note 1: This vulnerability applies to Java deployments, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). | 7.5 | ||
| 8.81.0.12 8u431-b01 | 8.82.0.21 8u432-b06 | ||
| 11.75.12 11.0.24.0.101+1 | 11.76.21 11.0.25+9 | ||
| 17.53.12 17.0.12.0.101+1 | 17.54.21 17.0.13+11 | ||
| 21.37.12 21.0.4.0.101+1 | 21.38.21 21.0.5+11 | ||
| — | 23.30.13 23.0.1+11 | ||
| CVE-2023-42950 Note 1: This vulnerability applies to Java deployments, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). | 7.5 | ||
| 8.81.0.12 8u431-b01 | 8.82.0.21 8u432-b06 | ||
| 11.75.12 11.0.24.0.101+1 | 11.76.21 11.0.25+9 | ||
| 17.53.12 17.0.12.0.101+1 | 17.54.21 17.0.13+11 | ||
| 21.37.12 21.0.4.0.101+1 | 21.38.21 21.0.5+11 | ||
| — | 23.30.13 23.0.1+11 | ||
| CVE-2024-21211 This CVE is not applicable to Azul Core. It is listed here for comparison with other Java implementations which may contain this CVE. Note 2: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. | 3.7 | — | |
| CVE-2024-36138 This CVE is not applicable to Azul Core. It is listed here for comparison with other Java implementations which may contain this CVE. | 8.1 | — | |
July 2024 CVEs
| July 2024 | Back to Top | ||
|---|---|---|---|
| July 2024 Quarterly Update Release | |||
| Azul Zulu Build of OpenJDK | |||
| CVE | Base Score | CPU | PSU |
| CVE-2024-21131 Note 1: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. | 3.7 | ||
| 6.65.0.16 6b165 | — | ||
| 7.71.0.18 7u431-b04 | — | ||
| 8.79.0.14 8u421-b02 | 8.80.0.17 8u422-b05 | ||
| 11.73.14 11.0.23.0.101+2 | 11.74.15 11.0.24+8 | ||
| 17.51.16 17.0.11.0.101+3 | 17.52.17 17.0.12+7 | ||
| 21.35.18 21.0.3.0.101+4 | 21.36.17 21.0.4+7 | ||
| — | 22.32.15 22.0.2+9 | ||
| CVE-2024-21138 Note 1: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. | 3.7 | ||
| 6.65.0.16 6b165 | — | ||
| 7.71.0.18 7u431-b04 | — | ||
| 8.79.0.14 8u421-b02 | 8.80.0.17 8u422-b05 | ||
| 11.73.14 11.0.23.0.101+2 | 11.74.15 11.0.24+8 | ||
| 17.51.16 17.0.11.0.101+3 | 17.52.17 17.0.12+7 | ||
| 21.35.18 21.0.3.0.101+4 | 21.36.17 21.0.4+7 | ||
| — | 22.32.15 22.0.2+9 | ||
| CVE-2024-21140 Note 1: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. | 4.8 | ||
| 6.65.0.16 6b165 | — | ||
| 7.71.0.18 7u431-b04 | — | ||
| 8.79.0.14 8u421-b02 | 8.80.0.17 8u422-b05 | ||
| 11.73.14 11.0.23.0.101+2 | 11.74.15 11.0.24+8 | ||
| 17.51.16 17.0.11.0.101+3 | 17.52.17 17.0.12+7 | ||
| 21.35.18 21.0.3.0.101+4 | 21.36.17 21.0.4+7 | ||
| — | 22.32.15 22.0.2+9 | ||
| CVE-2024-21145 Note 1: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. | 4.8 | ||
| 7.71.0.18 7u431-b04 | — | ||
| 8.79.0.14 8u421-b02 | 8.80.0.17 8u422-b05 | ||
| 11.73.14 11.0.23.0.101+2 | 11.74.15 11.0.24+8 | ||
| 17.51.16 17.0.11.0.101+3 | 17.52.17 17.0.12+7 | ||
| 21.35.18 21.0.3.0.101+4 | 21.36.17 21.0.4+7 | ||
| — | 22.32.15 22.0.2+9 | ||
| CVE-2024-21147 Note 1: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. | 7.4 | ||
| 8.79.0.14 8u421-b02 | 8.80.0.17 8u422-b05 | ||
| 11.73.14 11.0.23.0.101+2 | 11.74.15 11.0.24+8 | ||
| 17.51.16 17.0.11.0.101+3 | 17.52.17 17.0.12+7 | ||
| 21.35.18 21.0.3.0.101+4 | 21.36.17 21.0.4+7 | ||
| — | 22.32.15 22.0.2+9 | ||
| CVE-2024-21144 Note 2: This vulnerability applies to Java deployments that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). | 3.7 | ||
| 6.65.0.16 6b165 | — | ||
| 7.71.0.18 7u431-b04 | — | ||
| 8.79.0.14 8u421-b02 | 8.80.0.17 8u422-b05 | ||
| 11.73.14 11.0.23.0.101+2 | 11.74.15 11.0.24+8 | ||
| CVE-2024-27983 This CVE is not applicable to Azul Core. It is listed here for comparison with other Java implementations which may contain this CVE. | 8.2 | — | |
April 2024 CVEs
| April 2024 | Back to Top | ||
|---|---|---|---|
| April 2024 Quarterly Update Release | |||
| Azul Zulu Build of OpenJDK | |||
| CVE | Base Score | CPU | PSU |
| CVE-2024-21068 Note 2: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. | 3.7 | ||
| 6.63.0.14 6b163 | — | ||
| 7.69.0.14 7u421-b02 | — | ||
| 8.77.0.14 8u411-b02 | 8.78.0.19 8u412-b08 | ||
| 11.71.14 11.0.22.0.101+2 | 11.72.19 11.0.23+9 | ||
| 17.49.16 17.0.10.0.101+3 | 17.50.19 17.0.11+9 | ||
| 21.33.14 21.0.2.0.101+2 | 21.34.19 21.0.3+9 | ||
| — | 22.30.13 22.0.1+8 | ||
| CVE-2024-21094 Note 2: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. | 3.7 | ||
| 6.63.0.14 6b163 | — | ||
| 7.69.0.14 7u421-b02 | — | ||
| 8.77.0.14 8u411-b02 | 8.78.0.19 8u412-b08 | ||
| 11.71.14 11.0.22.0.101+2 | 11.72.19 11.0.23+9 | ||
| 17.49.16 17.0.10.0.101+3 | 17.50.19 17.0.11+9 | ||
| 21.33.14 21.0.2.0.101+2 | 21.34.19 21.0.3+9 | ||
| — | 22.30.13 22.0.1+8 | ||
| CVE-2024-21002 Note 1: This vulnerability applies to Java deployments that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). | 2.5 | ||
| 8.77.0.14 8u411-b02 | 8.78.0.19 8u412-b08 | ||
| 11.71.14 11.0.22.0.101+2 | 11.72.19 11.0.23+9 | ||
| 17.49.16 17.0.10.0.101+3 | 17.50.19 17.0.11+9 | ||
| 21.33.14 21.0.2.0.101+2 | 21.34.19 21.0.3+9 | ||
| — | 22.30.13 22.0.1+8 | ||
| CVE-2024-21003 Note 1: This vulnerability applies to Java deployments that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). | 3.1 | ||
| 8.77.0.14 8u411-b02 | 8.78.0.19 8u412-b08 | ||
| 11.71.14 11.0.22.0.101+2 | 11.72.19 11.0.23+9 | ||
| 17.49.16 17.0.10.0.101+3 | 17.50.19 17.0.11+9 | ||
| 21.33.14 21.0.2.0.101+2 | 21.34.19 21.0.3+9 | ||
| — | 22.30.13 22.0.1+8 | ||
| CVE-2024-21004 Note 1: This vulnerability applies to Java deployments that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). | 2.5 | ||
| 8.77.0.14 8u411-b02 | 8.78.0.19 8u412-b08 | ||
| 11.71.14 11.0.22.0.101+2 | 11.72.19 11.0.23+9 | ||
| 17.49.16 17.0.10.0.101+3 | 17.50.19 17.0.11+9 | ||
| 21.33.14 21.0.2.0.101+2 | 21.34.19 21.0.3+9 | ||
| — | 22.30.13 22.0.1+8 | ||
| CVE-2024-21005 Note 1: This vulnerability applies to Java deployments that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). | 3.1 | ||
| 8.77.0.14 8u411-b02 | 8.78.0.19 8u412-b08 | ||
| 11.71.14 11.0.22.0.101+2 | 11.72.19 11.0.23+9 | ||
| 17.49.16 17.0.10.0.101+3 | 17.50.19 17.0.11+9 | ||
| 21.33.14 21.0.2.0.101+2 | 21.34.19 21.0.3+9 | ||
| — | 22.30.13 22.0.1+8 | ||
| CVE-2024-21011 Note 2: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. | 3.7 | ||
| 8.77.0.14 8u411-b02 | 8.78.0.19 8u412-b08 | ||
| 11.71.14 11.0.22.0.101+2 | 11.72.19 11.0.23+9 | ||
| 17.49.16 17.0.10.0.101+3 | 17.50.19 17.0.11+9 | ||
| 21.33.14 21.0.2.0.101+2 | 21.34.19 21.0.3+9 | ||
| — | 22.30.13 22.0.1+8 | ||
| CVE-2023-41993 Note 1: This vulnerability applies to Java deployments that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). | 7.5 | ||
| 8.77.0.14 8u411-b02 | 8.78.0.19 8u412-b08 | ||
| 11.71.14 11.0.22.0.101+2 | 11.72.19 11.0.23+9 | ||
| 17.49.16 17.0.10.0.101+3 | 17.50.19 17.0.11+9 | ||
| 21.33.14 21.0.2.0.101+2 | 21.34.19 21.0.3+9 | ||
| — | 22.30.13 22.0.1+8 | ||
| CVE-2024-21012 Note 1: This vulnerability applies to Java deployments that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). | 3.7 | ||
| 11.71.14 11.0.22.0.101+2 | 11.72.19 11.0.23+9 | ||
| 17.49.16 17.0.10.0.101+3 | 17.50.19 17.0.11+9 | ||
| 21.33.14 21.0.2.0.101+2 | 21.34.19 21.0.3+9 | ||
| — | 22.30.13 22.0.1+8 | ||
| CVE-2024-21085 Note 2: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. | 3.7 | ||
| 6.63.0.14 6b163 | — | ||
| 7.69.0.14 7u421-b02 | — | ||
| 8.77.0.14 8u411-b02 | 8.78.0.19 8u412-b08 | ||
| 11.71.14 11.0.22.0.101+2 | 11.72.19 11.0.23+9 | ||
| CVE-2024-20954 This CVE is not applicable to Azul Core. It is listed here for comparison with other Java implementations which may contain this CVE. | 3.7 | — | |
| CVE-2024-21098 This CVE is not applicable to Azul Core. It is listed here for comparison with other Java implementations which may contain this CVE. | 3.7 | — | |
| CVE-2024-21892 This CVE is not applicable to Azul Core. It is listed here for comparison with other Java implementations which may contain this CVE. | 7.5 | — | |
January 2024 CVEs
| January 2024 | Back to Top | ||
|---|---|---|---|
| January 2024 Quarterly Update Release | |||
| Azul Zulu Build of OpenJDK | |||
| CVE | Base Score | CPU | PSU |
| CVE-2024-20919 Note 3: This vulnerability can only be exploited by supplying data to APIs in the specified Component without using Untrusted applications, such as through a web service. | 5.9 | ||
| 6.61.0.16 6b161 | — | ||
| 7.67.0.16 7u411-b03 | — | ||
| 8.75.0.16 8u401-b03 | 8.76.0.17 8u402-b06 | ||
| 11.69.14 11.0.21.0.101+2 | 11.70.15 11.0.22+7 | ||
| 17.47.16 17.0.9.0.101+3 | 17.48.15 17.0.10+7 | ||
| 21.31.16 21.0.1.0.101+3 | 21.32.17 21.0.2+13 | ||
| CVE-2024-20921 Note 2: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. | 5.9 | ||
| 6.61.0.16 6b161 | — | ||
| 7.67.0.16 7u411-b03 | — | ||
| 8.75.0.16 8u401-b03 | 8.76.0.17 8u402-b06 | ||
| 11.69.14 11.0.21.0.101+2 | 11.70.15 11.0.22+7 | ||
| 17.47.16 17.0.9.0.101+3 | 17.48.15 17.0.10+7 | ||
| 21.31.16 21.0.1.0.101+3 | 21.32.17 21.0.2+13 | ||
| CVE-2024-20945 Note 1: This vulnerability applies to Java deployments, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). | 4.7 | ||
| 6.61.0.16 6b161 | — | ||
| 7.67.0.16 7u411-b03 | — | ||
| 8.75.0.16 8u401-b03 | 8.76.0.17 8u402-b06 | ||
| 11.69.14 11.0.21.0.101+2 | 11.70.15 11.0.22+7 | ||
| 17.47.16 17.0.9.0.101+3 | 17.48.15 17.0.10+7 | ||
| 21.31.16 21.0.1.0.101+3 | 21.32.17 21.0.2+13 | ||
| CVE-2024-20952 Note 1: This vulnerability applies to Java deployments, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). | 7.4 | ||
| 6.61.0.16 6b161 | — | ||
| 7.67.0.16 7u411-b03 | — | ||
| 8.75.0.16 8u401-b03 | 8.76.0.17 8u402-b06 | ||
| 11.69.14 11.0.21.0.101+2 | 11.70.15 11.0.22+7 | ||
| 17.47.16 17.0.9.0.101+3 | 17.48.15 17.0.10+7 | ||
| 21.31.16 21.0.1.0.101+3 | 21.32.17 21.0.2+13 | ||
| CVE-2024-20918 Note 2: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. | 7.4 | ||
| 8.75.0.16 8u401-b03 | 8.76.0.17 8u402-b06 | ||
| 11.69.14 11.0.21.0.101+2 | 11.70.15 11.0.22+7 | ||
| 17.47.16 17.0.9.0.101+3 | 17.48.15 17.0.10+7 | ||
| 21.31.16 21.0.1.0.101+3 | 21.32.17 21.0.2+13 | ||
| CVE-2024-20922 Note 1: This vulnerability applies to Java deployments, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). | 2.5 | ||
| 8.75.0.16 8u401-b03 | 8.76.0.17 8u402-b06 | ||
| 11.69.14 11.0.21.0.101+2 | 11.70.15 11.0.22+7 | ||
| 17.47.16 17.0.9.0.101+3 | 17.48.15 17.0.10+7 | ||
| 21.31.16 21.0.1.0.101+3 | 21.32.17 21.0.2+13 | ||
| CVE-2024-20923 Note 1: This vulnerability applies to Java deployments, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). | 3.1 | ||
| 8.75.0.16 8u401-b03 | 8.76.0.17 8u402-b06 | ||
| 11.69.14 11.0.21.0.101+2 | 11.70.15 11.0.22+7 | ||
| 17.47.16 17.0.9.0.101+3 | 17.48.15 17.0.10+7 | ||
| 21.31.16 21.0.1.0.101+3 | 21.32.17 21.0.2+13 | ||
| CVE-2024-20925 Note 1: This vulnerability applies to Java deployments, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). | 3.1 | ||
| 8.75.0.16 8u401-b03 | 8.76.0.17 8u402-b06 | ||
| 11.69.14 11.0.21.0.101+2 | 11.70.15 11.0.22+7 | ||
| 17.47.16 17.0.9.0.101+3 | 17.48.15 17.0.10+7 | ||
| 21.31.16 21.0.1.0.101+3 | 21.32.17 21.0.2+13 | ||
| CVE-2024-20926 Note 2: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. | 5.9 | ||
| 8.75.0.16 8u401-b03 | 8.76.0.17 8u402-b06 | ||
| 11.69.14 11.0.21.0.101+2 | 11.70.15 11.0.22+7 | ||
| CVE-2024-20932 Note 1: This vulnerability applies to Java deployments, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). | 7.5 | ||
| 17.47.16 17.0.9.0.101+3 | 17.48.15 17.0.10+7 | ||
| CVE-2023-5072 This CVE is not applicable to Azul Core. It is listed here for comparison with other Java implementations which may contain this CVE. | 7.5 | — | |
| CVE-2024-20955 This CVE is not applicable to Azul Core. It is listed here for comparison with other Java implementations which may contain this CVE. | 3.7 | — | |
| CVE-2023-44487 This CVE is not applicable to Azul Core. It is listed here for comparison with other Java implementations which may contain this CVE. | 7.5 | — | |
October 2023 CVEs
| October 2023 | Back to Top | ||
|---|---|---|---|
| October 2023 Quarterly Update Release | |||
| Azul Zulu Build of OpenJDK | |||
| CVE | Base Score | CPU | PSU |
| CVE-2023-22081 Note 2: This vulnerability applies to Java deployments that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). | 5.3 | ||
| 6.59.0.14 6b159 | — | ||
| 7.65.0.14 7u401-b01 | — | ||
| 8.73.0.12 8u391-b01 | 8.74.0.17 8u392-b08 | ||
| 11.67.16 11.0.20.1.101+1 | 11.68.17 11.0.21+9 | ||
| 17.45.16 17.0.8.1.101+1 | 17.46.19 17.0.9+8 | ||
| 21.29.12 21.0.0.0.101+1 | 21.30.15 21.0.1+11 | ||
| CVE-2023-22025 Note 3: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. | 3.7 | ||
| 17.45.16 17.0.8.1.101+1 | 17.46.19 17.0.9+8 | ||
| 21.29.12 21.0.0.0.101+1 | 21.30.15 21.0.1+11 | ||
| CVE-2023-22067 Note 1: This vulnerability can only be exploited by supplying data to APIs in the specified Component, e.g., through a web service. | 5.3 | ||
| 6.59.0.14 6b159 | — | ||
| 7.65.0.14 7u401-b01 | — | ||
| 8.73.0.12 8u391-b01 | 8.74.0.17 8u392-b08 | ||
| CVE-2023-22091 This CVE is not applicable to Azul Core. It is listed here for comparison with other Java implementations which may contain this CVE. | 4.8 | — | |
| CVE-2023-30589 This CVE is not applicable to Azul Core. It is listed here for comparison with other Java implementations which may contain this CVE. | 7.5 | — | |
July 2023 CVEs
| July 2023 | Back to Top | ||
|---|---|---|---|
| July 2023 Quarterly Update Release | |||
| Azul Zulu Build of OpenJDK | |||
| CVE | Base Score | CPU | PSU |
| CVE-2023-22049 Note 2: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. | 3.7 | ||
| 7.63.0.14 7u391-b02 | — | ||
| 8.71.0.14 8u381-b02 | 8.72.0.17 8u382-b05 | ||
| 11.65.14 11.0.19.0.101+2 | 11.66.15 11.0.20+8 | ||
| 17.43.14 17.0.7.0.101+2 | 17.44.15 17.0.8+7 | ||
| — | 20.32.11 20.0.2+9 | ||
| CVE-2023-22043 Note 1: This vulnerability applies to Java deployments, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). | 5.9 | ||
| 8.71.0.14 8u381-b02 | 8.72.0.17 8u382-b05 | ||
| 11.65.14 11.0.19.0.101+2 | 11.66.15 11.0.20+8 | ||
| 17.43.14 17.0.7.0.101+2 | 17.44.15 17.0.8+7 | ||
| — | 20.32.11 20.0.2+9 | ||
| CVE-2023-22045 Note 2: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. | 3.7 | ||
| 8.71.0.14 8u381-b02 | 8.72.0.17 8u382-b05 | ||
| 11.65.14 11.0.19.0.101+2 | 11.66.15 11.0.20+8 | ||
| 17.43.14 17.0.7.0.101+2 | 17.44.15 17.0.8+7 | ||
| — | 20.32.11 20.0.2+9 | ||
| CVE-2023-22006 Note 1: This vulnerability applies to Java deployments, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). | 3.1 | ||
| 11.65.14 11.0.19.0.101+2 | 11.66.15 11.0.20+8 | ||
| 17.43.14 17.0.7.0.101+2 | 17.44.15 17.0.8+7 | ||
| — | 20.32.11 20.0.2+9 | ||
| CVE-2023-22036 Note 2: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. | 3.7 | ||
| 11.65.14 11.0.19.0.101+2 | 11.66.15 11.0.20+8 | ||
| 17.43.14 17.0.7.0.101+2 | 17.44.15 17.0.8+7 | ||
| — | 20.32.11 20.0.2+9 | ||
| CVE-2023-22041 Note 1: This vulnerability applies to Java deployments, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). | 5.1 | ||
| 11.65.14 11.0.19.0.101+2 | 11.66.15 11.0.20+8 | ||
| 17.43.14 17.0.7.0.101+2 | 17.44.15 17.0.8+7 | ||
| — | 20.32.11 20.0.2+9 | ||
| CVE-2023-25193 Note 2: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. | 3.7 | ||
| 11.65.14 11.0.19.0.101+2 | 11.66.15 11.0.20+8 | ||
| 17.43.14 17.0.7.0.101+2 | 17.44.15 17.0.8+7 | ||
| — | 20.32.11 20.0.2+9 | ||
| CVE-2023-22044 Note 2: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. | 3.7 | ||
| 17.43.14 17.0.7.0.101+2 | 17.44.15 17.0.8+7 | ||
| — | 20.32.11 20.0.2+9 | ||
| CVE-2023-22051 This CVE is not applicable to Azul Core. It is listed here for comparison with other Java implementations which may contain this CVE. | 3.7 | — | |
April 2023 CVEs
| April 2023 | Back to Top | ||
|---|---|---|---|
| April 2023 Quarterly Update Release | |||
| Azul Zulu Build of OpenJDK | |||
| CVE | Base Score | CPU | PSU |
| CVE-2023-21937 Note 1: This vulnerability applies to Java deployments that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. | 3.7 | ||
| 6.55.0.12 6b155 | — | ||
| 7.61.0.18 7u381-b03 | — | ||
| 8.69.0.16 8u371-b03 | 8.70.0.23 8u372-b05 | ||
| 11.63.16 11.0.18.0.101+3 | 11.64.19 11.0.19+7 | ||
| 17.41.14 17.0.6.0.101+2 | 17.42.19 17.0.7+7 | ||
| — | 20.30.11 20.0.1+9 | ||
| CVE-2023-21938 Note 2: This vulnerability applies to Java deployments that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). | 3.7 | ||
| 6.55.0.12 6b155 | — | ||
| 7.61.0.18 7u381-b03 | — | ||
| 8.69.0.16 8u371-b03 | 8.70.0.23 8u372-b05 | ||
| 11.63.16 11.0.18.0.101+3 | 11.64.19 11.0.19+7 | ||
| 17.41.14 17.0.6.0.101+2 | 17.42.19 17.0.7+7 | ||
| — | 20.30.11 20.0.1+9 | ||
| CVE-2023-21939 Note 1: This vulnerability applies to Java deployments that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. | 5.3 | ||
| 6.55.0.12 6b155 | — | ||
| 7.61.0.18 7u381-b03 | — | ||
| 8.69.0.16 8u371-b03 | 8.70.0.23 8u372-b05 | ||
| 11.63.16 11.0.18.0.101+3 | 11.64.19 11.0.19+7 | ||
| 17.41.14 17.0.6.0.101+2 | 17.42.19 17.0.7+7 | ||
| — | 20.30.11 20.0.1+9 | ||
| CVE-2023-21967 Note 1: This vulnerability applies to Java deployments that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. | 5.9 | ||
| 6.55.0.12 6b155 | — | ||
| 7.61.0.18 7u381-b03 | — | ||
| 8.69.0.16 8u371-b03 | 8.70.0.23 8u372-b05 | ||
| 11.63.16 11.0.18.0.101+3 | 11.64.19 11.0.19+7 | ||
| 17.41.14 17.0.6.0.101+2 | 17.42.19 17.0.7+7 | ||
| — | 20.30.11 20.0.1+9 | ||
| CVE-2023-21968 Note 1: This vulnerability applies to Java deployments that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. | 3.7 | ||
| 7.61.0.18 7u381-b03 | — | ||
| 8.69.0.16 8u371-b03 | 8.70.0.23 8u372-b05 | ||
| 11.63.16 11.0.18.0.101+3 | 11.64.19 11.0.19+7 | ||
| 17.41.14 17.0.6.0.101+2 | 17.42.19 17.0.7+7 | ||
| — | 20.30.11 20.0.1+9 | ||
| CVE-2023-21930 Note 1: This vulnerability applies to Java deployments that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. | 7.4 | ||
| 8.69.0.16 8u371-b03 | 8.70.0.23 8u372-b05 | ||
| 11.63.16 11.0.18.0.101+3 | 11.64.19 11.0.19+7 | ||
| 17.41.14 17.0.6.0.101+2 | 17.42.19 17.0.7+7 | ||
| — | 20.30.11 20.0.1+9 | ||
| CVE-2023-21954 Note 1: This vulnerability applies to Java deployments that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. | 5.9 | ||
| 7.61.0.18 7u381-b03 | — | ||
| 8.69.0.16 8u371-b03 | 8.70.0.23 8u372-b05 | ||
| 11.63.16 11.0.18.0.101+3 | 11.64.19 11.0.19+7 | ||
| 17.41.14 17.0.6.0.101+2 | 17.42.19 17.0.7+7 | ||
| CVE-2023-21986 This CVE is not applicable to Azul Core. It is listed here for comparison with other Java implementations which may contain this CVE. | 5.7 | — | |
January 2023 CVEs
| January 2023 | Back to Top | ||
|---|---|---|---|
| January 2023 Quarterly Update Release | |||
| Azul Zulu Build of OpenJDK | |||
| CVE | Base Score | CPU | PSU |
| CVE-2023-21843 | 3.7 | ||
| 6.53.0.12 6b153 | — | ||
| 7.59.0.18 7u371-b03 | — | ||
| 8.67.0.22 8u361-b05 | 8.68.0.19 8u362-b08 | ||
| 11.61.18 11.0.17.0.101+3 | 11.62.17 11.0.18+10 | ||
| 13.53.18 13.0.13.0.101+3 | 13.54.17 13.0.14+5 | ||
| 15.45.18 15.0.9.0.101+3 | 15.46.17 15.0.10+5 | ||
| 17.39.20 17.0.5.0.101+4 | 17.40.19 17.0.6+10 | ||
| — | 19.32.13 19.0.2+7 | ||
| CVE-2023-21835 | 5.3 | ||
| 11.61.18 11.0.17.0.101+3 | 11.62.17 11.0.18+10 | ||
| 13.53.18 13.0.13.0.101+3 | 13.54.17 13.0.14+5 | ||
| 15.45.18 15.0.9.0.101+3 | 15.46.17 15.0.10+5 | ||
| 17.39.20 17.0.5.0.101+4 | 17.40.19 17.0.6+10 | ||
| — | 19.32.13 19.0.2+7 | ||
| CVE-2023-21830 | 5.3 | ||
| 6.53.0.12 6b153 | — | ||
| 7.59.0.18 7u371-b03 | — | ||
| 8.67.0.22 8u361-b05 | 8.68.0.19 8u362-b08 | ||
| CVE-2022-43548 This CVE is not applicable to Azul Core. It is listed here for comparison with other Java implementations which may contain this CVE. | 8.1 | — | |
October 2022 CVEs
| October 2022 | Back to Top | ||
|---|---|---|---|
| October 2022 Quarterly Update Release | |||
| Azul Zulu Build of OpenJDK | |||
| CVE | Base Score | CPU | PSU |
| CVE-2022-21624 Note 2: This vulnerability applies to Java deployments that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. | 3.7 | ||
| 6.51.0.12 6b151 | — | ||
| 7.57.0.14 7u361-b02 | — | ||
| 8.65.0.14 8u351-b02 | 8.66.0.15 8u352-b08 | ||
| 11.59.16 11.0.16.1.101+3 | 11.60.19 11.0.17+8 | ||
| 13.51.14 13.0.12.0.101+2 | 13.52.15 13.0.13+5 | ||
| 15.43.14 15.0.8.0.101+2 | 15.44.13 15.0.9+5 | ||
| 17.37.14 17.0.4.1.101+2 | 17.38.21 17.0.5+8 | ||
| — | 19.30.11 19.0.1+10 | ||
| CVE-2022-21628 Note 1: This vulnerability applies to Java deployments that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). | 5.3 | ||
| 6.51.0.12 6b151 | — | ||
| 7.57.0.14 7u361-b02 | — | ||
| 8.65.0.14 8u351-b02 | 8.66.0.15 8u352-b08 | ||
| 11.59.16 11.0.16.1.101+3 | 11.60.19 11.0.17+8 | ||
| 13.51.14 13.0.12.0.101+2 | 13.52.15 13.0.13+5 | ||
| 15.43.14 15.0.8.0.101+2 | 15.44.13 15.0.9+5 | ||
| 17.37.14 17.0.4.1.101+2 | 17.38.21 17.0.5+8 | ||
| — | 19.30.11 19.0.1+10 | ||
| CVE-2022-21619 Note 2: This vulnerability applies to Java deployments that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. | 3.7 | ||
| 7.57.0.14 7u361-b02 | — | ||
| 8.65.0.14 8u351-b02 | 8.66.0.15 8u352-b08 | ||
| 11.59.16 11.0.16.1.101+3 | 11.60.19 11.0.17+8 | ||
| 13.51.14 13.0.12.0.101+2 | 13.52.15 13.0.13+5 | ||
| 15.43.14 15.0.8.0.101+2 | 15.44.13 15.0.9+5 | ||
| 17.37.14 17.0.4.1.101+2 | 17.38.21 17.0.5+8 | ||
| — | 19.30.11 19.0.1+10 | ||
| CVE-2022-21626 Note 2: This vulnerability applies to Java deployments that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. | 5.3 | ||
| 6.51.0.12 6b151 | — | ||
| 7.57.0.14 7u361-b02 | — | ||
| 8.65.0.14 8u351-b02 | 8.66.0.15 8u352-b08 | ||
| 11.59.16 11.0.16.1.101+3 | 11.60.19 11.0.17+8 | ||
| 13.51.14 13.0.12.0.101+2 | 13.52.15 13.0.13+5 | ||
| 15.43.14 15.0.8.0.101+2 | 15.44.13 15.0.9+5 | ||
| CVE-2022-21618 Note 2: This vulnerability applies to Java deployments that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. | 5.3 | ||
| 11.59.16 11.0.16.1.101+3 | 11.60.19 11.0.17+8 | ||
| 13.51.14 13.0.12.0.101+2 | 13.52.15 13.0.13+5 | ||
| 15.43.14 15.0.8.0.101+2 | 15.44.13 15.0.9+5 | ||
| 17.37.14 17.0.4.1.101+2 | 17.38.21 17.0.5+8 | ||
| — | 19.30.11 19.0.1+10 | ||
| CVE-2022-39399 Note 1: This vulnerability applies to Java deployments that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). | 3.7 | ||
| 11.59.16 11.0.16.1.101+3 | 11.60.19 11.0.17+8 | ||
| 13.51.14 13.0.12.0.101+2 | 13.52.15 13.0.13+5 | ||
| 15.43.14 15.0.8.0.101+2 | 15.44.13 15.0.9+5 | ||
| 17.37.14 17.0.4.1.101+2 | 17.38.21 17.0.5+8 | ||
| — | 19.30.11 19.0.1+10 | ||
| CVE-2022-21597 This CVE is not applicable to Azul Core. It is listed here for comparison with other Java implementations which may contain this CVE. | 5.3 | — | |
| CVE-2022-21634 This CVE is not applicable to Azul Core. It is listed here for comparison with other Java implementations which may contain this CVE. | 7.5 | — | |
| CVE-2022-32215 This CVE is not applicable to Azul Core. It is listed here for comparison with other Java implementations which may contain this CVE. | 9.1 | — | |
July 2022 CVEs
| July 2022 | Back to Top | ||
|---|---|---|---|
| July 2022 Quarterly Update Release | |||
| Azul Zulu Build of OpenJDK | |||
| CVE | Base Score | CPU | PSU |
| CVE-2022-21540 Note 1: This vulnerability applies to Java deployments that load and run untrusted code (e.g., code that comes from the internet) and relies on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. | 5.3 | ||
| 6.49 6b149 | — | ||
| 7.55 7u351-b02 | 7.56 7u352-b01 | ||
| 8.63 8u341-b03 | 8.64 8u342-b07 | ||
| 11.57 11.0.15.0.101+3 | 11.58 11.0.16+8 | ||
| 13.49 13.0.11.0.101+2 | 13.50 13.0.12+4 | ||
| 15.41 15.0.7.0.101+2 | 15.42 15.0.8+4 | ||
| 17.35 17.0.3.0.101+2 | 17.36 17.0.4+8 | ||
| — | 18.32 18.0.2+9 | ||
| CVE-2022-34169 Note 1: This vulnerability applies to Java deployments that load and run untrusted code (e.g., code that comes from the internet) and relies on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. | 7.5 | ||
| 6.49 6b149 | — | ||
| 7.55 7u351-b02 | 7.56 7u352-b01 | ||
| 8.63 8u341-b03 | 8.64 8u342-b07 | ||
| 11.57 11.0.15.0.101+3 | 11.58 11.0.16+8 | ||
| 13.49 13.0.11.0.101+2 | 13.50 13.0.12+4 | ||
| 15.41 15.0.7.0.101+2 | 15.42 15.0.8+4 | ||
| 17.35 17.0.3.0.101+2 | 17.36 17.0.4+8 | ||
| — | 18.32 18.0.2+9 | ||
| CVE-2022-21541 Note 1: This vulnerability applies to Java deployments that load and run untrusted code (e.g., code that comes from the internet) and relies on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. | 5.9 | ||
| 7.55 7u351-b02 | 7.56 7u352-b01 | ||
| 8.63 8u341-b03 | 8.64 8u342-b07 | ||
| 11.57 11.0.15.0.101+3 | 11.58 11.0.16+8 | ||
| 13.49 13.0.11.0.101+2 | 13.50 13.0.12+4 | ||
| 15.41 15.0.7.0.101+2 | 15.42 15.0.8+4 | ||
| 17.35 17.0.3.0.101+2 | 17.36 17.0.4+8 | ||
| — | 18.32 18.0.2+9 | ||
| CVE-2022-21549 Note 1: This vulnerability applies to Java deployments that load and run untrusted code (e.g., code that comes from the internet) and relies on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. | 5.3 | ||
| 17.35 17.0.3.0.101+2 | 17.36 17.0.4+8 | ||
| CVE-2022-25647 This CVE is not applicable to Azul Core. It is listed here for comparison with other Java implementations which may contain this CVE. | 6.2 | — | |
April 2022 CVEs
| April 2022 | Back to Top | ||
|---|---|---|---|
| April 2022 Quarterly Update Release | |||
| Azul Zulu Build of OpenJDK | |||
| CVE | Base Score | CPU | PSU |
| CVE-2022-21426 Note 1: This vulnerability applies to Java deployments, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. | 5.3 | ||
| 6.47 6b147 | — | ||
| 7.53 7u341-b03 | 7.54 7u342-b01 | ||
| 8.61 8u331-b04 | 8.62 8u332-b09 | ||
| 11.55 11.0.14.1.101+4 | 11.56 11.0.15+10 | ||
| 13.47 13.0.10.0.101+3 | 13.48 13.0.11+4 | ||
| 15.39 15.0.6.0.101+3 | 15.40 15.0.7+4 | ||
| 17.33 17.0.2.0.101+1 | 17.34 17.0.3+7 | ||
| — | 18.30 18.0.1+10 | ||
| CVE-2022-21434 Note 1: This vulnerability applies to Java deployments, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. | 5.3 | ||
| 6.47 6b147 | — | ||
| 7.53 7u341-b03 | 7.54 7u342-b01 | ||
| 8.61 8u331-b04 | 8.62 8u332-b09 | ||
| 11.55 11.0.14.1.101+4 | 11.56 11.0.15+10 | ||
| 13.47 13.0.10.0.101+3 | 13.48 13.0.11+4 | ||
| 15.39 15.0.6.0.101+3 | 15.40 15.0.7+4 | ||
| 17.33 17.0.2.0.101+1 | 17.34 17.0.3+7 | ||
| — | 18.30 18.0.1+10 | ||
| CVE-2022-21443 Note 1: This vulnerability applies to Java deployments, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. | 3.7 | ||
| 6.47 6b147 | — | ||
| 7.53 7u341-b03 | 7.54 7u342-b01 | ||
| 8.61 8u331-b04 | 8.62 8u332-b09 | ||
| 11.55 11.0.14.1.101+4 | 11.56 11.0.15+10 | ||
| 13.47 13.0.10.0.101+3 | 13.48 13.0.11+4 | ||
| 15.39 15.0.6.0.101+3 | 15.40 15.0.7+4 | ||
| 17.33 17.0.2.0.101+1 | 17.34 17.0.3+7 | ||
| — | 18.30 18.0.1+10 | ||
| CVE-2022-21496 Note 1: This vulnerability applies to Java deployments, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. | 5.3 | ||
| 6.47 6b147 | — | ||
| 7.53 7u341-b03 | 7.54 7u342-b01 | ||
| 8.61 8u331-b04 | 8.62 8u332-b09 | ||
| 11.55 11.0.14.1.101+4 | 11.56 11.0.15+10 | ||
| 13.47 13.0.10.0.101+3 | 13.48 13.0.11+4 | ||
| 15.39 15.0.6.0.101+3 | 15.40 15.0.7+4 | ||
| 17.33 17.0.2.0.101+1 | 17.34 17.0.3+7 | ||
| — | 18.30 18.0.1+10 | ||
| CVE-2018-25032 Note 2: Our analysis shows that Azul Zulu and OpenJDK are not affected by CVE-2018-25032. In OpenJDK, the Zlib "memLevel" parameter is always set to 8 and can not be changed by a Java code, and the Z_FIXED strategy is permanently disabled. The CVE does not apply to Azul Zulu and OpenJDK with these settings. However, Azul decided to include the corresponding patch to the Zlib library in Azul products just in case someone chooses to use Zlib from Azul Zulu outside of Java applications. | 7.5 | ||
| 6.47 6b147 | — | ||
| 7.53 7u341-b03 | 7.54 7u342-b01 | ||
| 8.61 8u331-b04 | 8.62 8u332-b09 | ||
| 11.55 11.0.14.1.101+4 | 11.56 11.0.15+10 | ||
| 13.47 13.0.10.0.101+3 | 13.48 13.0.11+4 | ||
| 15.39 15.0.6.0.101+3 | 15.40 15.0.7+4 | ||
| 17.33 17.0.2.0.101+1 | 17.34 17.0.3+7 | ||
| CVE-2022-21476 Note 1: This vulnerability applies to Java deployments, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. | 7.5 | ||
| 7.53 7u341-b03 | 7.54 7u342-b01 | ||
| 8.61 8u331-b04 | 8.62 8u332-b09 | ||
| 11.55 11.0.14.1.101+4 | 11.56 11.0.15+10 | ||
| 13.47 13.0.10.0.101+3 | 13.48 13.0.11+4 | ||
| 15.39 15.0.6.0.101+3 | 15.40 15.0.7+4 | ||
| 17.33 17.0.2.0.101+1 | 17.34 17.0.3+7 | ||
| CVE-2022-21449 Note 1: This vulnerability applies to Java deployments, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. | 7.5 | ||
| 15.39 15.0.6.0.101+3 | 15.40 15.0.7+4 | ||
| 17.33 17.0.2.0.101+1 | 17.34 17.0.3+7 | ||
| — | 18.30 18.0.1+10 | ||
| CVE-2022-0778 This CVE is not applicable to Azul Core. It is listed here for comparison with other Java implementations which may contain this CVE. | 7.5 | — | |
January 2022 CVEs
| January 2022 | Back to Top | ||
|---|---|---|---|
| January 2022 Quarterly Update Release | |||
| Azul Zulu Build of OpenJDK | |||
| CVE | Base Score | CPU | PSU |
| CVE-2022-21248 Note 1: This vulnerability applies to Java deployments, typically in clients running sandboxed Java applications, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. | 3.7 | ||
| 6.45 6b145 | — | ||
| 7.51 7u331-b01 | 7.52 7u332-b01 | ||
| 8.59 8u321-b01 | 8.60 8u322-b06 | ||
| 11.53 11.0.13.0.101+2 | 11.54 11.0.14+9 | ||
| 13.45 13.0.9.0.101+1 | 13.46 13.0.10+5 | ||
| 15.37 15.0.5.0.101+2 | 15.38 15.0.6+5 | ||
| — | 17.32 17.0.2+8 | ||
| CVE-2022-21283 Note 1: This vulnerability applies to Java deployments, typically in clients running sandboxed Java applications, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. | 5.3 | ||
| 6.45 6b145 | — | ||
| 7.51 7u331-b01 | 7.52 7u332-b01 | ||
| 8.59 8u321-b01 | 8.60 8u322-b06 | ||
| 11.53 11.0.13.0.101+2 | 11.54 11.0.14+9 | ||
| 13.45 13.0.9.0.101+1 | 13.46 13.0.10+5 | ||
| 15.37 15.0.5.0.101+2 | 15.38 15.0.6+5 | ||
| — | 17.32 17.0.2+8 | ||
| CVE-2022-21293 Note 1: This vulnerability applies to Java deployments, typically in clients running sandboxed Java applications, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. | 5.3 | ||
| 6.45 6b145 | — | ||
| 7.51 7u331-b01 | 7.52 7u332-b01 | ||
| 8.59 8u321-b01 | 8.60 8u322-b06 | ||
| 11.53 11.0.13.0.101+2 | 11.54 11.0.14+9 | ||
| 13.45 13.0.9.0.101+1 | 13.46 13.0.10+5 | ||
| 15.37 15.0.5.0.101+2 | 15.38 15.0.6+5 | ||
| — | 17.32 17.0.2+8 | ||
| CVE-2022-21294 Note 1: This vulnerability applies to Java deployments, typically in clients running sandboxed Java applications, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. | 5.3 | ||
| 6.45 6b145 | — | ||
| 7.51 7u331-b01 | 7.52 7u332-b01 | ||
| 8.59 8u321-b01 | 8.60 8u322-b06 | ||
| 11.53 11.0.13.0.101+2 | 11.54 11.0.14+9 | ||
| 13.45 13.0.9.0.101+1 | 13.46 13.0.10+5 | ||
| 15.37 15.0.5.0.101+2 | 15.38 15.0.6+5 | ||
| — | 17.32 17.0.2+8 | ||
| CVE-2022-21299 Note 1: This vulnerability applies to Java deployments, typically in clients running sandboxed Java applications, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. | 5.3 | ||
| 6.45 6b145 | — | ||
| 7.51 7u331-b01 | 7.52 7u332-b01 | ||
| 8.59 8u321-b01 | 8.60 8u322-b06 | ||
| 11.53 11.0.13.0.101+2 | 11.54 11.0.14+9 | ||
| 13.45 13.0.9.0.101+1 | 13.46 13.0.10+5 | ||
| 15.37 15.0.5.0.101+2 | 15.38 15.0.6+5 | ||
| — | 17.32 17.0.2+8 | ||
| CVE-2022-21305 Note 1: This vulnerability applies to Java deployments, typically in clients running sandboxed Java applications, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. | 5.3 | ||
| 6.45 6b145 | — | ||
| 7.51 7u331-b01 | 7.52 7u332-b01 | ||
| 8.59 8u321-b01 | 8.60 8u322-b06 | ||
| 11.53 11.0.13.0.101+2 | 11.54 11.0.14+9 | ||
| 13.45 13.0.9.0.101+1 | 13.46 13.0.10+5 | ||
| 15.37 15.0.5.0.101+2 | 15.38 15.0.6+5 | ||
| — | 17.32 17.0.2+8 | ||
| CVE-2022-21340 Note 1: This vulnerability applies to Java deployments, typically in clients running sandboxed Java applications, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. | 5.3 | ||
| 6.45 6b145 | — | ||
| 7.51 7u331-b01 | 7.52 7u332-b01 | ||
| 8.59 8u321-b01 | 8.60 8u322-b06 | ||
| 11.53 11.0.13.0.101+2 | 11.54 11.0.14+9 | ||
| 13.45 13.0.9.0.101+1 | 13.46 13.0.10+5 | ||
| 15.37 15.0.5.0.101+2 | 15.38 15.0.6+5 | ||
| — | 17.32 17.0.2+8 | ||
| CVE-2022-21341 Note 1: This vulnerability applies to Java deployments, typically in clients running sandboxed Java applications, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. | 5.3 | ||
| 6.45 6b145 | — | ||
| 7.51 7u331-b01 | 7.52 7u332-b01 | ||
| 8.59 8u321-b01 | 8.60 8u322-b06 | ||
| 11.53 11.0.13.0.101+2 | 11.54 11.0.14+9 | ||
| 13.45 13.0.9.0.101+1 | 13.46 13.0.10+5 | ||
| 15.37 15.0.5.0.101+2 | 15.38 15.0.6+5 | ||
| — | 17.32 17.0.2+8 | ||
| CVE-2022-21360 Note 1: This vulnerability applies to Java deployments, typically in clients running sandboxed Java applications, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. | 5.3 | ||
| 6.45 6b145 | — | ||
| 7.51 7u331-b01 | 7.52 7u332-b01 | ||
| 8.59 8u321-b01 | 8.60 8u322-b06 | ||
| 11.53 11.0.13.0.101+2 | 11.54 11.0.14+9 | ||
| 13.45 13.0.9.0.101+1 | 13.46 13.0.10+5 | ||
| 15.37 15.0.5.0.101+2 | 15.38 15.0.6+5 | ||
| — | 17.32 17.0.2+8 | ||
| CVE-2022-21365 Note 1: This vulnerability applies to Java deployments, typically in clients running sandboxed Java applications, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. | 5.3 | ||
| 6.45 6b145 | — | ||
| 7.51 7u331-b01 | 7.52 7u332-b01 | ||
| 8.59 8u321-b01 | 8.60 8u322-b06 | ||
| 11.53 11.0.13.0.101+2 | 11.54 11.0.14+9 | ||
| 13.45 13.0.9.0.101+1 | 13.46 13.0.10+5 | ||
| 15.37 15.0.5.0.101+2 | 15.38 15.0.6+5 | ||
| — | 17.32 17.0.2+8 | ||
| CVE-2022-21282 Note 1: This vulnerability applies to Java deployments, typically in clients running sandboxed Java applications, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. | 5.3 | ||
| 7.51 7u331-b01 | 7.52 7u332-b01 | ||
| 8.59 8u321-b01 | 8.60 8u322-b06 | ||
| 11.53 11.0.13.0.101+2 | 11.54 11.0.14+9 | ||
| 13.45 13.0.9.0.101+1 | 13.46 13.0.10+5 | ||
| 15.37 15.0.5.0.101+2 | 15.38 15.0.6+5 | ||
| — | 17.32 17.0.2+8 | ||
| CVE-2022-21296 Note 1: This vulnerability applies to Java deployments, typically in clients running sandboxed Java applications, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. | 5.3 | ||
| 7.51 7u331-b01 | 7.52 7u332-b01 | ||
| 8.59 8u321-b01 | 8.60 8u322-b06 | ||
| 11.53 11.0.13.0.101+2 | 11.54 11.0.14+9 | ||
| 13.45 13.0.9.0.101+1 | 13.46 13.0.10+5 | ||
| 15.37 15.0.5.0.101+2 | 15.38 15.0.6+5 | ||
| — | 17.32 17.0.2+8 | ||
| CVE-2022-21277 Note 1: This vulnerability applies to Java deployments, typically in clients running sandboxed Java applications, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. | 5.3 | ||
| 11.53 11.0.13.0.101+2 | 11.54 11.0.14+9 | ||
| 13.45 13.0.9.0.101+1 | 13.46 13.0.10+5 | ||
| 15.37 15.0.5.0.101+2 | 15.38 15.0.6+5 | ||
| — | 17.32 17.0.2+8 | ||
| CVE-2022-21291 Note 1: This vulnerability applies to Java deployments, typically in clients running sandboxed Java applications, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. | 5.3 | ||
| 11.53 11.0.13.0.101+2 | 11.54 11.0.14+9 | ||
| 13.45 13.0.9.0.101+1 | 13.46 13.0.10+5 | ||
| 15.37 15.0.5.0.101+2 | 15.38 15.0.6+5 | ||
| — | 17.32 17.0.2+8 | ||
| CVE-2022-21366 Note 1: This vulnerability applies to Java deployments, typically in clients running sandboxed Java applications, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. | 5.3 | ||
| 11.53 11.0.13.0.101+2 | 11.54 11.0.14+9 | ||
| 13.45 13.0.9.0.101+1 | 13.46 13.0.10+5 | ||
| 15.37 15.0.5.0.101+2 | 15.38 15.0.6+5 | ||
| — | 17.32 17.0.2+8 | ||
| CVE-2022-21349 Note 1: This vulnerability applies to Java deployments, typically in clients running sandboxed Java applications, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. | 5.3 | ||
| 7.51 7u331-b01 | 7.52 7u332-b01 | ||
| 8.59 8u321-b01 | 8.60 8u322-b06 | ||
| CVE-2022-21271 This CVE is not applicable to Azul Core. It is listed here for comparison with other Java implementations which may contain this CVE. Note 1: This vulnerability applies to Java deployments, typically in clients running sandboxed Java applications, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. | 5.3 | — | |
| CVE-2021-22959 This CVE is not applicable to Azul Core. It is listed here for comparison with other Java implementations which may contain this CVE. | 6.5 | — | |
October 2021 CVEs
| October 2021 | Back to Top | ||
|---|---|---|---|
| October 2021 Quarterly Update Release | |||
| Azul Zulu Build of OpenJDK | |||
| CVE | Base Score | CPU | PSU |
| CVE-2021-35556 Note 1: This vulnerability applies to Java deployments that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). | 5.3 | ||
| 6.43 6u143 | — | ||
| 7.49 7u321-b01 | 7.50 7u322-b01 | ||
| 8.57 8u311-b02 | 8.58 8u312-b07 | ||
| 11.51 11.0.12.0.101+2 | 11.52 11.0.13+8 | ||
| 13.43 13.0.8.0.101+1 | 13.44 13.0.9+3 | ||
| 15.35 15.0.4.0.101+1 | 15.36 15.0.5+3 | ||
| — | 17.30 17.0.1+12 | ||
| CVE-2021-35559 Note 2: This vulnerability applies to Java deployments that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. | 5.3 | ||
| 6.43 6u143 | — | ||
| 7.49 7u321-b01 | 7.50 7u322-b01 | ||
| 8.57 8u311-b02 | 8.58 8u312-b07 | ||
| 11.51 11.0.12.0.101+2 | 11.52 11.0.13+8 | ||
| 13.43 13.0.8.0.101+1 | 13.44 13.0.9+3 | ||
| 15.35 15.0.4.0.101+1 | 15.36 15.0.5+3 | ||
| — | 17.30 17.0.1+12 | ||
| CVE-2021-35561 Note 2: This vulnerability applies to Java deployments that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. | 5.3 | ||
| 6.43 6u143 | — | ||
| 7.49 7u321-b01 | 7.50 7u322-b01 | ||
| 8.57 8u311-b02 | 8.58 8u312-b07 | ||
| 11.51 11.0.12.0.101+2 | 11.52 11.0.13+8 | ||
| 13.43 13.0.8.0.101+1 | 13.44 13.0.9+3 | ||
| 15.35 15.0.4.0.101+1 | 15.36 15.0.5+3 | ||
| — | 17.30 17.0.1+12 | ||
| CVE-2021-35564 Note 2: This vulnerability applies to Java deployments that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. | 5.3 | ||
| 6.43 6u143 | — | ||
| 7.49 7u321-b01 | 7.50 7u322-b01 | ||
| 8.57 8u311-b02 | 8.58 8u312-b07 | ||
| 11.51 11.0.12.0.101+2 | 11.52 11.0.13+8 | ||
| 13.43 13.0.8.0.101+1 | 13.44 13.0.9+3 | ||
| 15.35 15.0.4.0.101+1 | 15.36 15.0.5+3 | ||
| — | 17.30 17.0.1+12 | ||
| CVE-2021-35586 Note 2: This vulnerability applies to Java deployments that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. | 5.3 | ||
| 6.43 6u143 | — | ||
| 7.49 7u321-b01 | 7.50 7u322-b01 | ||
| 8.57 8u311-b02 | 8.58 8u312-b07 | ||
| 11.51 11.0.12.0.101+2 | 11.52 11.0.13+8 | ||
| 13.43 13.0.8.0.101+1 | 13.44 13.0.9+3 | ||
| 15.35 15.0.4.0.101+1 | 15.36 15.0.5+3 | ||
| — | 17.30 17.0.1+12 | ||
| CVE-2021-35603 Note 2: This vulnerability applies to Java deployments that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. | 3.7 | ||
| 6.43 6u143 | — | ||
| 7.49 7u321-b01 | 7.50 7u322-b01 | ||
| 8.57 8u311-b02 | 8.58 8u312-b07 | ||
| 11.51 11.0.12.0.101+2 | 11.52 11.0.13+8 | ||
| 13.43 13.0.8.0.101+1 | 13.44 13.0.9+3 | ||
| 15.35 15.0.4.0.101+1 | 15.36 15.0.5+3 | ||
| — | 17.30 17.0.1+12 | ||
| CVE-2021-35565 Note 3: This vulnerability can only be exploited by supplying data to APIs in the specified Component without using Untrusted applications, such as through a web service. | 5.3 | ||
| 6.43 6u143 | — | ||
| 7.49 7u321-b01 | 7.50 7u322-b01 | ||
| 8.57 8u311-b02 | 8.58 8u312-b07 | ||
| 11.51 11.0.12.0.101+2 | 11.52 11.0.13+8 | ||
| 13.43 13.0.8.0.101+1 | 13.44 13.0.9+3 | ||
| 15.35 15.0.4.0.101+1 | 15.36 15.0.5+3 | ||
| CVE-2021-3517 Note 1: This vulnerability applies to Java deployments that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). | 8.6 | ||
| 8.57 8u311-b02 | 8.58 8u312-b07 | ||
| 11.51 11.0.12.0.101+2 | 11.52 11.0.13+8 | ||
| 13.43 13.0.8.0.101+1 | 13.44 13.0.9+3 | ||
| 15.35 15.0.4.0.101+1 | 15.36 15.0.5+3 | ||
| — | 17.30 17.0.1+12 | ||
| CVE-2021-3522 Note 1: This vulnerability applies to Java deployments that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). | 5.5 | ||
| 8.57 8u311-b02 | 8.58 8u312-b07 | ||
| 11.51 11.0.12.0.101+2 | 11.52 11.0.13+8 | ||
| 13.43 13.0.8.0.101+1 | 13.44 13.0.9+3 | ||
| 15.35 15.0.4.0.101+1 | 15.36 15.0.5+3 | ||
| — | 17.30 17.0.1+12 | ||
| CVE-2021-35567 Note 2: This vulnerability applies to Java deployments that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. | 6.8 | ||
| 8.57 8u311-b02 | 8.58 8u312-b07 | ||
| 11.51 11.0.12.0.101+2 | 11.52 11.0.13+8 | ||
| 13.43 13.0.8.0.101+1 | 13.44 13.0.9+3 | ||
| 15.35 15.0.4.0.101+1 | 15.36 15.0.5+3 | ||
| — | 17.30 17.0.1+12 | ||
| CVE-2021-35578 Note 3: This vulnerability can only be exploited by supplying data to APIs in the specified Component without using Untrusted applications, such as through a web service. | 5.3 | ||
| 8.57 8u311-b02 | 8.58 8u312-b07 | ||
| 11.51 11.0.12.0.101+2 | 11.52 11.0.13+8 | ||
| 13.43 13.0.8.0.101+1 | 13.44 13.0.9+3 | ||
| 15.35 15.0.4.0.101+1 | 15.36 15.0.5+3 | ||
| — | 17.30 17.0.1+12 | ||
| CVE-2021-35550 Note 2: This vulnerability applies to Java deployments that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. | 5.9 | ||
| 6.43 6u143 | — | ||
| 7.49 7u321-b01 | 7.50 7u322-b01 | ||
| 8.57 8u311-b02 | 8.58 8u312-b07 | ||
| 11.51 11.0.12.0.101+2 | 11.52 11.0.13+8 | ||
| CVE-2021-35588 Note 2: This vulnerability applies to Java deployments that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. | 3.1 | ||
| 6.43 6u143 | — | ||
| 7.49 7u321-b01 | 7.50 7u322-b01 | ||
| 8.57 8u311-b02 | 8.58 8u312-b07 | ||
| CVE-2021-27290 This CVE is not applicable to Azul Core. It is listed here for comparison with other Java implementations which may contain this CVE. | 7.5 | — | |
| CVE-2021-35560 This CVE is not applicable to Azul Core. It is listed here for comparison with other Java implementations which may contain this CVE. Note 1: This vulnerability applies to Java deployments that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). | 7.5 | — | |
July 2021 CVEs
| July 2021 | Back to Top | ||
|---|---|---|---|
| July 2021 Quarterly Update Release | |||
| Azul Zulu Build of OpenJDK | |||
| CVE | Base Score | CPU | PSU |
| CVE-2021-2341 Note 1: This vulnerability applies to Java deployments that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). | 3.1 | ||
| 6.41 6u141 | — | ||
| 7.47 7u311-b02 | 7.48 7u312-b01 | ||
| 8.55 8u301-b02 | 8.56 8u302-b08 | ||
| 11.49 11.0.11.0.101+2 | 11.50 11.0.12+7 | ||
| 13.41 13.0.7.0.101+1 | 13.42 13.0.8+5 | ||
| 15.33 15.0.3.0.101+1 | 15.34 15.0.4+5 | ||
| — | 16.32 16.0.2+7 | ||
| CVE-2021-2369 Note 1: This vulnerability applies to Java deployments that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). | 4.3 | ||
| 6.41 6u141 | — | ||
| 7.47 7u311-b02 | 7.48 7u312-b01 | ||
| 8.55 8u301-b02 | 8.56 8u302-b08 | ||
| 11.49 11.0.11.0.101+2 | 11.50 11.0.12+7 | ||
| 13.41 13.0.7.0.101+1 | 13.42 13.0.8+5 | ||
| 15.33 15.0.3.0.101+1 | 15.34 15.0.4+5 | ||
| — | 16.32 16.0.2+7 | ||
| CVE-2021-2388 Note 1: This vulnerability applies to Java deployments that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). | 7.5 | ||
| 8.55 8u301-b02 | 8.56 8u302-b08 | ||
| 11.49 11.0.11.0.101+2 | 11.50 11.0.12+7 | ||
| 13.41 13.0.7.0.101+1 | 13.42 13.0.8+5 | ||
| 15.33 15.0.3.0.101+1 | 15.34 15.0.4+5 | ||
| — | 16.32 16.0.2+7 | ||
| CVE-2021-2432 Note 2: This vulnerability applies to Java deployments that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. | 3.7 | ||
| 6.41 6u141 | — | ||
| 7.47 7u311-b02 | 7.48 7u312-b01 | ||
| CVE-2020-28928 This CVE is not applicable to Azul Core. It is listed here for comparison with other Java implementations which may contain this CVE. | 5.5 | — | |
| CVE-2021-29921 This CVE is not applicable to Azul Core. It is listed here for comparison with other Java implementations which may contain this CVE. | 9.8 | — | |
April 2021 CVEs
| April 2021 | Back to Top | ||
|---|---|---|---|
| April 2021 Quarterly Update Release | |||
| Azul Zulu Build of OpenJDK | |||
| CVE | Base Score | CPU | PSU |
| CVE-2021-2161 Note 1: This vulnerability applies to Java deployments that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. It can also be exploited by supplying untrusted data to APIs in the specified Component. | 5.9 | ||
| 6.39 6u139 | — | ||
| 7.45 7u301-b01 | 7.46 7u302-b01 | ||
| 8.53 8u291-b01 | 8.54 8u292-b10 | ||
| 11.47 11.0.10.0.101+1 | 11.48 11.0.11+9 | ||
| 13.39 13.0.6.0.101+2 | 13.40 13.0.7+5 | ||
| 15.31 15.0.2.0.101+2 | 15.32 15.0.3+3 | ||
| — | 16.30 16.0.1+9 | ||
| CVE-2021-2163 Note 2: This vulnerability applies to Java deployments that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. | 5.3 | ||
| 6.39 6u139 | — | ||
| 7.45 7u301-b01 | 7.46 7u302-b01 | ||
| 8.53 8u291-b01 | 8.54 8u292-b10 | ||
| 11.47 11.0.10.0.101+1 | 11.48 11.0.11+9 | ||
| 13.39 13.0.6.0.101+2 | 13.40 13.0.7+5 | ||
| 15.31 15.0.2.0.101+2 | 15.32 15.0.3+3 | ||
| — | 16.30 16.0.1+9 | ||
| CVE-2021-3450 This CVE is not applicable to Azul Core. It is listed here for comparison with other Java implementations which may contain this CVE. | 7.4 | — | |
| CVE-2021-23841 This CVE is not applicable to Azul Core. It is listed here for comparison with other Java implementations which may contain this CVE. | 7.5 | — | |
January 2021 CVEs
| January 2021 | Back to Top | ||
|---|---|---|---|
| January 2021 Quarterly Update Release | |||
| Azul Zulu Build of OpenJDK | |||
| CVE | Base Score | CPU | PSU |
| CVE-2020-14803 Note 1: This vulnerability applies to Java deployments that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. | 5.3 | ||
| 6.38 6u138 | — | ||
| 7.43 7u291-b07 | 7.44 7u292-b07 | ||
| 8.51 8u281-b07 | 8.52 8u282-b08 | ||
| 11.44 11.0.9.1.101+5 | 11.45 11.0.10+7 | ||
| 13.36 13.0.5.1.101+5 | 13.37 13.0.6+3 | ||
| — | 15.29 15.0.2+7 | ||
October 2020 CVEs
| October 2020 | Back to Top | ||
|---|---|---|---|
| October 2020 Quarterly Update Release | |||
| Azul Zulu Build of OpenJDK | |||
| CVE | Base Score | CPU | PSU |
| CVE-2020-14779 Note 2: This vulnerability applies to client and server deployment of Java. This vulnerability can be exploited through untrusted code executed under Java sandbox restrictions. It can also be exploited by supplying data to APIs in the specified Component without using untrusted code executed under Java sandbox restrictions, such as through a web service. | 3.7 | ||
| 6.36 6u136 | — | ||
| 7.41 7u281-b07 | 7.42 7u282-b10 | ||
| 8.49 8u271-b09 | 8.50 8u272-b17 | ||
| 11.42 11.0.8.0.101+5 | 11.43 11.0.9+11 | ||
| 13.34 13.0.4.0.101+5 | 13.35 13.0.5+3 | ||
| — | 15.28 15.0.1+8 | ||
| CVE-2020-14781 Note 2: This vulnerability applies to client and server deployment of Java. This vulnerability can be exploited through untrusted code executed under Java sandbox restrictions. It can also be exploited by supplying data to APIs in the specified Component without using untrusted code executed under Java sandbox restrictions, such as through a web service. | 3.7 | ||
| 6.36 6u136 | — | ||
| 7.41 7u281-b07 | 7.42 7u282-b10 | ||
| 8.49 8u271-b09 | 8.50 8u272-b17 | ||
| 11.42 11.0.8.0.101+5 | 11.43 11.0.9+11 | ||
| 13.34 13.0.4.0.101+5 | 13.35 13.0.5+3 | ||
| — | 15.28 15.0.1+8 | ||
| CVE-2020-14792 Note 2: This vulnerability applies to client and server deployment of Java. This vulnerability can be exploited through untrusted code executed under Java sandbox restrictions. It can also be exploited by supplying data to APIs in the specified Component without using untrusted code executed under Java sandbox restrictions, such as through a web service. | 4.2 | ||
| 6.36 6u136 | — | ||
| 7.41 7u281-b07 | 7.42 7u282-b10 | ||
| 8.49 8u271-b09 | 8.50 8u272-b17 | ||
| 11.42 11.0.8.0.101+5 | 11.43 11.0.9+11 | ||
| 13.34 13.0.4.0.101+5 | 13.35 13.0.5+3 | ||
| — | 15.28 15.0.1+8 | ||
| CVE-2020-14803 Note 1: This vulnerability applies to Java deployments that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). | 5.3 | ||
| 6.36 6u136 | — | ||
| 7.41 7u281-b07 | 7.42 7u282-b10 | ||
| 8.49 8u271-b09 | 8.50 8u272-b17 | ||
| 11.42 11.0.8.0.101+5 | 11.43 11.0.9+11 | ||
| 13.34 13.0.4.0.101+5 | 13.35 13.0.5+3 | ||
| — | 15.28 15.0.1+8 | ||
| CVE-2020-14782 Note 2: This vulnerability applies to client and server deployment of Java. This vulnerability can be exploited through untrusted code executed under Java sandbox restrictions. It can also be exploited by supplying data to APIs in the specified Component without using untrusted code executed under Java sandbox restrictions, such as through a web service. | 3.7 | ||
| 7.41 7u281-b07 | 7.42 7u282-b10 | ||
| 8.49 8u271-b09 | 8.50 8u272-b17 | ||
| 11.42 11.0.8.0.101+5 | 11.43 11.0.9+11 | ||
| 13.34 13.0.4.0.101+5 | 13.35 13.0.5+3 | ||
| — | 15.28 15.0.1+8 | ||
| CVE-2020-14796 Note 1: This vulnerability applies to Java deployments that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). | 3.1 | ||
| 7.41 7u281-b07 | 7.42 7u282-b10 | ||
| 8.49 8u271-b09 | 8.50 8u272-b17 | ||
| 11.42 11.0.8.0.101+5 | 11.43 11.0.9+11 | ||
| 13.34 13.0.4.0.101+5 | 13.35 13.0.5+3 | ||
| — | 15.28 15.0.1+8 | ||
| CVE-2020-14797 Note 2: This vulnerability applies to client and server deployment of Java. This vulnerability can be exploited through untrusted code executed under Java sandbox restrictions. It can also be exploited by supplying data to APIs in the specified Component without using untrusted code executed under Java sandbox restrictions, such as through a web service. | 3.7 | ||
| 7.41 7u281-b07 | 7.42 7u282-b10 | ||
| 8.49 8u271-b09 | 8.50 8u272-b17 | ||
| 11.42 11.0.8.0.101+5 | 11.43 11.0.9+11 | ||
| 13.34 13.0.4.0.101+5 | 13.35 13.0.5+3 | ||
| — | 15.28 15.0.1+8 | ||
| CVE-2020-14798 Note 1: This vulnerability applies to Java deployments that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). | 3.1 | ||
| 7.41 7u281-b07 | 7.42 7u282-b10 | ||
| 8.49 8u271-b09 | 8.50 8u272-b17 | ||
| 11.42 11.0.8.0.101+5 | 11.43 11.0.9+11 | ||
| 13.34 13.0.4.0.101+5 | 13.35 13.0.5+3 | ||
| — | 15.28 15.0.1+8 | ||
July 2020 CVEs
| July 2020 | Back to Top | ||
|---|---|---|---|
| July 2020 Quarterly Update Release | |||
| Azul Zulu Build of OpenJDK | |||
| CVE | Base Score | CPU | PSU |
| CVE-2020-14577 Note 3: This vulnerability applies to client and server deployment of Java. This vulnerability can be exploited through untrusted code executed under Java sandbox restrictions. It can also be exploited by supplying data to APIs in the specified Component without using untrusted code executed under Java sandbox restrictions, such as through a web service. | 3.7 | ||
| 6.34 6u134 | — | ||
| 7.39 7u271b07 | 7.40 7u272b10 | ||
| 8.47 8u261b09 | 8.48 8u262b19 | ||
| 11.40 11.0.7.0.101+5 | 11.41 11.0.8+10 | ||
| 13.32 13.0.3.0.101+5 | 13.33 13.0.4+8 | ||
| — | 14.29 14.0.2+12 | ||
| CVE-2020-14583 Note 1: This vulnerability applies to Java deployments that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). | 8.3 | ||
| 6.34 6u134 | — | ||
| 7.39 7u271b07 | 7.40 7u272b10 | ||
| 8.47 8u261b09 | 8.48 8u262b19 | ||
| 11.40 11.0.7.0.101+5 | 11.41 11.0.8+10 | ||
| 13.32 13.0.3.0.101+5 | 13.33 13.0.4+8 | ||
| — | 14.29 14.0.2+12 | ||
| CVE-2020-14593 Note 1: This vulnerability applies to Java deployments that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). | 7.4 | ||
| 6.34 6u134 | — | ||
| 7.39 7u271b07 | 7.40 7u272b10 | ||
| 8.47 8u261b09 | 8.48 8u262b19 | ||
| 11.40 11.0.7.0.101+5 | 11.41 11.0.8+10 | ||
| 13.32 13.0.3.0.101+5 | 13.33 13.0.4+8 | ||
| — | 14.29 14.0.2+12 | ||
| CVE-2020-14621 Note 2: This vulnerability can only be exploited by supplying data to APIs in the specified Component without using untrusted code executed under Java sandbox restrictions, such as through a web service. | 5.3 | ||
| 6.34 6u134 | — | ||
| 7.39 7u271b07 | 7.40 7u272b10 | ||
| 8.47 8u261b09 | 8.48 8u262b19 | ||
| 11.40 11.0.7.0.101+5 | 11.41 11.0.8+10 | ||
| 13.32 13.0.3.0.101+5 | 13.33 13.0.4+8 | ||
| — | 14.29 14.0.2+12 | ||
| CVE-2020-14556 Note 3: This vulnerability applies to client and server deployment of Java. This vulnerability can be exploited through untrusted code executed under Java sandbox restrictions. It can also be exploited by supplying data to APIs in the specified Component without using untrusted code executed under Java sandbox restrictions, such as through a web service. | 4.8 | ||
| 8.47 8u261b09 | 8.48 8u262b19 | ||
| 11.40 11.0.7.0.101+5 | 11.41 11.0.8+10 | ||
| 13.32 13.0.3.0.101+5 | 13.33 13.0.4+8 | ||
| — | 14.29 14.0.2+12 | ||
| CVE-2020-14664 Note 1: This vulnerability applies to Java deployments that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). | 8.3 | ||
| 8.47 8u261b09 | 8.48 8u262b19 | ||
| 11.40 11.0.7.0.101+5 | 11.41 11.0.8+10 | ||
| 13.32 13.0.3.0.101+5 | 13.33 13.0.4+8 | ||
| — | 14.29 14.0.2+12 | ||
| CVE-2020-14562 Note 1: This vulnerability applies to Java deployments that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). | 5.3 | ||
| 11.40 11.0.7.0.101+5 | 11.41 11.0.8+10 | ||
| 13.32 13.0.3.0.101+5 | 13.33 13.0.4+8 | ||
| — | 14.29 14.0.2+12 | ||
| CVE-2020-14578 Note 3: This vulnerability applies to client and server deployment of Java. This vulnerability can be exploited through untrusted code executed under Java sandbox restrictions. It can also be exploited by supplying data to APIs in the specified Component without using untrusted code executed under Java sandbox restrictions, such as through a web service. | 3.7 | ||
| 6.34 6u134 | — | ||
| 7.39 7u271b07 | 7.40 7u272b10 | ||
| 8.47 8u261b09 | 8.48 8u262b19 | ||
| CVE-2020-14579 Note 3: This vulnerability applies to client and server deployment of Java. This vulnerability can be exploited through untrusted code executed under Java sandbox restrictions. It can also be exploited by supplying data to APIs in the specified Component without using untrusted code executed under Java sandbox restrictions, such as through a web service. | 3.7 | ||
| 6.34 6u134 | — | ||
| 7.39 7u271b07 | 7.40 7u272b10 | ||
| 8.47 8u261b09 | 8.48 8u262b19 | ||
| CVE-2020-14581 Note 3: This vulnerability applies to client and server deployment of Java. This vulnerability can be exploited through untrusted code executed under Java sandbox restrictions. It can also be exploited by supplying data to APIs in the specified Component without using untrusted code executed under Java sandbox restrictions, such as through a web service. | 3.7 | ||
| 11.40 11.0.7.0.101+5 | 11.41 11.0.8+10 | ||
| 13.32 13.0.3.0.101+5 | 13.33 13.0.4+8 | ||
| — | 14.29 14.0.2+12 | ||
| CVE-2020-14573 This CVE is not applicable to Azul Core. It is listed here for comparison with other Java implementations which may contain this CVE. Note 3: This vulnerability applies to client and server deployment of Java. This vulnerability can be exploited through untrusted code executed under Java sandbox restrictions. It can also be exploited by supplying data to APIs in the specified Component without using untrusted code executed under Java sandbox restrictions, such as through a web service. | 3.7 | — | |
April 2020 CVEs
| April 2020 | Back to Top | ||
|---|---|---|---|
| April 2020 Quarterly Update Release | |||
| Azul Zulu Build of OpenJDK | |||
| CVE | Base Score | CPU | PSU |
| CVE-2020-2756 Note 3: This vulnerability applies to client and server deployment of Java. This vulnerability can be exploited through untrusted code executed under Java sandbox restrictions. It can also be exploited by supplying data to APIs in the specified Component without using untrusted code executed under Java sandbox restrictions, such as through a web service. | 3.7 | ||
| 6.32 6u132 | — | ||
| 7.37 7u261b7 | 7.38 7u262b10 | ||
| 8.45 8u251b09 | 8.46 8u252b14 | ||
| 11.38 11.0.6.0.101+11 | 11.39 11.0.7+10 | ||
| 13.30 13.0.2.0.101+5 | 13.31 13.0.3+3 | ||
| — | 14.28 14.0.1+8 | ||
| CVE-2020-2757 Note 3: This vulnerability applies to client and server deployment of Java. This vulnerability can be exploited through untrusted code executed under Java sandbox restrictions. It can also be exploited by supplying data to APIs in the specified Component without using untrusted code executed under Java sandbox restrictions, such as through a web service. | 3.7 | ||
| 6.32 6u132 | — | ||
| 7.37 7u261b7 | 7.38 7u262b10 | ||
| 8.45 8u251b09 | 8.46 8u252b14 | ||
| 11.38 11.0.6.0.101+11 | 11.39 11.0.7+10 | ||
| 13.30 13.0.2.0.101+5 | 13.31 13.0.3+3 | ||
| — | 14.28 14.0.1+8 | ||
| CVE-2020-2773 Note 3: This vulnerability applies to client and server deployment of Java. This vulnerability can be exploited through untrusted code executed under Java sandbox restrictions. It can also be exploited by supplying data to APIs in the specified Component without using untrusted code executed under Java sandbox restrictions, such as through a web service. | 3.7 | ||
| 6.32 6u132 | — | ||
| 7.37 7u261b7 | 7.38 7u262b10 | ||
| 8.45 8u251b09 | 8.46 8u252b14 | ||
| 11.38 11.0.6.0.101+11 | 11.39 11.0.7+10 | ||
| 13.30 13.0.2.0.101+5 | 13.31 13.0.3+3 | ||
| — | 14.28 14.0.1+8 | ||
| CVE-2020-2781 Note 3: This vulnerability applies to client and server deployment of Java. This vulnerability can be exploited through untrusted code executed under Java sandbox restrictions. It can also be exploited by supplying data to APIs in the specified Component without using untrusted code executed under Java sandbox restrictions, such as through a web service. | 5.3 | ||
| 6.32 6u132 | — | ||
| 7.37 7u261b7 | 7.38 7u262b10 | ||
| 8.45 8u251b09 | 8.46 8u252b14 | ||
| 11.38 11.0.6.0.101+11 | 11.39 11.0.7+10 | ||
| 13.30 13.0.2.0.101+5 | 13.31 13.0.3+3 | ||
| — | 14.28 14.0.1+8 | ||
| CVE-2020-2800 Note 2: This vulnerability can only be exploited by supplying data to APIs in the specified Component without using untrusted code executed under Java sandbox restrictions, such as through a web service. | 4.8 | ||
| 6.32 6u132 | — | ||
| 7.37 7u261b7 | 7.38 7u262b10 | ||
| 8.45 8u251b09 | 8.46 8u252b14 | ||
| 11.38 11.0.6.0.101+11 | 11.39 11.0.7+10 | ||
| 13.30 13.0.2.0.101+5 | 13.31 13.0.3+3 | ||
| — | 14.28 14.0.1+8 | ||
| CVE-2020-2830 Note 3: This vulnerability applies to client and server deployment of Java. This vulnerability can be exploited through untrusted code executed under Java sandbox restrictions. It can also be exploited by supplying data to APIs in the specified Component without using untrusted code executed under Java sandbox restrictions, such as through a web service. | 5.3 | ||
| 6.32 6u132 | — | ||
| 7.37 7u261b7 | 7.38 7u262b10 | ||
| 8.45 8u251b09 | 8.46 8u252b14 | ||
| 11.38 11.0.6.0.101+11 | 11.39 11.0.7+10 | ||
| 13.30 13.0.2.0.101+5 | 13.31 13.0.3+3 | ||
| — | 14.28 14.0.1+8 | ||
| CVE-2020-2803 Note 1: This vulnerability applies to Java deployments that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). | 8.3 | ||
| 7.37 7u261b7 | 7.38 7u262b10 | ||
| 8.45 8u251b09 | 8.46 8u252b14 | ||
| 11.38 11.0.6.0.101+11 | 11.39 11.0.7+10 | ||
| 13.30 13.0.2.0.101+5 | 13.31 13.0.3+3 | ||
| — | 14.28 14.0.1+8 | ||
| CVE-2020-2805 Note 1: This vulnerability applies to Java deployments that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). | 8.3 | ||
| 7.37 7u261b7 | 7.38 7u262b10 | ||
| 8.45 8u251b09 | 8.46 8u252b14 | ||
| 11.38 11.0.6.0.101+11 | 11.39 11.0.7+10 | ||
| 13.30 13.0.2.0.101+5 | 13.31 13.0.3+3 | ||
| — | 14.28 14.0.1+8 | ||
| CVE-2020-2754 Note 3: This vulnerability applies to client and server deployment of Java. This vulnerability can be exploited through untrusted code executed under Java sandbox restrictions. It can also be exploited by supplying data to APIs in the specified Component without using untrusted code executed under Java sandbox restrictions, such as through a web service. | 3.7 | ||
| 8.45 8u251b09 | 8.46 8u252b14 | ||
| 11.38 11.0.6.0.101+11 | 11.39 11.0.7+10 | ||
| 13.30 13.0.2.0.101+5 | 13.31 13.0.3+3 | ||
| — | 14.28 14.0.1+8 | ||
| CVE-2020-2755 Note 3: This vulnerability applies to client and server deployment of Java. This vulnerability can be exploited through untrusted code executed under Java sandbox restrictions. It can also be exploited by supplying data to APIs in the specified Component without using untrusted code executed under Java sandbox restrictions, such as through a web service. | 3.7 | ||
| 8.45 8u251b09 | 8.46 8u252b14 | ||
| 11.38 11.0.6.0.101+11 | 11.39 11.0.7+10 | ||
| 13.30 13.0.2.0.101+5 | 13.31 13.0.3+3 | ||
| — | 14.28 14.0.1+8 | ||
| CVE-2020-2767 Note 3: This vulnerability applies to client and server deployment of Java. This vulnerability can be exploited through untrusted code executed under Java sandbox restrictions. It can also be exploited by supplying data to APIs in the specified Component without using untrusted code executed under Java sandbox restrictions, such as through a web service. | 4.8 | ||
| 8.45 8u251b09 | 8.46 8u252b14 | ||
| 11.38 11.0.6.0.101+11 | 11.39 11.0.7+10 | ||
| 13.30 13.0.2.0.101+5 | 13.31 13.0.3+3 | ||
| — | 14.28 14.0.1+8 | ||
| CVE-2020-2778 Note 3: This vulnerability applies to client and server deployment of Java. This vulnerability can be exploited through untrusted code executed under Java sandbox restrictions. It can also be exploited by supplying data to APIs in the specified Component without using untrusted code executed under Java sandbox restrictions, such as through a web service. | 3.7 | ||
| 8.45 8u251b09 | 8.46 8u252b14 | ||
| 11.38 11.0.6.0.101+11 | 11.39 11.0.7+10 | ||
| 13.30 13.0.2.0.101+5 | 13.31 13.0.3+3 | ||
| — | 14.28 14.0.1+8 | ||
| CVE-2020-2816 Note 2: This vulnerability can only be exploited by supplying data to APIs in the specified Component without using untrusted code executed under Java sandbox restrictions, such as through a web service. | 7.5 | ||
| 8.45 8u251b09 | 8.46 8u252b14 | ||
| 11.38 11.0.6.0.101+11 | 11.39 11.0.7+10 | ||
| 13.30 13.0.2.0.101+5 | 13.31 13.0.3+3 | ||
| — | 14.28 14.0.1+8 | ||
| CVE-2019-18197 Note 1: This vulnerability applies to Java deployments that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). | 8.1 | ||
| 8.45 8u251b09 | 8.46 8u252b14 | ||
| 11.38 11.0.6.0.101+11 | 11.39 11.0.7+10 | ||
| 13.30 13.0.2.0.101+5 | 13.31 13.0.3+3 | ||
January 2020 CVEs
| January 2020 | Back to Top | ||
|---|---|---|---|
| January 2020 Quarterly Update Release | |||
| Azul Zulu Build of OpenJDK | |||
| CVE | Base Score | CPU | PSU |
| CVE-2020-2583 Note 1: This vulnerability applies to Java deployments, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. | 3.7 | ||
| 6.30 6u130-b130 | — | ||
| 7.35 7u251-b5 | 7.36 7u252-b10 | ||
| 8.43 8u241-b08 | 8.44 8u242-b20 | ||
| 11.36 11.0.5.0.101+11 | 11.37 11.0.6+10 | ||
| — | 13.29 13.0.2+6 | ||
| CVE-2020-2590 Note 1: This vulnerability applies to Java deployments, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. | 3.7 | ||
| 6.30 6u130-b130 | — | ||
| 7.35 7u251-b5 | 7.36 7u252-b10 | ||
| 8.43 8u241-b08 | 8.44 8u242-b20 | ||
| 11.36 11.0.5.0.101+11 | 11.37 11.0.6+10 | ||
| — | 13.29 13.0.2+6 | ||
| CVE-2020-2593 Note 1: This vulnerability applies to Java deployments, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. | 4.8 | ||
| 6.30 6u130-b130 | — | ||
| 7.35 7u251-b5 | 7.36 7u252-b10 | ||
| 8.43 8u241-b08 | 8.44 8u242-b20 | ||
| 11.36 11.0.5.0.101+11 | 11.37 11.0.6+10 | ||
| — | 13.29 13.0.2+6 | ||
| CVE-2020-2601 Note 1: This vulnerability applies to Java deployments, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. | 6.8 | ||
| 6.30 6u130-b130 | — | ||
| 7.35 7u251-b5 | 7.36 7u252-b10 | ||
| 8.43 8u241-b08 | 8.44 8u242-b20 | ||
| 11.36 11.0.5.0.101+11 | 11.37 11.0.6+10 | ||
| — | 13.29 13.0.2+6 | ||
| CVE-2020-2604 Note 1: This vulnerability applies to Java deployments, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. | 8.1 | ||
| 6.30 6u130-b130 | — | ||
| 7.35 7u251-b5 | 7.36 7u252-b10 | ||
| 8.43 8u241-b08 | 8.44 8u242-b20 | ||
| 11.36 11.0.5.0.101+11 | 11.37 11.0.6+10 | ||
| — | 13.29 13.0.2+6 | ||
| CVE-2020-2654 Note 2: This vulnerability applies to Java deployments, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. | 3.7 | ||
| 6.30 6u130-b130 | — | ||
| 7.35 7u251-b5 | 7.36 7u252-b10 | ||
| 8.43 8u241-b08 | 8.44 8u242-b20 | ||
| 11.36 11.0.5.0.101+11 | 11.37 11.0.6+10 | ||
| — | 13.29 13.0.2+6 | ||
| CVE-2020-2585 Note 1: This vulnerability applies to Java deployments, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. | 5.9 | ||
| 8.43 8u241-b08 | 8.44 8u242-b20 | ||
| 11.36 11.0.5.0.101+11 | 11.37 11.0.6+10 | ||
| — | 13.29 13.0.2+6 | ||
| CVE-2020-2659 Note 1: This vulnerability applies to Java deployments, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. | 3.7 | ||
| 6.30 6u130-b130 | — | ||
| 7.35 7u251-b5 | 7.36 7u252-b10 | ||
| 8.43 8u241-b08 | 8.44 8u242-b20 | ||
| CVE-2019-13117 Note 2: This vulnerability applies to Java deployments, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. | 7.5 | ||
| 8.43 8u241-b08 | 8.44 8u242-b20 | ||
| 11.36 11.0.5.0.101+11 | 11.37 11.0.6+10 | ||
| — | 13.29 13.0.2+6 | ||
| CVE-2019-13118 Note 2: This vulnerability applies to Java deployments, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. | 7.5 | ||
| 8.43 8u241-b08 | 8.44 8u242-b20 | ||
| 11.36 11.0.5.0.101+11 | 11.37 11.0.6+10 | ||
| — | 13.29 13.0.2+6 | ||
| CVE-2019-16168 Note 2: This vulnerability applies to Java deployments, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. | 7.5 | ||
| 8.43 8u241-b08 | 8.44 8u242-b20 | ||
| 11.36 11.0.5.0.101+11 | 11.37 11.0.6+10 | ||
| — | 13.29 13.0.2+6 | ||
| CVE-2020-2655 Note 1: This vulnerability applies to Java deployments, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. | 4.8 | ||
| 11.36 11.0.5.0.101+11 | 11.37 11.0.6+10 | ||
| — | 13.29 13.0.2+6 | ||
October 2019 CVEs
| October 2019 | Back to Top | ||
|---|---|---|---|
| October 2019 Quarterly Update Release | |||
| Azul Zulu Build of OpenJDK | |||
| CVE | Base Score | CPU | PSU |
| CVE-2019-2894 Note 1: This vulnerability applies to Java deployments, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. | 3.7 | ||
| 7.33 7u241-b5 | 7.34 7u242-b1 | ||
| 8.41 8u231-b08 | 8.42 8u232-b18 | ||
| 11.34 11.0.4.0.101+11 | 11.35 11.0.5+10 | ||
| — | 13.28 13.0.1+10 | ||
| CVE-2019-2933 Note 1: This vulnerability applies to Java deployments, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. | 3.1 | ||
| 7.33 7u241-b5 | 7.34 7u242-b1 | ||
| 8.41 8u231-b08 | 8.42 8u232-b18 | ||
| 11.34 11.0.4.0.101+11 | 11.35 11.0.5+10 | ||
| — | 13.28 13.0.1+10 | ||
| CVE-2019-2945 Note 2: This vulnerability applies to Java deployments that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). | 3.1 | ||
| 7.33 7u241-b5 | 7.34 7u242-b1 | ||
| 8.41 8u231-b08 | 8.42 8u232-b18 | ||
| 11.34 11.0.4.0.101+11 | 11.35 11.0.5+10 | ||
| — | 13.28 13.0.1+10 | ||
| CVE-2019-2958 Note 1: This vulnerability applies to Java deployments, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. | 5.9 | ||
| 7.33 7u241-b5 | 7.34 7u242-b1 | ||
| 8.41 8u231-b08 | 8.42 8u232-b18 | ||
| 11.34 11.0.4.0.101+11 | 11.35 11.0.5+10 | ||
| — | 13.28 13.0.1+10 | ||
| CVE-2019-2962 Note 1: This vulnerability applies to Java deployments, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. | 3.7 | ||
| 7.33 7u241-b5 | 7.34 7u242-b1 | ||
| 8.41 8u231-b08 | 8.42 8u232-b18 | ||
| 11.34 11.0.4.0.101+11 | 11.35 11.0.5+10 | ||
| — | 13.28 13.0.1+10 | ||
| CVE-2019-2964 Note 3: This vulnerability can only be exploited by supplying data to APIs in the specified Component without using Untrusted Java deployments, such as through a web service. | 3.7 | ||
| 7.33 7u241-b5 | 7.34 7u242-b1 | ||
| 8.41 8u231-b08 | 8.42 8u232-b18 | ||
| 11.34 11.0.4.0.101+11 | 11.35 11.0.5+10 | ||
| — | 13.28 13.0.1+10 | ||
| CVE-2019-2973 Note 1: This vulnerability applies to Java deployments, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. | 3.7 | ||
| 7.33 7u241-b5 | 7.34 7u242-b1 | ||
| 8.41 8u231-b08 | 8.42 8u232-b18 | ||
| 11.34 11.0.4.0.101+11 | 11.35 11.0.5+10 | ||
| — | 13.28 13.0.1+10 | ||
| CVE-2019-2978 Note 1: This vulnerability applies to Java deployments, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. | 3.7 | ||
| 7.33 7u241-b5 | 7.34 7u242-b1 | ||
| 8.41 8u231-b08 | 8.42 8u232-b18 | ||
| 11.34 11.0.4.0.101+11 | 11.35 11.0.5+10 | ||
| — | 13.28 13.0.1+10 | ||
| CVE-2019-2981 Note 1: This vulnerability applies to Java deployments, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. | 3.7 | ||
| 7.33 7u241-b5 | 7.34 7u242-b1 | ||
| 8.41 8u231-b08 | 8.42 8u232-b18 | ||
| 11.34 11.0.4.0.101+11 | 11.35 11.0.5+10 | ||
| — | 13.28 13.0.1+10 | ||
| CVE-2019-2983 Note 1: This vulnerability applies to Java deployments, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. | 3.7 | ||
| 7.33 7u241-b5 | 7.34 7u242-b1 | ||
| 8.41 8u231-b08 | 8.42 8u232-b18 | ||
| 11.34 11.0.4.0.101+11 | 11.35 11.0.5+10 | ||
| — | 13.28 13.0.1+10 | ||
| CVE-2019-2987 Note 1: This vulnerability applies to Java deployments, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. | 3.7 | ||
| 7.33 7u241-b5 | 7.34 7u242-b1 | ||
| 8.41 8u231-b08 | 8.42 8u232-b18 | ||
| 11.34 11.0.4.0.101+11 | 11.35 11.0.5+10 | ||
| — | 13.28 13.0.1+10 | ||
| CVE-2019-2988 Note 2: This vulnerability applies to Java deployments that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). | 3.7 | ||
| 7.33 7u241-b5 | 7.34 7u242-b1 | ||
| 8.41 8u231-b08 | 8.42 8u232-b18 | ||
| 11.34 11.0.4.0.101+11 | 11.35 11.0.5+10 | ||
| — | 13.28 13.0.1+10 | ||
| CVE-2019-2989 Note 1: This vulnerability applies to Java deployments, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. | 6.8 | ||
| 7.33 7u241-b5 | 7.34 7u242-b1 | ||
| 8.41 8u231-b08 | 8.42 8u232-b18 | ||
| 11.34 11.0.4.0.101+11 | 11.35 11.0.5+10 | ||
| — | 13.28 13.0.1+10 | ||
| CVE-2019-2992 Note 2: This vulnerability applies to Java deployments that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). | 3.7 | ||
| 7.33 7u241-b5 | 7.34 7u242-b1 | ||
| 8.41 8u231-b08 | 8.42 8u232-b18 | ||
| 11.34 11.0.4.0.101+11 | 11.35 11.0.5+10 | ||
| — | 13.28 13.0.1+10 | ||
| CVE-2019-2999 Note 2: This vulnerability applies to Java deployments that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). | 4.7 | ||
| 7.33 7u241-b5 | 7.34 7u242-b1 | ||
| 8.41 8u231-b08 | 8.42 8u232-b18 | ||
| 11.34 11.0.4.0.101+11 | 11.35 11.0.5+10 | ||
| — | 13.28 13.0.1+10 | ||
| CVE-2019-2949 Note 1: This vulnerability applies to Java deployments, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. | 6.8 | ||
| 8.41 8u231-b08 | 8.42 8u232-b18 | ||
| 11.34 11.0.4.0.101+11 | 11.35 11.0.5+10 | ||
| — | 13.28 13.0.1+10 | ||
| CVE-2019-2975 Note 1: This vulnerability applies to Java deployments, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. | 4.8 | ||
| 8.41 8u231-b08 | 8.42 8u232-b18 | ||
| 11.34 11.0.4.0.101+11 | 11.35 11.0.5+10 | ||
| — | 13.28 13.0.1+10 | ||
| CVE-2019-2977 Note 2: This vulnerability applies to Java deployments that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). | 4.8 | ||
| 11.34 11.0.4.0.101+11 | 11.35 11.0.5+10 | ||
| — | 13.28 13.0.1+10 | ||
July 2019 CVEs
| July 2019 | Back to Top | ||
|---|---|---|---|
| July 2019 Quarterly Update Release | |||
| Azul Zulu Build of OpenJDK | |||
| CVE | Base Score | CPU | PSU |
| CVE-2019-2762 Note 2: This vulnerability applies to Java deployments that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). | 5.3 | ||
| 7.30 7u231-b5 | 7.31 7u232-b6 | ||
| 8.39 8u221-b08 | 8.40 8u222-b10 | ||
| 11.32 11.0.3.0.101+11 | 11.33 11.0.4+11 | ||
| — | 12.3 12.0.2+3 | ||
| CVE-2019-2766 Note 2: This vulnerability applies to Java deployments that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). | 3.1 | ||
| 7.30 7u231-b5 | 7.31 7u232-b6 | ||
| 8.39 8u221-b08 | 8.40 8u222-b10 | ||
| 11.32 11.0.3.0.101+11 | 11.33 11.0.4+11 | ||
| — | 12.3 12.0.2+3 | ||
| CVE-2019-2769 Note 2: This vulnerability applies to Java deployments that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). | 5.3 | ||
| 7.30 7u231-b5 | 7.31 7u232-b6 | ||
| 8.39 8u221-b08 | 8.40 8u222-b10 | ||
| 11.32 11.0.3.0.101+11 | 11.33 11.0.4+11 | ||
| — | 12.3 12.0.2+3 | ||
| CVE-2019-2786 Note 2: This vulnerability applies to Java deployments that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). | 3.4 | ||
| 7.30 7u231-b5 | 7.31 7u232-b6 | ||
| 8.39 8u221-b08 | 8.40 8u222-b10 | ||
| 11.32 11.0.3.0.101+11 | 11.33 11.0.4+11 | ||
| — | 12.3 12.0.2+3 | ||
| CVE-2019-2816 Note 2: This vulnerability applies to Java deployments that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). | 4.8 | ||
| 7.30 7u231-b5 | 7.31 7u232-b6 | ||
| 8.39 8u221-b08 | 8.40 8u222-b10 | ||
| 11.32 11.0.3.0.101+11 | 11.33 11.0.4+11 | ||
| — | 12.3 12.0.2+3 | ||
| CVE-2019-7317 Note 1: This vulnerability applies to Java deployments, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. | 6.8 | ||
| 7.30 7u231-b5 | 7.31 7u232-b6 | ||
| 8.39 8u221-b08 | 8.40 8u222-b10 | ||
| 11.32 11.0.3.0.101+11 | 11.33 11.0.4+11 | ||
| — | 12.3 12.0.2+3 | ||
| CVE-2019-2745 Note 2: This vulnerability applies to Java deployments that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). | 5.1 | ||
| 7.30 7u231-b5 | 7.31 7u232-b6 | ||
| 8.39 8u221-b08 | 8.40 8u222-b10 | ||
| 11.32 11.0.3.0.101+11 | 11.33 11.0.4+11 | ||
| CVE-2019-2842 Note 2: This vulnerability applies to Java deployments that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). | 3.7 | ||
| 7.30 7u231-b5 | 7.31 7u232-b6 | ||
| 8.39 8u221-b08 | 8.40 8u222-b10 | ||
| CVE-2019-2818 Note 1: This vulnerability applies to Java deployments, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. | 3.1 | ||
| 11.32 11.0.3.0.101+11 | 11.33 11.0.4+11 | ||
| — | 12.3 12.0.2+3 | ||
| CVE-2019-2821 Note 1: This vulnerability applies to Java deployments, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. | 5.3 | ||
| 11.32 11.0.3.0.101+11 | 11.33 11.0.4+11 | ||
| — | 12.3 12.0.2+3 | ||
April 2019 CVEs
| April 2019 | Back to Top | ||
|---|---|---|---|
| April 2019 Quarterly Update Release | |||
| Azul Zulu Build of OpenJDK | |||
| CVE | Base Score | CPU | PSU |
| CVE-2019-2602 Note 3: This vulnerability can only be exploited by supplying data to APIs in the specified Component without using Untrusted Java deployments, such as through a web service. | 7.5 | ||
| 7.28 7u221-b09 | 7.29 7u222-b08 | ||
| 8.37 8u211-b19 | 8.38 8u212-b04 | ||
| 11.30 11.0.2.0.101+5 | 11.31 11.0.3+7 | ||
| — | 12.2 12.0.1+12 | ||
| CVE-2019-2684 Note 1: This vulnerability applies to Java deployments, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. | 5.9 | ||
| 7.28 7u221-b09 | 7.29 7u222-b08 | ||
| 8.37 8u211-b19 | 8.38 8u212-b04 | ||
| 11.30 11.0.2.0.101+5 | 11.31 11.0.3+7 | ||
| — | 12.2 12.0.1+12 | ||
| CVE-2019-2698 Note 2: This vulnerability applies to Java deployments that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). | 8.1 | ||
| 7.28 7u221-b09 | 7.29 7u222-b08 | ||
| 8.37 8u211-b19 | 8.38 8u212-b04 | ||
| CVE-2019-2699 Note 1: This vulnerability applies to Java deployments, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. | 9 | ||
| 7.28 7u221-b09 | 7.29 7u222-b08 | ||
| CVE-2019-2697 This CVE is not applicable to Azul Core. It is listed here for comparison with other Java implementations which may contain this CVE. Note 2: This vulnerability applies to Java deployments that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). | 8.1 | — | |
January 2019 CVEs
| January 2019 | Back to Top | ||
|---|---|---|---|
| January 2019 Quarterly Update Release | |||
| Azul Zulu Build of OpenJDK | |||
| CVE | Base Score | CPU | PSU |
| CVE-2019-2422 | 3.1 | ||
| 6.23 6u123 | — | ||
| 7.27 7u211 | — | ||
| 8.34 8u201 | 8.35 8u202 | ||
| — | 11.29 11.0.2 | ||
| CVE-2019-2426 | 3.7 | ||
| 6.23 6u123 | — | ||
| 7.27 7u211 | — | ||
| 8.34 8u201 | 8.35 8u202 | ||
| — | 11.29 11.0.2 | ||
| CVE-2018-11212 | 5.3 | ||
| 6.23 6u123 | — | ||
| 7.27 7u211 | — | ||
| 8.34 8u201 | 8.35 8u202 | ||
| — | 11.29 11.0.2 | ||
October 2018 CVEs
| October 2018 | Back to Top | ||
|---|---|---|---|
| October 2018 Quarterly Update Release | |||
| Azul Zulu Build of OpenJDK | |||
| CVE | Base Score | CPU | PSU |
| CVE-2018-3136 | 3.4 | ||
| 6.22 6u119 | — | ||
| 7.25 7u201 | — | ||
| 8.32 8u191 | 8.33 8u192 | ||
| — | 11.2 11.0.1 | ||
| CVE-2018-3139 | 3.1 | ||
| 6.22 6u119 | — | ||
| 7.25 7u201 | — | ||
| 8.32 8u191 | 8.33 8u192 | ||
| — | 11.2 11.0.1 | ||
| CVE-2018-3149 | 8.3 | ||
| 6.22 6u119 | — | ||
| 7.25 7u201 | — | ||
| 8.32 8u191 | 8.33 8u192 | ||
| — | 11.2 11.0.1 | ||
| CVE-2018-3180 | 5.6 | ||
| 6.22 6u119 | — | ||
| 7.25 7u201 | — | ||
| 8.32 8u191 | 8.33 8u192 | ||
| — | 11.2 11.0.1 | ||
| CVE-2018-13785 | 3.7 | ||
| 6.22 6u119 | — | ||
| 7.25 7u201 | — | ||
| 8.32 8u191 | 8.33 8u192 | ||
| — | 11.2 11.0.1 | ||
| CVE-2018-3169 | 8.3 | ||
| 7.25 7u201 | — | ||
| 8.32 8u191 | 8.33 8u192 | ||
| — | 11.2 11.0.1 | ||
| CVE-2018-3214 | 5.3 | ||
| 6.22 6u119 | — | ||
| 7.25 7u201 | — | ||
| 8.32 8u191 | 8.33 8u192 | ||
| CVE-2018-3183 | 9 | ||
| 8.32 8u191 | 8.33 8u192 | ||
| — | 11.2 11.0.1 | ||
| CVE-2018-3150 | 3.7 | ||
| — | 11.2 11.0.1 | ||
| CVE-2018-3157 | 3.7 | ||
| — | 11.2 11.0.1 | ||
July 2018 CVEs
| July 2018 | Back to Top | ||
|---|---|---|---|
| July 2018 Quarterly Update Release | |||
| Azul Zulu Build of OpenJDK | |||
| CVE | Base Score | CPU | PSU |
| CVE-2018-2940 | 4.3 | ||
| 6.21 6u113 | — | ||
| 7.24 7u191 | — | ||
| 8.31 8u181 | — | ||
| — | 10.3 10.0.2 | ||
| CVE-2018-2952 | 3.7 | ||
| 6.21 6u113 | — | ||
| 7.24 7u191 | — | ||
| 8.31 8u181 | — | ||
| — | 10.3 10.0.2 | ||
| CVE-2018-2973 | 5.9 | ||
| 6.21 6u113 | — | ||
| 7.24 7u191 | — | ||
| 8.31 8u181 | — | ||
| — | 10.3 10.0.2 | ||
| CVE-2018-2938 | 9 | ||
| 8.31 8u181 | — | ||
| CVE-2018-2972 | 5.9 | ||
| — | 10.3 10.0.2 | ||
April 2018 CVEs
| April 2018 | Back to Top | ||
|---|---|---|---|
| April 2018 Quarterly Update Release | |||
| Azul Zulu Build of OpenJDK | |||
| CVE | Base Score | CPU | PSU |
| CVE-2018-2790 | 3.1 | ||
| 6.20 6u107 | — | ||
| 7.23 7u181 | — | ||
| 8.29 8u171 | 8.30 8u172 | ||
| — | 9.0.7 9.0.7 | ||
| — | 10.2 10.0.1 | ||
| CVE-2018-2794 | 7.7 | ||
| 6.20 6u107 | — | ||
| 7.23 7u181 | — | ||
| 8.29 8u171 | 8.30 8u172 | ||
| — | 9.0.7 9.0.7 | ||
| — | 10.2 10.0.1 | ||
| CVE-2018-2795 | 5.3 | ||
| 6.20 6u107 | — | ||
| 7.23 7u181 | — | ||
| 8.29 8u171 | 8.30 8u172 | ||
| — | 9.0.7 9.0.7 | ||
| — | 10.2 10.0.1 | ||
| CVE-2018-2797 | 5.3 | ||
| 6.20 6u107 | — | ||
| 7.23 7u181 | — | ||
| 8.29 8u171 | 8.30 8u172 | ||
| — | 9.0.7 9.0.7 | ||
| — | 10.2 10.0.1 | ||
| CVE-2018-2798 | 5.3 | ||
| 6.20 6u107 | — | ||
| 7.23 7u181 | — | ||
| 8.29 8u171 | 8.30 8u172 | ||
| — | 9.0.7 9.0.7 | ||
| — | 10.2 10.0.1 | ||
| CVE-2018-2814 | 8.3 | ||
| 6.20 6u107 | — | ||
| 7.23 7u181 | — | ||
| 8.29 8u171 | 8.30 8u172 | ||
| — | 9.0.7 9.0.7 | ||
| — | 10.2 10.0.1 | ||
| CVE-2018-2815 | 5.3 | ||
| 6.20 6u107 | — | ||
| 7.23 7u181 | — | ||
| 8.29 8u171 | 8.30 8u172 | ||
| — | 9.0.7 9.0.7 | ||
| — | 10.2 10.0.1 | ||
| CVE-2018-2796 | 5.3 | ||
| 7.23 7u181 | — | ||
| 8.29 8u171 | 8.30 8u172 | ||
| — | 9.0.7 9.0.7 | ||
| — | 10.2 10.0.1 | ||
| CVE-2018-2799 | 5.3 | ||
| 7.23 7u181 | — | ||
| 8.29 8u171 | 8.30 8u172 | ||
| — | 9.0.7 9.0.7 | ||
| — | 10.2 10.0.1 | ||
| CVE-2018-2783 | 7.4 | ||
| 6.20 6u107 | — | ||
| 7.23 7u181 | — | ||
| 8.29 8u171 | 8.30 8u172 | ||
| CVE-2018-2800 | 4.2 | ||
| 6.20 6u107 | — | ||
| 7.23 7u181 | — | ||
| 8.29 8u171 | 8.30 8u172 | ||
| CVE-2018-2825 | 8.3 | ||
| — | 9.0.7 9.0.7 | ||
| — | 10.2 10.0.1 | ||
| CVE-2018-2826 | 8.3 | ||
| — | 9.0.7 9.0.7 | ||
| — | 10.2 10.0.1 | ||
January 2018 CVEs
| January 2018 | Back to Top | ||
|---|---|---|---|
| January 2018 Quarterly Update Release | |||
| Azul Zulu Build of OpenJDK | |||
| CVE | Base Score | CPU | PSU |
| CVE-2018-2579 | 3.7 | ||
| 6.19 6u103 | — | ||
| 7.22 7u171 | — | ||
| 8.27 8u162 | — | ||
| — | 9.0.4 9.0.4 | ||
| CVE-2018-2588 | 4.3 | ||
| 6.19 6u103 | — | ||
| 7.22 7u171 | — | ||
| 8.27 8u162 | — | ||
| — | 9.0.4 9.0.4 | ||
| CVE-2018-2599 | 4.8 | ||
| 6.19 6u103 | — | ||
| 7.22 7u171 | — | ||
| 8.27 8u162 | — | ||
| — | 9.0.4 9.0.4 | ||
| CVE-2018-2602 | 4.5 | ||
| 6.19 6u103 | — | ||
| 7.22 7u171 | — | ||
| 8.27 8u162 | — | ||
| — | 9.0.4 9.0.4 | ||
| CVE-2018-2603 | 5.3 | ||
| 6.19 6u103 | — | ||
| 7.22 7u171 | — | ||
| 8.27 8u162 | — | ||
| — | 9.0.4 9.0.4 | ||
| CVE-2018-2618 | 5.9 | ||
| 6.19 6u103 | — | ||
| 7.22 7u171 | — | ||
| 8.27 8u162 | — | ||
| — | 9.0.4 9.0.4 | ||
| CVE-2018-2629 | 5.3 | ||
| 6.19 6u103 | — | ||
| 7.22 7u171 | — | ||
| 8.27 8u162 | — | ||
| — | 9.0.4 9.0.4 | ||
| CVE-2018-2633 | 8.3 | ||
| 6.19 6u103 | — | ||
| 7.22 7u171 | — | ||
| 8.27 8u162 | — | ||
| — | 9.0.4 9.0.4 | ||
| CVE-2018-2637 | 7.4 | ||
| 6.19 6u103 | — | ||
| 7.22 7u171 | — | ||
| 8.27 8u162 | — | ||
| — | 9.0.4 9.0.4 | ||
| CVE-2018-2641 | 6.1 | ||
| 6.19 6u103 | — | ||
| 7.22 7u171 | — | ||
| 8.27 8u162 | — | ||
| — | 9.0.4 9.0.4 | ||
| CVE-2018-2663 | 4.3 | ||
| 6.19 6u103 | — | ||
| 7.22 7u171 | — | ||
| 8.27 8u162 | — | ||
| — | 9.0.4 9.0.4 | ||
| CVE-2018-2677 | 4.3 | ||
| 6.19 6u103 | — | ||
| 7.22 7u171 | — | ||
| 8.27 8u162 | — | ||
| — | 9.0.4 9.0.4 | ||
| CVE-2018-2678 | 4.3 | ||
| 6.19 6u103 | — | ||
| 7.22 7u171 | — | ||
| 8.27 8u162 | — | ||
| — | 9.0.4 9.0.4 | ||
| CVE-2018-2634 | 6.8 | ||
| 7.22 7u171 | — | ||
| 8.27 8u162 | — | ||
| — | 9.0.4 9.0.4 | ||
| CVE-2018-2582 | 6.5 | ||
| 8.27 8u162 | — | ||
| — | 9.0.4 9.0.4 | ||
October 2017 CVEs
| October 2017 | Back to Top | ||
|---|---|---|---|
| October 2017 Quarterly Update Release | |||
| Azul Zulu Build of OpenJDK | |||
| CVE | Base Score | CPU | PSU |
| CVE-2016-9841 | 5.3 | ||
| 6.18 6u99 | — | ||
| 7.21 7u161 | — | ||
| 8.25 8u152 | — | ||
| — | 9.0.1 9.0.1 | ||
| CVE-2017-10274 | 6.8 | ||
| 6.18 6u99 | — | ||
| 7.21 7u161 | — | ||
| 8.25 8u152 | — | ||
| — | 9.0.1 9.0.1 | ||
| CVE-2017-10281 | 5.3 | ||
| 6.18 6u99 | — | ||
| 7.21 7u161 | — | ||
| 8.25 8u152 | — | ||
| — | 9.0.1 9.0.1 | ||
| CVE-2017-10285 | 9.6 | ||
| 6.18 6u99 | — | ||
| 7.21 7u161 | — | ||
| 8.25 8u152 | — | ||
| — | 9.0.1 9.0.1 | ||
| CVE-2017-10295 | 4 | ||
| 6.18 6u99 | — | ||
| 7.21 7u161 | — | ||
| 8.25 8u152 | — | ||
| — | 9.0.1 9.0.1 | ||
| CVE-2017-10345 | 3.1 | ||
| 6.18 6u99 | — | ||
| 7.21 7u161 | — | ||
| 8.25 8u152 | — | ||
| — | 9.0.1 9.0.1 | ||
| CVE-2017-10346 | 9.6 | ||
| 6.18 6u99 | — | ||
| 7.21 7u161 | — | ||
| 8.25 8u152 | — | ||
| — | 9.0.1 9.0.1 | ||
| CVE-2017-10347 | 5.3 | ||
| 6.18 6u99 | — | ||
| 7.21 7u161 | — | ||
| 8.25 8u152 | — | ||
| — | 9.0.1 9.0.1 | ||
| CVE-2017-10348 | 5.3 | ||
| 6.18 6u99 | — | ||
| 7.21 7u161 | — | ||
| 8.25 8u152 | — | ||
| — | 9.0.1 9.0.1 | ||
| CVE-2017-10349 | 5.3 | ||
| 6.18 6u99 | — | ||
| 7.21 7u161 | — | ||
| 8.25 8u152 | — | ||
| — | 9.0.1 9.0.1 | ||
| CVE-2017-10355 | 5.3 | ||
| 6.18 6u99 | — | ||
| 7.21 7u161 | — | ||
| 8.25 8u152 | — | ||
| — | 9.0.1 9.0.1 | ||
| CVE-2017-10356 | 6.2 | ||
| 6.18 6u99 | — | ||
| 7.21 7u161 | — | ||
| 8.25 8u152 | — | ||
| — | 9.0.1 9.0.1 | ||
| CVE-2017-10357 | 5.3 | ||
| 6.18 6u99 | — | ||
| 7.21 7u161 | — | ||
| 8.25 8u152 | — | ||
| — | 9.0.1 9.0.1 | ||
| CVE-2017-10388 | 7.5 | ||
| 6.18 6u99 | — | ||
| 7.21 7u161 | — | ||
| 8.25 8u152 | — | ||
| — | 9.0.1 9.0.1 | ||
| CVE-2016-10165 | 5.3 | ||
| 7.21 7u161 | — | ||
| 8.25 8u152 | — | ||
| — | 9.0.1 9.0.1 | ||
| CVE-2017-10350 | 5.3 | ||
| 7.21 7u161 | — | ||
| 8.25 8u152 | — | ||
| — | 9.0.1 9.0.1 | ||
July 2017 CVEs
| July 2017 | Back to Top | ||
|---|---|---|---|
| July 2017 Quarterly Update Release | |||
| Azul Zulu Build of OpenJDK | |||
| CVE | Base Score | CPU | PSU |
| CVE-2017-10053 | 5.3 | ||
| 7.20 7u154 | — | ||
| 8.23 8u144 | — | ||
| CVE-2017-10067 | 7.5 | ||
| 7.20 7u154 | — | ||
| 8.23 8u144 | — | ||
| CVE-2017-10074 | 8.3 | ||
| 7.20 7u154 | — | ||
| 8.23 8u144 | — | ||
| CVE-2017-10081 | 4.3 | ||
| 7.20 7u154 | — | ||
| 8.23 8u144 | — | ||
| CVE-2017-10087 | 9.6 | ||
| 7.20 7u154 | — | ||
| 8.23 8u144 | — | ||
| CVE-2017-10089 | 9.6 | ||
| 7.20 7u154 | — | ||
| 8.23 8u144 | — | ||
| CVE-2017-10090 | 9.6 | ||
| 7.20 7u154 | — | ||
| 8.23 8u144 | — | ||
| CVE-2017-10096 | 9.6 | ||
| 7.20 7u154 | — | ||
| 8.23 8u144 | — | ||
| CVE-2017-10101 | 9.6 | ||
| 7.20 7u154 | — | ||
| 8.23 8u144 | — | ||
| CVE-2017-10102 | 9 | ||
| 7.20 7u154 | — | ||
| 8.23 8u144 | — | ||
| CVE-2017-10107 | 9.6 | ||
| 7.20 7u154 | — | ||
| 8.23 8u144 | — | ||
| CVE-2017-10108 | 5.3 | ||
| 7.20 7u154 | — | ||
| 8.23 8u144 | — | ||
| CVE-2017-10109 | 5.3 | ||
| 7.20 7u154 | — | ||
| 8.23 8u144 | — | ||
| CVE-2017-10110 | 9.6 | ||
| 7.20 7u154 | — | ||
| 8.23 8u144 | — | ||
| CVE-2017-10111 | 9.6 | ||
| 7.20 7u154 | — | ||
| 8.23 8u144 | — | ||
| CVE-2017-10115 | 7.5 | ||
| 7.20 7u154 | — | ||
| 8.23 8u144 | — | ||
| CVE-2017-10116 | 8.3 | ||
| 7.20 7u154 | — | ||
| 8.23 8u144 | — | ||
| CVE-2017-10118 | 7.5 | ||
| 7.20 7u154 | — | ||
| 8.23 8u144 | — | ||
| CVE-2017-10135 | 5.9 | ||
| 7.20 7u154 | — | ||
| 8.23 8u144 | — | ||
| CVE-2017-10176 | 7.5 | ||
| 7.20 7u154 | — | ||
| 8.23 8u144 | — | ||
| CVE-2017-10193 | 3.1 | ||
| 7.20 7u154 | — | ||
| 8.23 8u144 | — | ||
| CVE-2017-10198 | 6.8 | ||
| 7.20 7u154 | — | ||
| 8.23 8u144 | — | ||
| CVE-2017-10243 | 6.5 | ||
| 7.20 7u154 | — | ||
| 8.23 8u144 | — | ||
| CVE-2017-10078 | 8.1 | ||
| 8.23 8u144 | — | ||
April 2017 CVEs
| April 2017 | Back to Top | ||
|---|---|---|---|
| April 2017 Quarterly Update Release | |||
| Azul Zulu Build of OpenJDK | |||
| CVE | Base Score | CPU | PSU |
| CVE-2017-3509 | 4.2 | ||
| 6.16 6u93 | — | ||
| 7.18 7u141 | — | ||
| 8.21 8u131 | — | ||
| CVE-2017-3514 | 8.3 | ||
| 6.16 6u93 | — | ||
| 7.18 7u141 | — | ||
| 8.21 8u131 | — | ||
| CVE-2017-3526 | 5.9 | ||
| 6.16 6u93 | — | ||
| 7.18 7u141 | — | ||
| 8.21 8u131 | — | ||
| CVE-2017-3533 | 3.7 | ||
| 6.16 6u93 | — | ||
| 7.18 7u141 | — | ||
| 8.21 8u131 | — | ||
| CVE-2017-3539 | 3.1 | ||
| 6.16 6u93 | — | ||
| 7.18 7u141 | — | ||
| 8.21 8u131 | — | ||
| CVE-2017-3544 | 3.7 | ||
| 6.16 6u93 | — | ||
| 7.18 7u141 | — | ||
| 8.21 8u131 | — | ||
| CVE-2017-3511 | 7.7 | ||
| 7.18 7u141 | — | ||
| 8.21 8u131 | — | ||
| CVE-2017-3512 | 8.3 | ||
| 7.18 7u141 | — | ||
| 8.21 8u131 | — | ||
| CVE-2017-3523 | 9.6 | ||
| 8.21 8u131 | — | ||
January 2017 CVEs
| January 2017 | Back to Top | ||
|---|---|---|---|
| January 2017 Quarterly Update Release | |||
| Azul Zulu Build of OpenJDK | |||
| CVE | Base Score | CPU | PSU |
| CVE-2016-2183 | 3.1 | ||
| 7.17 7u131 | — | ||
| 8.20 8u121 | — | ||
| CVE-2017-3231 | 4.3 | ||
| 7.17 7u131 | — | ||
| 8.20 8u121 | — | ||
| CVE-2017-3241 | 9 | ||
| 7.17 7u131 | — | ||
| 8.20 8u121 | — | ||
| CVE-2016-3252 | 5.8 | ||
| 7.17 7u131 | — | ||
| 8.20 8u121 | — | ||
| CVE-2017-3253 | 7.5 | ||
| 7.17 7u131 | — | ||
| 8.20 8u121 | — | ||
| CVE-2017-3260 | 8.3 | ||
| 7.17 7u131 | — | ||
| 8.20 8u121 | — | ||
| CVE-2017-3261 | 4.3 | ||
| 7.17 7u131 | — | ||
| 8.20 8u121 | — | ||
| CVE-2017-3272 | 9.6 | ||
| 7.17 7u131 | — | ||
| 8.20 8u121 | — | ||
| CVE-2017-3289 | 9.6 | ||
| 7.17 7u131 | — | ||
| 8.20 8u121 | — | ||
| CVE-2016-5546 | 7.5 | ||
| 7.17 7u131 | — | ||
| 8.20 8u121 | — | ||
| CVE-2016-5547 | 5.3 | ||
| 7.17 7u131 | — | ||
| 8.20 8u121 | — | ||
| CVE-2016-5548 | 6.5 | ||
| 7.17 7u131 | — | ||
| 8.20 8u121 | — | ||
| CVE-2016-5549 | 6.5 | ||
| 7.17 7u131 | — | ||
| 8.20 8u121 | — | ||
| CVE-2016-5552 | 5.3 | ||
| 7.17 7u131 | — | ||
| 8.20 8u121 | — | ||
October 2016 CVEs
| October 2016 | Back to Top | ||
|---|---|---|---|
| October 2016 Quarterly Update Release | |||
| Azul Zulu Build of OpenJDK | |||
| CVE | Base Score | CPU | PSU |
| CVE-2016-5542 | 3.1 | ||
| 6.14 6u87 | — | ||
| 7.16 7u121 | — | ||
| 8.18 8u111 | 8.19 8u112 | ||
| CVE-2016-5554 | 4.3 | ||
| 6.14 6u87 | — | ||
| 7.16 7u121 | — | ||
| 8.18 8u111 | 8.19 8u112 | ||
| CVE-2016-5568 | 9.6 | ||
| 6.14 6u87 | — | ||
| 7.16 7u121 | — | ||
| 8.18 8u111 | 8.19 8u112 | ||
| CVE-2016-5573 | 8.3 | ||
| 6.14 6u87 | — | ||
| 7.16 7u121 | — | ||
| 8.18 8u111 | 8.19 8u112 | ||
| CVE-2016-5582 | 9.6 | ||
| 6.14 6u87 | — | ||
| 7.16 7u121 | — | ||
| 8.18 8u111 | 8.19 8u112 | ||
| CVE-2016-5597 | 5.9 | ||
| 6.14 6u87 | — | ||
| 7.16 7u121 | — | ||
| 8.18 8u111 | 8.19 8u112 | ||
July 2016 CVEs
| July 2016 | Back to Top | ||
|---|---|---|---|
| July 2016 Quarterly Update Release | |||
| Azul Zulu Build of OpenJDK | |||
| CVE | Base Score | CPU | PSU |
| CVE-2016-3458 | 4.3 | ||
| 6.13 6u83 | — | ||
| 7.15 7u111 | — | ||
| 8.16 8u101 | 8.17 8u102 | ||
| CVE-2016-3485 | 2.9 | ||
| 6.13 6u83 | — | ||
| 7.15 7u111 | — | ||
| 8.16 8u101 | 8.17 8u102 | ||
| CVE-2016-3500 | 5.3 | ||
| 6.13 6u83 | — | ||
| 7.15 7u111 | — | ||
| 8.16 8u101 | 8.17 8u102 | ||
| CVE-2016-3508 | 5.3 | ||
| 6.13 6u83 | — | ||
| 7.15 7u111 | — | ||
| 8.16 8u101 | 8.17 8u102 | ||
| CVE-2016-3550 | 4.3 | ||
| 6.13 6u83 | — | ||
| 7.15 7u111 | — | ||
| 8.16 8u101 | 8.17 8u102 | ||
| CVE-2016-3606 | 9.6 | ||
| 7.15 7u111 | — | ||
| 8.16 8u101 | 8.17 8u102 | ||
| CVE-2016-0695 | 5.9 | ||
| 6.13 6u83 | — | ||
| 7.15 7u111 | — | ||
| CVE-2016-3587 | 9.6 | ||
| 8.16 8u101 | 8.17 8u102 | ||
| CVE-2016-3598 | 9.6 | ||
| 8.16 8u101 | 8.17 8u102 | ||
| CVE-2016-3610 | 9.6 | ||
| 8.16 8u101 | 8.17 8u102 | ||
April 2016 CVEs
| April 2016 | Back to Top | ||
|---|---|---|---|
| April 2016 Quarterly Update Release | |||
| Azul Zulu Build of OpenJDK | |||
| CVE | Base Score | CPU | PSU |
| CVE-2016-0686 | 9.6 | ||
| 6.12 6u79 | — | ||
| 7.14 7u101 | — | ||
| 8.14 8u91 | 8.15 8u92 | ||
| CVE-2016-0687 | 9.6 | ||
| 6.12 6u79 | — | ||
| 7.14 7u101 | — | ||
| 8.14 8u91 | 8.15 8u92 | ||
| CVE-2016-3425 | 5.3 | ||
| 6.12 6u79 | — | ||
| 7.14 7u101 | — | ||
| 8.14 8u91 | 8.15 8u92 | ||
| CVE-2016-3427 | 9 | ||
| 6.12 6u79 | — | ||
| 7.14 7u101 | — | ||
| 8.14 8u91 | 8.15 8u92 | ||
| CVE-2016-0695 | 5.9 | ||
| 8.14 8u91 | 8.15 8u92 | ||
| CVE-2016-3426 | 3.1 | ||
| 8.14 8u91 | 8.15 8u92 | ||
January 2016 CVEs
| January 2016 | Back to Top | ||
|---|---|---|---|
| January 2016 Quarterly Update Release | |||
| Azul Zulu Build of OpenJDK | |||
| CVE | Base Score | CPU | PSU |
| CVE-2016-0402 | 5 | ||
| 6.11 6u77 | — | ||
| 7.13 7u95 | — | ||
| 8.12 8u71 | 8.13 8u72 | ||
| CVE-2016-0448 | 4 | ||
| 6.11 6u77 | — | ||
| 7.13 7u95 | — | ||
| 8.12 8u71 | 8.13 8u72 | ||
| CVE-2016-0466 | 5 | ||
| 6.11 6u77 | — | ||
| 7.13 7u95 | — | ||
| 8.12 8u71 | 8.13 8u72 | ||
| CVE-2016-0483 | 10 | ||
| 6.11 6u77 | — | ||
| 7.13 7u95 | — | ||
| 8.12 8u71 | 8.13 8u72 | ||
| CVE-2016-0494 | 10 | ||
| 6.11 6u77 | — | ||
| 7.13 7u95 | — | ||
| 8.12 8u71 | 8.13 8u72 | ||
| CVE-2015-7575 | 4 | ||
| 6.11 6u77 | — | ||
| 7.13 7u95 | — | ||
| 8.12 8u71 | 8.13 8u72 | ||
| CVE-2015-8126 | 10 | ||
| 6.11 6u77 | — | ||
| 7.13 7u95 | — | ||
| 8.12 8u71 | 8.13 8u72 | ||
| CVE-2016-0475 | 5.8 | ||
| 8.12 8u71 | 8.13 8u72 | ||