CVE-2014-2421

critical
Published 2014-04-16 · Modified 2026-05-06
CVSS v3
CVSS v2
10.0
VIR risk
10.0

Description

Unspecified vulnerability in Oracle Java SE 5.0u61, 6u71, 7u51, and 8; JavaFX 2.2.51; and Java SE Embedded 7u51 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: secalert_us@oracle.com — http://www.oracle.com/technetwork/topics/security/cpuapr2014-1972952.html

OS impact

OSVersionStatusFixed in
debian debian6.0affected
debian debian7.0affected
debian debian8.0affected
ubuntu ubuntu10.04affected
ubuntu ubuntu12.04affected
ubuntu ubuntu12.10affected
ubuntu ubuntu13.10affected
ubuntu ubuntu14.04affected

Application impact

VendorProductVersionsFixed
oraclejrockitr27.8.1
oraclejrockitr28.3.1
juniperjunos_space{"endExcluding":"15.1"}15.1
oraclejdk1.5.0
oraclejdk1.6.0
oraclejdk1.7.0
oraclejdk1.8.0
oraclejre1.5.0
oraclejre1.6.0
oraclejre1.7.0
oraclejre1.8.0
ibmforms_viewer{"startIncluding":"4.0.0","endExcluding":"4.0.0.3"}4.0.0.3

References

Verify integrity in audit chain (admin only). AS-IS.