Hacker Read top | best | new | newcomments | leaders | about | bookmarklet login
Java security update: 36 vulnerabilities, 34 remotely exploitable (www.oracle.com) similar stories update story
20.0 points by praseodym | karma 2226 | avg karma 5.12 2014-01-14 21:54:02+00:00 | hide | past | favorite | 13 comments



view as:

Anyone who uses gerrit?

Too numerous to mention.

Applet sandbox related holes only affect applets, which most Java developers don't use. There are other vulnerabilities from time to time, but the bulk are related to the browser plug in applet sandbox and related deployment exploits.

Off the top of my head Twitter, Google, Amazon and most of the largest Internet services use Java/JVM on the web...


Apple, Amazon, Twitter, Google, Red Hat etc.

There is a big difference between server side and client side Java.


that's more holes than swiss cheese has... i can't name any other software that fixes this many remote exploits in a single release...

I seem to recall that Windows 2000 had large releases to patch remotely exploitable bugs, but that was a whole other era in the field of security.

Ok well, compare it to software projects on the same scale. When you're talking about an installed base of hundreds of millions across a variety of platforms things get a little complicated.


anyone have writeups for any of these CVE's?

I'm beginning to suspect their vulerabilities are intentional, to trick me into accidentally installing the Ask toolbar.

Legal | privacy