← Vulnerability feed

Vulnerability record · CVE-2014-8873 · published 9 November 2015

CVE-2014-8873: Oracle openjdk improper input validation vulnerability

Oracle · Openjdk

A .desktop file in the Debian openjdk-7 package 7u79-2.5.5-1~deb8u1 includes a MIME type registration that is added to /etc/mailcap by mime-support, which allows remote attackers to execute arbitrary code via a JAR file.

10.0 CVSS 2.0 High EPSS 4.5% · top 8.7% CWE-20 · Improper input validation
10.0CVSS 2.0 base score
4.5%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References
17 Jun 2026Last modified by NVD

Description

A .desktop file in the Debian openjdk-7 package 7u79-2.5.5-1~deb8u1 includes a MIME type registration that is added to /etc/mailcap by mime-support, which allows remote attackers to execute arbitrary code via a JAR file.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2014-8873 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

5.3CVE-2013-0431Oracle JRE and OpenJDK JMX sandbox bypassAn unspecified flaw in the Java Runtime Environment (JRE) component of Oracle Java SE 7 through Update 11 and OpenJDK 7 allows a user-assisted remote…KEVEPSS 90%analysed10.0CVE-2014-2405Oracle openjdk vulnerabilityUnspecified vulnerability in OpenJDK 6 before 6b31 on Debian GNU/Linux and Ubuntu 12.04 LTS and 10.04 LTS has unknown impact and attack vectors, a di…EPSS 2.3%10.0CVE-2014-0462Oracle openjdk vulnerabilityUnspecified vulnerability in OpenJDK 6 before 6b31 on Debian GNU/Linux and Ubuntu 12.04 LTS and 10.04 LTS has unknown impact and attack vectors, a di…EPSS 2.3%9.3CVE-2014-2483Debian linux vulnerabilityUnspecified vulnerability in the Java SE component in Oracle Java SE Java SE 7u60 and OpenJDK 7 allows remote attackers to affect confidentiality, in…EPSS 5.2%8.6CVE-2021-3517Xmlsoft libxml2 out-of-bounds write vulnerabilityThere is a flaw in the xml entity encoding functionality of libxml2 in versions before 2.9.11. An attacker who is able to supply a crafted file to be…EPSS 17%8.3CVE-2020-14583Oracle openjdk vulnerabilityVulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 7u…EPSS 3.9%8.3CVE-2020-2803Oracle jdk vulnerabilityVulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 7u…EPSS 6.2%8.3CVE-2020-2805Oracle jdk vulnerabilityVulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 7u…EPSS 4.1%

Source: NIST National Vulnerability Database (record CVE-2014-8873), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.