CVE-2014-2403: Canonical Ubuntu Linux

Medium severity, CVSS 5.0. EPSS: 3.9% chance of exploitation in the next 30 days.

Unspecified vulnerability in Oracle Java SE 6u71, 7u51, and 8, and Java SE Embedded 7u51, allows remote attackers to affect confidentiality via vectors related to JAXP.

Affected products

  • Canonical Ubuntu Linux: version 10.04 only; version 12.04 only; version 12.10 only; version 13.10 only; version 14.04 only
  • Debian Debian Linux: version 6.0 only; version 7.0 only; version 8.0 only
  • Oracle JDK: version 1.6.0 only; version 1.7.0 only; version 1.8.0 only
  • Oracle JRE: version 1.6.0 only; version 1.7.0 only; version 1.8.0 only

Published 2014-04-16. Last modified 2026-06-17.