CVE-2014-6504: Oracle JDK

Medium severity, CVSS 5.0. EPSS: 3.3% chance of exploitation in the next 30 days.

Unspecified vulnerability in Oracle Java SE 5.0u71, 6u81, and 7u67, and Java SE Embedded 7u60, allows remote attackers to affect confidentiality via unknown vectors related to Hotspot.

Affected products

  • Oracle JDK: version 1.5.0 only; version 1.6.0 only; version 1.7.0 only
  • Oracle JRE: version 1.5.0 only; version 1.6.0 only; version 1.7.0 only

Published 2014-10-15. Last modified 2026-06-17.