Oracle Jre vulnerabilities
799 known vulnerabilities affecting oracle/jre.
Total CVEs
799
CISA KEV
14
actively exploited
Public exploits
33
Exploited in wild
24
Severity breakdown
CRITICAL205HIGH121MEDIUM349LOW122
Vulnerabilities
Page 1 of 40
CVE-2012-1723P1CRITICALCVSS 9.8KEVPoCRansomware≤ 1.4.2_37v1.5.0+2 more2012-06-16
CVE-2012-1723 [CRITICAL] CWE-284 CVE-2012-1723: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update 4 and earlier, 6 update 32 and earlier, 5 update 35 and earlier, and 1.4.2_37 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Hotspot.
nvd
CVE-2012-5076P1CRITICALCVSS 9.8KEVPoCRansomwarev1.7.02012-10-16
CVE-2012-5076 [CRITICAL] CWE-284 CVE-2012-5076: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier allows remote attackers to affect confidentiality, integrity, and availability, related to JAX-WS.
nvd
CVE-2012-4681P1CRITICALCVSS 9.8KEVPoCRansomwarev1.6.0v1.7.02012-08-28
CVE-2012-4681 [CRITICAL] CWE-284 CVE-2012-4681: Multiple vulnerabilities in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update
Multiple vulnerabilities in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier allow remote attackers to execute arbitrary code via a crafted applet that bypasses SecurityManager restrictions by (1) using com.sun.beans.finder.ClassFinder.findClass and leveraging an exception with the forName method to access restric
nvd
CVE-2016-3427P1CRITICALCVSS 9.8KEVPoCv1.6.0v1.7.0+1 more2016-04-21
CVE-2016-3427 [CRITICAL] CWE-284 CVE-2016-3427: Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRocki
Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to JMX.
nvd
CVE-2013-0422P1CRITICALCVSS 9.8KEVPoCRansomwarev1.7.02013-01-10
CVE-2013-0422 [CRITICAL] CVE-2013-0422: Multiple vulnerabilities in Oracle Java 7 before Update 11 allow remote attackers to execute arbitra
Multiple vulnerabilities in Oracle Java 7 before Update 11 allow remote attackers to execute arbitrary code by (1) using the public getMBeanInstantiator method in the JmxMBeanServer class to obtain a reference to a private MBeanInstantiator object, then retrieving arbitrary Class references using the findClass method, and (2) using the Reflection API with r
nvd
CVE-2013-2465P1CRITICALCVSS 9.8KEVPoCRansomwarev1.7.0v1.6.0+1 more2013-06-18
CVE-2013-2465 [CRITICAL] CWE-693 CVE-2013-2465: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier, and OpenJDK 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D. NOTE: the previous information is from the June 2
nvd
CVE-2012-0507P1CRITICALCVSS 9.8KEVPoCRansomwarev1.6.0v1.7.02012-06-07
CVE-2012-0507 [CRITICAL] CVE-2012-0507: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, and 5.0 Update 33 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Concurrency. NOTE: the previous information was obtained from the February 201
nvd
CVE-2010-0840P1CRITICALCVSS 9.8KEVPoCRansomwarev1.4.2_25v1.5.0+1 more2010-04-01
CVE-2010-0840 [CRITICAL] CVE-2010-0840: Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for B
Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, and 1.4.2_25 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the March 2010 CPU. Oracle has not commented on claims from a
nvd
CVE-2011-3544P1CRITICALCVSS 9.8KEVPoCfixed in 1.6.0v1.6.0+1 more2011-10-19
CVE-2011-3544 [CRITICAL] CWE-284 CVE-2011-3544: Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7
Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7 and 6 Update 27 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality, integrity, and availability via unknown vectors related to Scripting.
nvd
CVE-2013-0431P1MEDIUMCVSS 5.3KEVPoCRansomwarev1.7.02013-01-31
CVE-2013-0431 [MEDIUM] CWE-693 CVE-2013-0431: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 throug
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, and OpenJDK 7, allows user-assisted remote attackers to bypass the Java security sandbox via unspecified vectors related to JMX, aka "Issue 52," a different vulnerability than CVE-2013-1490.
nvd
CVE-2013-2423P1LOWCVSS 3.7KEVPoCRansomwarev1.7.02013-04-17
CVE-2013-2423 [LOW] CWE-284 CVE-2013-2423: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, and OpenJDK 7, allows remote attackers to affect integrity via unknown vectors related to HotSpot. NOTE: the previous information is from the April 2013 CPU. Oracle has not commented on claims from the original researcher that this vulnera
nvd
CVE-2023-41993P1HIGHCVSS 8.8KEVPoCv1.8.02023-09-21
CVE-2023-41993 [HIGH] CWE-754 CVE-2023-41993: The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14. Processing web
The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14. Processing web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited against versions of iOS before iOS 16.7.
nvd
CVE-2015-2590P1CRITICALCVSS 9.8KEVv1.6.0v1.7.0+1 more2015-07-16
CVE-2015-2590 [CRITICAL] CVE-2015-2590: Unspecified vulnerability in Oracle Java SE 6u95, 7u80, and 8u45, and Java SE Embedded 7u75 and 8u33
Unspecified vulnerability in Oracle Java SE 6u95, 7u80, and 8u45, and Java SE Embedded 7u75 and 8u33 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries, a different vulnerability than CVE-2015-4732.
nvd
CVE-2015-4902P2MEDIUMCVSS 5.3KEVv1.6.0v1.7.0+1 more2015-10-22
CVE-2015-4902 [MEDIUM] CWE-284 CVE-2015-4902: Unspecified vulnerability in Oracle Java SE 6u101, 7u85, and 8u60 allows remote attackers to affect
Unspecified vulnerability in Oracle Java SE 6u101, 7u85, and 8u60 allows remote attackers to affect integrity via unknown vectors related to Deployment.
nvd
CVE-2013-1493P1CRITICALCVSS 10.0ExploitedPoCRansomware≤ 1.7.0v1.7.0+4 more2013-03-05
CVE-2013-1493 [CRITICAL] CWE-119 CVE-2013-1493: The color management (CMM) functionality in the 2D component in Oracle Java SE 7 Update 15 and earli
The color management (CMM) functionality in the 2D component in Oracle Java SE 7 Update 15 and earlier, 6 Update 41 and earlier, and 5.0 Update 40 and earlier allows remote attackers to execute arbitrary code or cause a denial of service (crash) via an image with crafted raster parameters, which triggers (1) an out-of-bounds read or (2) memory corru
nvd
CVE-2013-2460P1CRITICALCVSS 9.3ExploitedPoC≤ 1.7.0v1.7.02013-06-18
CVE-2013-2460 [CRITICAL] CVE-2013-2460: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, and OpenJDK 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Serviceability. NOTE: the previous information is from the June 2013 CPU. Oracle has not commented on claims from ano
nvd
CVE-2013-2416P2MEDIUMCVSS 4.3ExploitedPoC≤ 1.7.0v1.7.02013-04-17
CVE-2013-2416 [MEDIUM] CVE-2013-2416: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier allows remote attackers to affect integrity via unknown vectors related to Deployment.
nvd
CVE-2012-5081P1MEDIUMCVSS 5.0Exploited≤ 1.7.0v1.7.0+4 more2012-10-16
CVE-2012-5081 [MEDIUM] CVE-2012-5081: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier, 6 Update 35 and earlier, 5.0 Update 36 and earlier, and 1.4.2_38 and earlier allows remote attackers to affect availability, related to JSSE.
nvd
CVE-2013-2471P2CRITICALCVSS 10.0Exploited≤ 1.7.0v1.7.0+4 more2013-06-18
CVE-2013-2471 [CRITICAL] CVE-2013-2471: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier, and OpenJDK 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D. NOTE: the previous information is from the June 2013 CPU.
nvd
CVE-2012-3213P2CRITICALCVSS 10.0Exploitedv1.7.0v1.6.02013-02-02
CVE-2012-3213 [CRITICAL] CVE-2012-3213: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 throug
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11 and 6 through Update 38 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Scripting.
nvd
1 / 40Next →