Sun Java vulnerabilities
7 known vulnerabilities affecting sun/java.
Total CVEs
7
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH1MEDIUM1LOW2
Vulnerabilities
Page 1 of 1
CVE-2010-0887CRITICALCVSS 10.0v62010-04-20
CVE-2010-0887 [CRITICAL] CVE-2010-0887: Unspecified vulnerability in the New Java Plug-in component in Oracle Java SE and Java for Business
Unspecified vulnerability in the New Java Plug-in component in Oracle Java SE and Java for Business JDK and JRE 6 Update 18 and 19 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.
nvd
CVE-2008-3440HIGHCVSS 7.5≤ 1.6.0v1.6.02008-08-01
CVE-2008-3440 [HIGH] CWE-94 CVE-2008-3440: Sun Java 1.6.0_03 and earlier versions, and possibly later versions, does not properly verify the au
Sun Java 1.6.0_03 and earlier versions, and possibly later versions, does not properly verify the authenticity of updates, which allows man-in-the-middle attackers to execute arbitrary code via a Trojan horse update, as demonstrated by evilgrade and DNS cache poisoning.
nvd
CVE-2005-2530CRITICALCVSS 10.0v1.3.12005-12-31
CVE-2005-2530 [CRITICAL] CVE-2005-2530: Unspecified vulnerability in Java 1.3.1 before 1.3.1_16 on Apple Mac OS X allows an untrusted applet
Unspecified vulnerability in Java 1.3.1 before 1.3.1_16 on Apple Mac OS X allows an untrusted applet to gain privileges, related to "Mac OS X specific extensions."
nvd
CVE-2005-2529CRITICALCVSS 10.0v1.4.22005-12-31
CVE-2005-2529 [CRITICAL] CVE-2005-2529: Unspecified vulnerability in Java 1.4.2 before 1.4.2 Release 2 on Apple Mac OS X allows local users
Unspecified vulnerability in Java 1.4.2 before 1.4.2 Release 2 on Apple Mac OS X allows local users to gain privileges via unspecified attack vectors relating to "the utility used to update Java shared archives."
nvd
CVE-2005-2738MEDIUMCVSS 5.0v1.4.22005-12-31
CVE-2005-2738 [MEDIUM] CVE-2005-2738: Java 1.4.2 before 1.4.2 Release 2 on Apple Mac OS X does not prevent multiple programs from opening
Java 1.4.2 before 1.4.2 Release 2 on Apple Mac OS X does not prevent multiple programs from opening the same port as a Java ServerSocket, which allows local users to operate a Java program that intercepts network data intended for the ServerSocket of a different Java program.
nvd
CVE-2005-2527LOWCVSS 1.2≤ 1.4.2_release12005-12-31
CVE-2005-2527 [LOW] CWE-59 CVE-2005-2527: Race condition in Java 1.4.2 before 1.4.2 Release 2 on Apple Mac OS X allows local users to corrupt
Race condition in Java 1.4.2 before 1.4.2 Release 2 on Apple Mac OS X allows local users to corrupt files or create arbitrary files via unspecified attack vectors related to a temporary directory, possibly due to a symlink attack.
nvd
CVE-2003-1134LOWCVSS 2.1PoCv1.3.1v1.4.1+1 more2003-12-31
CVE-2003-1134 [LOW] CVE-2003-1134: Sun Java 1.3.1, 1.4.1, and 1.4.2 allows local users to cause a denial of service (JVM crash), possib
Sun Java 1.3.1, 1.4.1, and 1.4.2 allows local users to cause a denial of service (JVM crash), possibly by calling the ClassDepth function with a null parameter, which causes a crash instead of generating a null pointer exception.
nvd