Sun Jdk vulnerabilities
392 known vulnerabilities affecting sun/jdk.
Total CVEs
392
CISA KEV
0
Public exploits
27
Exploited in wild
12
Severity breakdown
CRITICAL151HIGH70MEDIUM149LOW20
Vulnerabilities
Page 10 of 20
CVE-2009-3872P3CRITICALCVSS 9.3v1.5.0v1.6.02009-11-05
CVE-2009-3872 [CRITICAL] CVE-2009-3872: Unspecified vulnerability in the JPEG JFIF Decoder in Sun Java SE in JDK and JRE 5.0 before Update 2
Unspecified vulnerability in the JPEG JFIF Decoder in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to gain privileges via a crafted image file, aka Bug Id 6862969.
nvd
CVE-2010-4463P3CRITICALCVSS 10.0v1.6.02011-02-17
CVE-2010-4463 [CRITICAL] CVE-2010-4463: Unspecified vulnerability in the Java Runtime Environment (JRE) in Oracle Java SE and Java for Busin
Unspecified vulnerability in the Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 21 through 6 Update 23 allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality, integrity, and availability via unknown vectors related to Deployment.
nvd
CVE-2011-3557P3MEDIUMCVSS 6.8v1.7.0≤ 1.6.0+37 more2011-10-19
CVE-2011-3557 [MEDIUM] CVE-2011-3557: Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7,
Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7, 6 Update 27 and earlier, 5.0 Update 31 and earlier, 1.4.2_33 and earlier, and JRockit R28.1.4 and earlier allows remote attackers to affect confidentiality, integrity, and availability, related to RMI, a different vulnerability than CVE-2011-3556.
nvd
CVE-2009-2675P3CRITICALCVSS 10.0≤ 6v5.0+1 more2009-08-05
CVE-2009-2675 [CRITICAL] CWE-264 CVE-2009-2675: Integer overflow in the unpack200 utility in Sun Java Runtime Environment (JRE) in JDK and JRE 6 bef
Integer overflow in the unpack200 utility in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15, and JDK and JRE 5.0 before Update 20, allows context-dependent attackers to gain privileges via unspecified length fields in the header of a Pack200-compressed JAR file, which leads to a heap-based buffer overflow during decompression.
nvd
CVE-2008-3111P3CRITICALCVSS 10.0v5.0v62008-07-09
CVE-2008-3111 [CRITICAL] CWE-20 CVE-2008-3111: Multiple buffer overflows in Sun Java Web Start in JDK and JRE 6 before Update 4, JDK and JRE 5.0 be
Multiple buffer overflows in Sun Java Web Start in JDK and JRE 6 before Update 4, JDK and JRE 5.0 before Update 16, and SDK and JRE 1.4.x before 1.4.2_18 allow context-dependent attackers to gain privileges via an untrusted application, as demonstrated by (a) an application that grants itself privileges to (1) read local files, (2) write to local fil
nvd
CVE-2008-3103P3CRITICALCVSS 9.3≤ 5.0≤ 6+2 more2008-07-09
CVE-2008-3103 [CRITICAL] CWE-264 CVE-2008-3103: Unspecified vulnerability in the Java Management Extensions (JMX) management agent in Sun Java Runti
Unspecified vulnerability in the Java Management Extensions (JMX) management agent in Sun Java Runtime Environment (JRE) in JDK and JRE 6 Update 6 and earlier and JDK and JRE 5.0 Update 15 and earlier, when local monitoring is enabled, allows remote attackers to "perform unauthorized operations" via unspecified vectors.
nvd
CVE-2009-2674P3HIGHCVSS 7.5v1.6.0v62009-08-05
CVE-2009-2674 [HIGH] CWE-264 CVE-2009-2674: Integer overflow in javaws.exe in Sun Java Web Start in Sun Java Runtime Environment (JRE) in JDK an
Integer overflow in javaws.exe in Sun Java Web Start in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15 allows context-dependent attackers to execute arbitrary code via a crafted JPEG image that is not properly handled during display to a splash screen, which triggers a heap-based buffer overflow.
nvd
CVE-2010-3570P3HIGHCVSS 7.6≤ 1.6.0v1.6.02010-10-19
CVE-2010-3570 [HIGH] CVE-2010-3570: Unspecified vulnerability in the Deployment Toolkit component in Oracle Java SE and Java for Busines
Unspecified vulnerability in the Deployment Toolkit component in Oracle Java SE and Java for Business 6 Update 21 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.
nvd
CVE-2010-4451P3HIGHCVSS 7.6≤ 1.6.0v1.6.02011-02-17
CVE-2010-4451 [HIGH] CVE-2010-4451: Unspecified vulnerability in the Java Runtime Environment (JRE) in Oracle Java SE and Java for Busin
Unspecified vulnerability in the Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 23 and earlier for Windows, when using Java Update, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Install.
nvd
CVE-2010-3561P3HIGHCVSS 7.5≤ 1.6.0v1.6.0+2 more2010-10-19
CVE-2010-3561 [HIGH] CVE-2010-3561: Unspecified vulnerability in the CORBA component in Oracle Java SE and Java for Business 6 Update 21
Unspecified vulnerability in the CORBA component in Oracle Java SE and Java for Business 6 Update 21 and 5.0 Update 25 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the October 2010 CPU. Oracle has not commented on claims from a reliable downstream vendor that
nvd
CVE-2008-0657P3CRITICALCVSS 10.0≤ 5.0_update132008-02-07
CVE-2008-0657 [CRITICAL] CWE-264 CVE-2008-0657: Multiple unspecified vulnerabilities in the Java Runtime Environment in Sun JDK and JRE 6 Update 1 a
Multiple unspecified vulnerabilities in the Java Runtime Environment in Sun JDK and JRE 6 Update 1 and earlier, and 5.0 Update 13 and earlier, allow context-dependent attackers to gain privileges via an untrusted (1) application or (2) applet, as demonstrated by an application or applet that grants itself privileges to (a) read local files, (b) writ
nvd
CVE-2009-3873P3CRITICALCVSS 9.3v1.5.0v1.6.02009-11-05
CVE-2009-3873 [CRITICAL] CWE-119 CVE-2009-3873: The JPEG Image Writer in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Updat
The JPEG Image Writer in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to gain privileges via a crafted image file, related to a "quantization problem," aka Bug Id 6862968.
nvd
CVE-2008-5352P3CRITICALCVSS 9.3≤ 5.0≤ 6+2 more2008-12-05
CVE-2008-5352 [CRITICAL] CWE-189 CVE-2008-5352: Integer overflow in the JAR unpacking utility (unpack200) in the unpack library (unpack.dll) in Java
Integer overflow in the JAR unpacking utility (unpack200) in the unpack library (unpack.dll) in Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier, and JDK and JRE 5.0 Update 16 and earlier, allows untrusted applications and applets to gain privileges via a Pack200 compressed JAR file that triggers a heap-based buffer overflo
nvd
CVE-2008-1185P3CRITICALCVSS 9.3v1.5.0v1.6.02008-03-06
CVE-2008-1185 [CRITICAL] CWE-264 CVE-2008-1185: Unspecified vulnerability in the Virtual Machine for Sun Java Runtime Environment (JRE) and JDK 6 Up
Unspecified vulnerability in the Virtual Machine for Sun Java Runtime Environment (JRE) and JDK 6 Update 4 and earlier, 5.0 Update 14 and earlier, and SDK/JRE 1.4.2_16 and earlier allows remote attackers to gain privileges via an untrusted application or applet, a different issue than CVE-2008-1186, aka "the first issue."
nvd
CVE-2008-1186P3CRITICALCVSS 9.3v1.5.02008-03-06
CVE-2008-1186 [CRITICAL] CVE-2008-1186: Unspecified vulnerability in the Virtual Machine for Sun Java Runtime Environment (JRE) and JDK 5.0
Unspecified vulnerability in the Virtual Machine for Sun Java Runtime Environment (JRE) and JDK 5.0 Update 13 and earlier, and SDK/JRE 1.4.2_16 and earlier, allows remote attackers to gain privileges via an untrusted application or applet, a different issue than CVE-2008-1185, aka "the second issue."
nvd
CVE-2010-0837P3HIGHCVSS 7.5≤ 1.6.0v1.6.0+2 more2010-04-01
CVE-2010-0837 [HIGH] CVE-2010-0837: Unspecified vulnerability in the Pack200 component in Oracle Java SE and Java for Business 6 Update
Unspecified vulnerability in the Pack200 component in Oracle Java SE and Java for Business 6 Update 18, 5.0, Update, and 23 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.
nvd
CVE-2010-0850P3HIGHCVSS 7.5≤ 1.3.1_27v1.3.0+33 more2010-04-01
CVE-2010-0850 [HIGH] CVE-2010-0850: Unspecified vulnerability in the Java 2D component in Oracle Java SE and Java for Business 1.3.1_27
Unspecified vulnerability in the Java 2D component in Oracle Java SE and Java for Business 1.3.1_27 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.
nvd
CVE-2013-5804P3MEDIUMCVSS 6.4v1.5.0v1.6.02013-10-16
CVE-2013-5804 [MEDIUM] CVE-2013-5804: Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u
Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, JRockit R28.2.8 and earlier, and JRockit R27.7.6 and earlier allows remote attackers to affect confidentiality and integrity via unknown vectors related to Javadoc.
nvd
CVE-2008-3115P3HIGHCVSS 7.5≤ 6v5.0+1 more2008-07-09
CVE-2008-3115 [HIGH] CWE-16 CVE-2008-3115: Secure Static Versioning in Sun Java JDK and JRE 6 Update 6 and earlier, and 5.0 Update 6 through 15
Secure Static Versioning in Sun Java JDK and JRE 6 Update 6 and earlier, and 5.0 Update 6 through 15, does not properly prevent execution of applets on older JRE releases, which might allow remote attackers to exploit vulnerabilities in these older releases.
nvd
CVE-2012-0547P4UNKNOWNCVSS 0.0PoCv1.6.02012-08-30
CVE-2012-0547 [NONE] CVE-2012-0547: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier, and 6 Update 34 and earlier, has no impact and remote attack vectors involving AWT and "a security-in-depth issue that is not directly exploitable but which can be used to aggravate security vulnerabilities that can be directly exploited." NOTE: t
nvd