Sun Jdk vulnerabilities
392 known vulnerabilities affecting sun/jdk.
Total CVEs
392
CISA KEV
0
Public exploits
27
Exploited in wild
12
Severity breakdown
CRITICAL151HIGH70MEDIUM149LOW20
Vulnerabilities
Page 11 of 20
CVE-2010-0848P3HIGHCVSS 7.5≤ 1.6.0v1.6.0+37 more2010-04-01
CVE-2010-0848 [HIGH] CVE-2010-0848: Unspecified vulnerability in the Java 2D component in Oracle Java SE and Java for Business 6 Update
Unspecified vulnerability in the Java 2D component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, 1.4.2_25, and 1.3.1_27 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.
nvd
CVE-2010-0839P3HIGHCVSS 7.5≤ 1.6.0v1.6.0+37 more2010-04-01
CVE-2010-0839 [HIGH] CVE-2010-0839: Unspecified vulnerability in the Sound component in Oracle Java SE and Java for Business 6 Update 18
Unspecified vulnerability in the Sound component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, 1.4.2_25, and 1.3.1_27 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.
nvd
CVE-2008-5344P3HIGHCVSS 7.5≤ 5.0≤ 6+2 more2008-12-05
CVE-2008-5344 [HIGH] CVE-2008-5344: Unspecified vulnerability in Java Web Start (JWS) and Java Plug-in with Sun JDK and JRE 6 Update 10
Unspecified vulnerability in Java Web Start (JWS) and Java Plug-in with Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier allows untrusted applets to read arbitrary files and make unauthorized network connections via unknown vectors related to applet classloading, aka 6716217.
nvd
CVE-2011-0866P3HIGHCVSS 7.6≤ 1.4.2_31v1.4.2+34 more2011-06-14
CVE-2011-0866 [HIGH] CVE-2011-0866: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 6 Update
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 6 Update 25 and earlier, 5.0 Update 29 and earlier, and 1.4.2_31 and earlier, when running on Windows, allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality, integrity, and availability via unknown vectors related to Jav
nvd
CVE-2007-3716P3CRITICALCVSS 9.3≤ 62007-07-11
CVE-2007-3716 [CRITICAL] CVE-2007-3716: The Java XML Digital Signature implementation in Sun JDK and JRE 6 before Update 2 does not properly
The Java XML Digital Signature implementation in Sun JDK and JRE 6 before Update 2 does not properly process XSLT stylesheets in XSLT transforms in XML signatures, which allows context-dependent attackers to execute arbitrary code via a crafted stylesheet, a related issue to CVE-2007-3715.
nvd
CVE-2013-5783P3MEDIUMCVSS 6.4v1.5.0v1.6.02013-10-16
CVE-2013-5783 [MEDIUM] CVE-2013-5783: Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u
Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, and Java SE Embedded 7u40 and earlier allows remote attackers to affect confidentiality and integrity via unknown vectors related to Swing.
nvd
CVE-2012-5071P3MEDIUMCVSS 6.4v1.6.0v1.6.0.200+2 more2012-10-16
CVE-2012-5071 [MEDIUM] CVE-2012-5071: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier, 6 Update 35 and earlier, and 5.0 Update 36 and earlier allows remote attackers to affect confidentiality and integrity, related to JMX.
nvd
CVE-2010-0087P3HIGHCVSS 7.5≤ 1.6.0v1.6.0+37 more2010-04-01
CVE-2010-0087 [HIGH] CVE-2010-0087: Unspecified vulnerability in the Java Web Start, Java Plug-in component in Oracle Java SE and Java f
Unspecified vulnerability in the Java Web Start, Java Plug-in component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, 1.4.2_25, and 1.3.1_27 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.
nvd
CVE-2011-0706P3HIGHCVSS 7.5v1.6.02011-02-19
CVE-2011-0706 [HIGH] CWE-264 CVE-2011-0706: The JNLPClassLoader class in IcedTea-Web before 1.0.1, as used in OpenJDK Runtime Environment 1.6.0,
The JNLPClassLoader class in IcedTea-Web before 1.0.1, as used in OpenJDK Runtime Environment 1.6.0, allows remote attackers to gain privileges via unknown vectors related to multiple signers and the assignment of "an inappropriate security descriptor."
nvd
CVE-2011-3516P3HIGHCVSS 7.6≤ 1.6.0v1.6.02011-10-19
CVE-2011-3516 [HIGH] CVE-2011-3516: Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 6
Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 6 Update 27 and earlier, when running on Windows, allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality, integrity, and availability via unknown vectors related to Deployment.
nvd
CVE-2011-0786P3HIGHCVSS 7.6≤ 1.6.0v1.6.02011-06-14
CVE-2011-0786 [HIGH] CVE-2011-0786: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 6 Update
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 6 Update 25 and earlier, when running on Windows, allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality, integrity, and availability via unknown vectors related to Deployment, a different vulnerability than CVE-2011-0788
nvd
CVE-2011-0788P3HIGHCVSS 7.6≤ 1.6.0v1.6.02011-06-14
CVE-2011-0788 [HIGH] CVE-2011-0788: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 6 Update
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 6 Update 25 and earlier, when running on Windows, allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality, integrity, and availability via unknown vectors related to Deployment, a different vulnerability than CVE-2011-0786
nvd
CVE-2012-1695P3MEDIUMCVSS 6.8v5.0v62012-05-03
CVE-2012-1695 [MEDIUM] CVE-2012-1695: Unspecified vulnerability in the Oracle JRockit component in Oracle Fusion Middleware 28.2.2 and ear
Unspecified vulnerability in the Oracle JRockit component in Oracle Fusion Middleware 28.2.2 and earlier, and JDK/JRE 5 and 6 27.7.1 and earlier, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.
nvd
CVE-2012-4416P3MEDIUMCVSS 6.4v1.6.0v1.6.0.200+1 more2012-10-16
CVE-2012-4416 [MEDIUM] CVE-2012-4416: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier, and 6 Update 35 and earlier, allows remote attackers to affect confidentiality and integrity via unknown vectors related to Hotspot.
nvd
CVE-2008-1189P3MEDIUMCVSS 6.8v1.5.0v1.6.02008-03-06
CVE-2008-1189 [MEDIUM] CVE-2008-1189: Buffer overflow in Java Web Start in Sun JDK and JRE 6 Update 4 and earlier, 5.0 Update 14 and earli
Buffer overflow in Java Web Start in Sun JDK and JRE 6 Update 4 and earlier, 5.0 Update 14 and earlier, and SDK/JRE 1.4.2_16 and earlier allows remote attackers to execute arbitrary code via unknown vectors, a different issue than CVE-2008-1188, aka the "third" issue.
nvd
CVE-2005-3904P3HIGHCVSS 7.5v1.5.0_032005-11-30
CVE-2005-3904 [HIGH] CVE-2005-3904: Unspecified vulnerability in Java Management Extensions (JMX) in Java JDK and JRE 5.0 Update 3, 1.4.
Unspecified vulnerability in Java Management Extensions (JMX) in Java JDK and JRE 5.0 Update 3, 1.4.2 and later, 1.3.1 and later allows remote attackers to escape the Java sandbox and access arbitrary files or execute arbitrary application via unknown attack vectors.
nvd
CVE-2008-5345P3HIGHCVSS 7.5v1.5.0v1.6.02008-12-05
CVE-2008-5345 [HIGH] CVE-2008-5345: Unspecified vulnerability in Java Runtime Environment (JRE) with Sun JDK and JRE 6 Update 10 and ear
Unspecified vulnerability in Java Runtime Environment (JRE) with Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; SDK and JRE 1.4.2_18 and earlier; and SDK and JRE 1.3.1_23 and earlier allows code that is loaded from a local filesystem to read arbitrary files and make unauthorized connections to localhost via unknown vectors.
nvd
CVE-2008-5351P3HIGHCVSS 7.5≤ 5.0≤ 6+2 more2008-12-05
CVE-2008-5351 [HIGH] CWE-264 CVE-2008-5351: Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 1
Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier accepts UTF-8 encodings that are not the "shortest" form, which makes it easier for attackers to bypass protection mechanisms for other applications that rely on shortest-form UTF-8 encodings.
nvd
CVE-2011-3550P3HIGHCVSS 7.6v1.7.0≤ 1.6.0+1 more2011-10-19
CVE-2011-3550 [HIGH] CVE-2011-3550: Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7,
Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7, 6 Update 27 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality, integrity, and availability, related to AWT.
nvd
CVE-2009-2672P3HIGHCVSS 7.5≤ 6v5.0+1 more2009-08-05
CVE-2009-2672 [HIGH] CWE-264 CVE-2009-2672: The proxy mechanism implementation in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Upd
The proxy mechanism implementation in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15, and JDK and JRE 5.0 before Update 20, does not prevent access to browser cookies by untrusted (1) applets and (2) Java Web Start applications, which allows remote attackers to hijack web sessions via unspecified vectors.
nvd