Sun Jdk vulnerabilities
392 known vulnerabilities affecting sun/jdk.
Total CVEs
392
CISA KEV
0
Public exploits
27
Exploited in wild
12
Severity breakdown
CRITICAL151HIGH70MEDIUM149LOW20
Vulnerabilities
Page 12 of 20
CVE-2008-5347P3HIGHCVSS 7.5≤ 6v62008-12-05
CVE-2008-5347 [HIGH] CWE-264 CVE-2008-5347: Multiple unspecified vulnerabilities in Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update
Multiple unspecified vulnerabilities in Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier allow untrusted applets and applications to gain privileges via vectors related to access to inner classes in the (1) JAX-WS and (2) JAXB packages.
nvd
CVE-2013-2407P3MEDIUMCVSS 6.4v1.6.02013-06-18
CVE-2013-2407 [MEDIUM] CVE-2013-2407: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier and 6 Update 45 and earlier, and OpenJDK 7, allows remote attackers to affect confidentiality and availability via unknown vectors related to Libraries. NOTE: the previous information is from the June 2013 CPU. Oracle has not commented on claims
nvd
CVE-2013-0432P3MEDIUMCVSS 6.4v1.6.0v1.5.0+35 more2013-02-02
CVE-2013-0432 [MEDIUM] CVE-2013-0432: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 throug
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, 5.0 through Update 38, and 1.4.2_40 and earlier, and OpenJDK 6 and 7, allows remote attackers to affect confidentiality and integrity via vectors related to AWT. NOTE: the previous information is from the February 2013 CPU. Ora
nvd
CVE-2010-0088P3MEDIUMCVSS 6.8≤ 1.6.0v1.6.0+37 more2010-04-01
CVE-2010-0088 [MEDIUM] CVE-2010-0088: Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for B
Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, 1.4.2_25, and 1.3.1_27 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors, a different vulnerability than CVE-2010-0085.
nvd
CVE-2010-0095P3MEDIUMCVSS 6.8≤ 1.6.0v1.6.0+2 more2010-04-01
CVE-2010-0095 [MEDIUM] CVE-2010-0095: Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for B
Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, and 1.4.2_25 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors, a different vulnerability than CVE-2010-0093.
nvd
CVE-2013-3829P3MEDIUMCVSS 6.4v1.6.0v1.5.02013-10-16
CVE-2013-3829 [MEDIUM] CVE-2013-3829: Unspecified vulnerability in the Java SE, Java SE Embedded component in Oracle Java SE Java SE 7u40
Unspecified vulnerability in the Java SE, Java SE Embedded component in Oracle Java SE Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, and Java SE Embedded 7u40 and earlier allows remote attackers to affect confidentiality and integrity via unknown vectors related to Libraries.
nvd
CVE-2013-5812P3MEDIUMCVSS 6.4v1.6.02013-10-16
CVE-2013-5812 [MEDIUM] CVE-2013-5812: Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, and Java SE
Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, and Java SE Embedded 7u40 and earlier allows remote attackers to affect confidentiality and availability via unknown vectors related to Deployment.
nvd
CVE-2005-3905P3HIGHCVSS 7.5v1.3v1.3.0_02+36 more2005-11-30
CVE-2005-3905 [HIGH] CVE-2005-3905: Unspecified vulnerability in reflection APIs in Java SDK and JRE 1.3.1_15 and earlier, 1.4.2_08 and
Unspecified vulnerability in reflection APIs in Java SDK and JRE 1.3.1_15 and earlier, 1.4.2_08 and earlier, and JDK and JRE 5.0 Update 3 and earlier allows remote attackers to escape the Java sandbox and access arbitrary files or execute arbitrary application via unknown attack vectors, a different vulnerability than CVE-2005-3906. NOTE: this is associated with
nvd
CVE-2008-3109P3HIGHCVSS 7.5≤ 6v62008-07-09
CVE-2008-3109 [HIGH] CWE-264 CVE-2008-3109: Unspecified vulnerability in scripting language support in Sun Java Runtime Environment (JRE) in JDK
Unspecified vulnerability in scripting language support in Sun Java Runtime Environment (JRE) in JDK and JRE 6 Update 6 and earlier allows context-dependent attackers to gain privileges via an untrusted (1) application or (2) applet, as demonstrated by an application or applet that grants itself privileges to (a) read local files, (b) write to local fil
nvd
CVE-2002-0076P4HIGHCVSS 7.5v1.1.82002-03-19
CVE-2002-0076 [HIGH] CVE-2002-0076: Java Runtime Environment (JRE) Bytecode Verifier allows remote attackers to escape the Java sandbox
Java Runtime Environment (JRE) Bytecode Verifier allows remote attackers to escape the Java sandbox and execute commands via an applet containing an illegal cast operation, as seen in (1) Microsoft VM build 3802 and earlier as used in Internet Explorer 4.x and 5.x, (2) Netscape 6.2.1 and earlier, and possibly other implementations that use vulnerable versions of
nvd
CVE-2006-6731P3CRITICALCVSS 9.3v1.5.02006-12-26
CVE-2006-6731 [CRITICAL] CVE-2006-6731: Multiple buffer overflows in Sun Java Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 U
Multiple buffer overflows in Sun Java Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 7 and earlier, Java System Development Kit (SDK) and JRE 1.4.2_12 and earlier 1.4.x versions, and SDK and JRE 1.3.1_18 and earlier allow attackers to develop Java applets that read, write, or execute local files, possibly related to (1) integer overflow
nvd
CVE-2010-3549P3MEDIUMCVSS 6.8≤ 1.6.0v1.6.0+38 more2010-10-19
CVE-2010-3549 [MEDIUM] CVE-2010-3549: Unspecified vulnerability in the Networking component in Oracle Java SE and Java for Business 6 Upda
Unspecified vulnerability in the Networking component in Oracle Java SE and Java for Business 6 Update 21, 5.0 Update 25, 1.4.2_27, and 1.3.1_28 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the October 2010 CPU. Oracle has not commented on claims from a rel
nvd
CVE-2008-3105P3HIGHCVSS 8.3≤ 6v62008-07-09
CVE-2008-3105 [HIGH] CWE-264 CVE-2008-3105: Unspecified vulnerability in the JAX-WS client and service in Sun Java Runtime Environment (JRE) in
Unspecified vulnerability in the JAX-WS client and service in Sun Java Runtime Environment (JRE) in JDK and JRE 6 Update 6 and earlier allows remote attackers to access URLs or cause a denial of service via unknown vectors involving "processing of XML data" by a trusted application.
nvd
CVE-2008-1196P3MEDIUMCVSS 6.8v1.5.0v1.6.02008-03-06
CVE-2008-1196 [MEDIUM] CWE-119 CVE-2008-1196: Stack-based buffer overflow in Java Web Start (javaws.exe) in Sun JDK and JRE 6 Update 4 and earlier
Stack-based buffer overflow in Java Web Start (javaws.exe) in Sun JDK and JRE 6 Update 4 and earlier and 5.0 Update 14 and earlier; and SDK and JRE 1.4.2_16 and earlier; allows remote attackers to execute arbitrary code via a crafted JNLP file.
nvd
CVE-2005-3907P3HIGHCVSS 7.5v1.5.0_032005-11-30
CVE-2005-3907 [HIGH] CVE-2005-3907: Unspecified vulnerability in Java Runtime Environment in Java JDK and JRE 5.0 Update 3 and earlier a
Unspecified vulnerability in Java Runtime Environment in Java JDK and JRE 5.0 Update 3 and earlier allows remote attackers to escape the Java sandbox and access arbitrary files or execute arbitrary applications via unknown attack vectors involving untrusted Java applets.
nvd
CVE-2008-0628P3HIGHCVSS 7.8v1.62008-02-06
CVE-2008-0628 [HIGH] CWE-264 CVE-2008-0628: The XML parsing code in Sun Java Runtime Environment JDK and JRE 6 Update 3 and earlier processes ex
The XML parsing code in Sun Java Runtime Environment JDK and JRE 6 Update 3 and earlier processes external entity references even when the "external general entities" property is false, which allows remote attackers to conduct XML external entity (XXE) attacks and cause a denial of service or access restricted resources.
nvd
CVE-2009-2030P3CRITICALCVSS 10.0v62009-06-11
CVE-2009-2030 [CRITICAL] CVE-2009-2030: Unspecified vulnerability in the XML Digital Signature verification functionality in JVA-RUN in JDK
Unspecified vulnerability in the XML Digital Signature verification functionality in JVA-RUN in JDK 6.0 in IBM OS/400 i5/OS V5R4M0 and V6R1M0 has unknown impact and attack vectors related to "XML SECURITY PATCH."
nvd
CVE-2009-2676P3MEDIUMCVSS 6.8≤ 1.5.0≤ 1.6.0+2 more2009-08-05
CVE-2009-2676 [MEDIUM] CVE-2009-2676: Unspecified vulnerability in JNLPAppletlauncher in Sun Java SE, and SE for Business, in JDK and JRE
Unspecified vulnerability in JNLPAppletlauncher in Sun Java SE, and SE for Business, in JDK and JRE 6 Update 14 and earlier and JDK and JRE 5.0 Update 19 and earlier; and Java SE for Business in SDK and JRE 1.4.2_21 and earlier; allows remote attackers to create or modify arbitrary files via vectors involving an untrusted Java applet that accesses an old versi
nvd
CVE-2010-3557P3MEDIUMCVSS 6.8≤ 1.6.0v1.6.0+38 more2010-10-19
CVE-2010-3557 [MEDIUM] CVE-2010-3557: Unspecified vulnerability in the Swing component in Oracle Java SE and Java for Business 6 Update 21
Unspecified vulnerability in the Swing component in Oracle Java SE and Java for Business 6 Update 21, 5.0 Update 25, 1.4.2_27, and 1.3.1_28 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the October 2010 CPU. Oracle has not commented on claims from a reliable
nvd
CVE-2009-1106P3MEDIUMCVSS 6.4v1.6.02009-03-25
CVE-2009-1106 [MEDIUM] CWE-20 CVE-2009-1106: The Java Plug-in in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 6 Update 12, 11
The Java Plug-in in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 6 Update 12, 11, and 10 does not properly parse crossdomain.xml files, which allows remote attackers to bypass intended access restrictions and connect to arbitrary sites via unknown vectors, aka CR 6798948.
nvd