Sun Jdk vulnerabilities

392 known vulnerabilities affecting sun/jdk.

Total CVEs
392
CISA KEV
0
Public exploits
27
Exploited in wild
1
Severity breakdown
CRITICAL151HIGH70MEDIUM149LOW20

Vulnerabilities

Page 15 of 20
CVE-2009-3864HIGHCVSS 7.5v1.5.0v1.6.02009-11-05
CVE-2009-3864 [HIGH] CVE-2009-3864: The Java Update functionality in Java Runtime Environment (JRE) in Sun Java SE in JDK and JRE 5.0 be The Java Update functionality in Java Runtime Environment (JRE) in Sun Java SE in JDK and JRE 5.0 before Update 22 and JDK and JRE 6 before Update 17, when a non-English version of Windows is used, does not retrieve available new JRE versions, which allows remote attackers to leverage vulnerabilities in older releases of this software, aka Bug Id 6869694.
nvd
CVE-2009-3877MEDIUMCVSS 5.0v1.5.0v1.6.02009-11-05
CVE-2009-3877 [MEDIUM] CWE-399 CVE-2009-3877: Unspecified vulnerability in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before U Unspecified vulnerability in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to cause a denial of service (memory consumption) via crafted HTTP headers, which are not properly parsed by the ASN.1 DER input stream parser, ak
nvd
CVE-2009-3875MEDIUMCVSS 5.0v1.5.0v1.6.02009-11-05
CVE-2009-3875 [MEDIUM] CWE-310 CVE-2009-3875: The MessageDigest.isEqual function in Java Runtime Environment (JRE) in Sun Java SE in JDK and JRE 5 The MessageDigest.isEqual function in Java Runtime Environment (JRE) in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to spoof HMAC-based digital signatures, and possibly bypass authentication, via unspecified vectors rel
nvd
CVE-2009-3876MEDIUMCVSS 5.0v1.5.0v1.6.02009-11-05
CVE-2009-3876 [MEDIUM] CWE-399 CVE-2009-3876: Unspecified vulnerability in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before U Unspecified vulnerability in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to cause a denial of service (memory consumption) via crafted DER encoded data, which is not properly decoded by the ASN.1 DER input stream parser
nvd
CVE-2009-2675CRITICALCVSS 10.0≤ 6v5.0+1 more2009-08-05
CVE-2009-2675 [CRITICAL] CWE-264 CVE-2009-2675: Integer overflow in the unpack200 utility in Sun Java Runtime Environment (JRE) in JDK and JRE 6 bef Integer overflow in the unpack200 utility in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15, and JDK and JRE 5.0 before Update 20, allows context-dependent attackers to gain privileges via unspecified length fields in the header of a Pack200-compressed JAR file, which leads to a heap-based buffer overflow during decompression.
nvd
CVE-2009-2674HIGHCVSS 7.5v1.6.0v62009-08-05
CVE-2009-2674 [HIGH] CWE-264 CVE-2009-2674: Integer overflow in javaws.exe in Sun Java Web Start in Sun Java Runtime Environment (JRE) in JDK an Integer overflow in javaws.exe in Sun Java Web Start in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15 allows context-dependent attackers to execute arbitrary code via a crafted JPEG image that is not properly handled during display to a splash screen, which triggers a heap-based buffer overflow.
nvd
CVE-2009-2672HIGHCVSS 7.5≤ 6v5.0+1 more2009-08-05
CVE-2009-2672 [HIGH] CWE-264 CVE-2009-2672: The proxy mechanism implementation in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Upd The proxy mechanism implementation in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15, and JDK and JRE 5.0 before Update 20, does not prevent access to browser cookies by untrusted (1) applets and (2) Java Web Start applications, which allows remote attackers to hijack web sessions via unspecified vectors.
nvd
CVE-2009-2673HIGHCVSS 7.5≤ 6v5.0+1 more2009-08-05
CVE-2009-2673 [HIGH] CWE-264 CVE-2009-2673: The proxy mechanism implementation in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Upd The proxy mechanism implementation in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15, and JDK and JRE 5.0 before Update 20, allows remote attackers to bypass intended access restrictions and connect to arbitrary sites via unspecified vectors, related to a declaration that lacks the final keyword.
nvd
CVE-2009-2670MEDIUMCVSS 5.0≤ 6v5.0+1 more2009-08-05
CVE-2009-2670 [MEDIUM] CWE-264 CVE-2009-2670: The audio system in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15, and JDK an The audio system in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15, and JDK and JRE 5.0 before Update 20, does not prevent access to java.lang.System properties by (1) untrusted applets and (2) Java Web Start applications, which allows context-dependent attackers to obtain sensitive information by reading these properties.
nvd
CVE-2009-2671MEDIUMCVSS 5.0≤ 6v5.0+1 more2009-08-05
CVE-2009-2671 [MEDIUM] CVE-2009-2671: The SOCKS proxy implementation in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update The SOCKS proxy implementation in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15, and JDK and JRE 5.0 before Update 20, allows remote attackers to discover the username of the account that invoked an untrusted (1) applet or (2) Java Web Start application via unspecified vectors.
nvd
CVE-2009-2676MEDIUMCVSS 6.8≤ 1.5.0≤ 1.6.0+2 more2009-08-05
CVE-2009-2676 [MEDIUM] CVE-2009-2676: Unspecified vulnerability in JNLPAppletlauncher in Sun Java SE, and SE for Business, in JDK and JRE Unspecified vulnerability in JNLPAppletlauncher in Sun Java SE, and SE for Business, in JDK and JRE 6 Update 14 and earlier and JDK and JRE 5.0 Update 19 and earlier; and Java SE for Business in SDK and JRE 1.4.2_21 and earlier; allows remote attackers to create or modify arbitrary files via vectors involving an untrusted Java applet that accesses an old versi
nvd
CVE-2009-2030CRITICALCVSS 10.0v62009-06-11
CVE-2009-2030 [CRITICAL] CVE-2009-2030: Unspecified vulnerability in the XML Digital Signature verification functionality in JVA-RUN in JDK Unspecified vulnerability in the XML Digital Signature verification functionality in JVA-RUN in JDK 6.0 in IBM OS/400 i5/OS V5R4M0 and V6R1M0 has unknown impact and attack vectors related to "XML SECURITY PATCH."
nvd
CVE-2009-1190MEDIUMCVSS 5.0≤ 1.5.0v1.1.0+77 more2009-04-27
CVE-2009-1190 [MEDIUM] CVE-2009-1190: Algorithmic complexity vulnerability in the java.util.regex.Pattern.compile method in Sun Java Devel Algorithmic complexity vulnerability in the java.util.regex.Pattern.compile method in Sun Java Development Kit (JDK) before 1.6, when used with spring.jar in SpringSource Spring Framework 1.1.0 through 2.5.6 and 3.0.0.M1 through 3.0.0.M2 and dm Server 1.0.0 through 1.0.2, allows remote attackers to cause a denial of service (CPU consumption) via serializable
nvd
CVE-2009-1095CRITICALCVSS 10.0≤ 1.5.0v1.5.0+2 more2009-03-25
CVE-2009-1095 [CRITICAL] CWE-189 CVE-2009-1095: Integer overflow in unpack200 in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 5. Integer overflow in unpack200 in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 17 and earlier, and 6 Update 12 and earlier, allows remote attackers to access files or execute arbitrary code via a JAR file with crafted Pack200 headers.
nvd
CVE-2009-1094CRITICALCVSS 10.0≤ 1.5.0≤ 1.6.0+2 more2009-03-25
CVE-2009-1094 [CRITICAL] CVE-2009-1094: Unspecified vulnerability in the LDAP implementation in Java SE Development Kit (JDK) and Java Runti Unspecified vulnerability in the LDAP implementation in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 17 and earlier; 6 Update 12 and earlier; SDK and JRE 1.3.1_24 and earlier; and 1.4.2_19 and earlier allows remote LDAP servers to execute arbitrary code via unknown vectors related to serialized data.
nvd
CVE-2009-1096CRITICALCVSS 10.0≤ 1.5.0v1.5.0+2 more2009-03-25
CVE-2009-1096 [CRITICAL] CWE-119 CVE-2009-1096: Buffer overflow in unpack200 in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Buffer overflow in unpack200 in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 17 and earlier, and 6 Update 12 and earlier, allows remote attackers to access files or execute arbitrary code via a JAR file with crafted Pack200 headers.
nvd
CVE-2009-1097CRITICALCVSS 9.3≤ 1.6.0v1.6.02009-03-25
CVE-2009-1097 [CRITICAL] CWE-119 CVE-2009-1097: Multiple buffer overflows in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 6 Upda Multiple buffer overflows in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 6 Update 12 and earlier allow remote attackers to access files or execute arbitrary code via (1) a crafted PNG image that triggers an integer overflow during memory allocation for display on the splash screen, aka CR 6804996; and (2) a crafted GIF image fro
nvd
CVE-2009-1098CRITICALCVSS 9.3≤ 1.5.0≤ 1.6.0+2 more2009-03-25
CVE-2009-1098 [CRITICAL] CWE-119 CVE-2009-1098: Buffer overflow in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 17 an Buffer overflow in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 17 and earlier; 6 Update 12 and earlier; 1.4.2_19 and earlier; and 1.3.1_24 and earlier allows remote attackers to access files or execute arbitrary code via a crafted GIF image, aka CR 6804998.
nvd
CVE-2009-1100MEDIUMCVSS 5.0≤ 1.5.0v1.5.0+2 more2009-03-25
CVE-2009-1100 [MEDIUM] CVE-2009-1100: Multiple unspecified vulnerabilities in Java SE Development Kit (JDK) and Java Runtime Environment ( Multiple unspecified vulnerabilities in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 17 and earlier, and 6 Update 12 and earlier, allow remote attackers to cause a denial of service (disk consumption) via vectors related to temporary font files and (1) "limits on Font creation," aka CR 6522586, and (2) another unspecified vector
nvd
CVE-2009-1106MEDIUMCVSS 6.4v1.6.02009-03-25
CVE-2009-1106 [MEDIUM] CWE-20 CVE-2009-1106: The Java Plug-in in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 6 Update 12, 11 The Java Plug-in in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 6 Update 12, 11, and 10 does not properly parse crossdomain.xml files, which allows remote attackers to bypass intended access restrictions and connect to arbitrary sites via unknown vectors, aka CR 6798948.
nvd