Sun Jdk vulnerabilities
392 known vulnerabilities affecting sun/jdk.
Total CVEs
392
CISA KEV
0
Public exploits
27
Exploited in wild
12
Severity breakdown
CRITICAL151HIGH70MEDIUM149LOW20
Vulnerabilities
Page 18 of 20
CVE-2010-0091P4MEDIUMCVSS 4.3≤ 1.6.0v1.6.0+2 more2010-04-01
CVE-2010-0091 [MEDIUM] CVE-2010-0091: Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for B
Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, and 1.4.2_25 allows remote attackers to affect confidentiality via unknown vectors, a different vulnerability than CVE-2010-0084.
nvd
CVE-2013-0430P4MEDIUMCVSS 6.9v1.6.02013-02-02
CVE-2013-0430 [MEDIUM] CVE-2013-0430: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 throug
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11 and 6 through Update 38, allows local users to affect confidentiality, integrity, and availability via unknown vectors related to the installation process of the client.
nvd
CVE-2013-2439P4MEDIUMCVSS 6.9v1.6.0v1.5.02013-04-17
CVE-2013-2439 [MEDIUM] CVE-2013-2439: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, 6 Update 43 and earlier, 5.0 Update 41 and earlier, and JavaFX 2.2.7 and earlier allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Install.
nvd
CVE-2007-5236P4MEDIUMCVSS 5.4v1.5.02007-10-06
CVE-2007-5236 [MEDIUM] CWE-264 CVE-2007-5236: Java Web Start in Sun JDK and JRE 5.0 Update 12 and earlier, and SDK and JRE 1.4.2_15 and earlier, o
Java Web Start in Sun JDK and JRE 5.0 Update 12 and earlier, and SDK and JRE 1.4.2_15 and earlier, on Windows does not properly enforce access restrictions for untrusted applications, which allows user-assisted remote attackers to read local files via an untrusted application.
nvd
CVE-2009-2670P4MEDIUMCVSS 5.0≤ 6v5.0+1 more2009-08-05
CVE-2009-2670 [MEDIUM] CWE-264 CVE-2009-2670: The audio system in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15, and JDK an
The audio system in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15, and JDK and JRE 5.0 before Update 20, does not prevent access to java.lang.System properties by (1) untrusted applets and (2) Java Web Start applications, which allows context-dependent attackers to obtain sensitive information by reading these properties.
nvd
CVE-2008-5342P4MEDIUMCVSS 5.0≤ 5.0≤ 6+2 more2008-12-05
CVE-2008-5342 [MEDIUM] CWE-200 CVE-2008-5342: Unspecified vulnerability in the BasicService for Java Web Start (JWS) and Java Plug-in with Sun JDK
Unspecified vulnerability in the BasicService for Java Web Start (JWS) and Java Plug-in with Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier allows untrusted downloaded applications to cause local files to be displayed in the browser of the user of the untrusted application via unkno
nvd
CVE-2006-0615P4MEDIUMCVSS 4.0v1.5.02006-02-09
CVE-2006-0615 [MEDIUM] CVE-2006-0615: Multiple unspecified vulnerabilities in Sun Java JDK and JRE 5.0 Update 4 and earlier, SDK and JRE 1
Multiple unspecified vulnerabilities in Sun Java JDK and JRE 5.0 Update 4 and earlier, SDK and JRE 1.4.x through 1.4.2_09 allow remote attackers to bypass Java sandbox security and obtain privileges via unspecified vectors involving the reflection APIs, aka the "second and third issues."
nvd
CVE-2006-0617P4MEDIUMCVSS 4.0≤ 1.5.02006-02-09
CVE-2006-0617 [MEDIUM] CVE-2006-0617: Multiple unspecified vulnerabilities in Sun Java JDK and JRE 5.0 Update 5 and earlier allow remote a
Multiple unspecified vulnerabilities in Sun Java JDK and JRE 5.0 Update 5 and earlier allow remote attackers to bypass Java sandbox security and obtain privileges via unspecified vectors involving the reflection APIs, aka the "fifth, sixth, and seventh issues."
nvd
CVE-2010-4475P4MEDIUMCVSS 4.3≤ 1.6.0v1.6.0+2 more2011-02-17
CVE-2010-4475 [MEDIUM] CVE-2010-4475: Unspecified vulnerability in the Java Runtime Environment (JRE) in Oracle Java SE and Java for Busin
Unspecified vulnerability in the Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 23 and earlier, 5.0 Update 27 and earlier, and 1.4.2_29 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality via unknown vectors related to Deployment, a different vulnerability than C
nvd
CVE-2008-5341P4MEDIUMCVSS 5.0≤ 5.0≤ 6+2 more2008-12-05
CVE-2008-5341 [MEDIUM] CWE-200 CVE-2008-5341: Unspecified vulnerability in Java Web Start (JWS) and Java Plug-in with Sun JDK and JRE 6 Update 10
Unspecified vulnerability in Java Web Start (JWS) and Java Plug-in with Sun JDK and JRE 6 Update 10 and earlier, and JDK and JRE 5.0 Update 16 and earlier, allows untrusted JWS applications to obtain the pathname of the JWS cache and the application username via unknown vectors, aka CR 6727071.
nvd
CVE-2007-2789P4MEDIUMCVSS 4.3v1.5.0v1.6.02007-05-22
CVE-2007-2789 [MEDIUM] CWE-399 CVE-2007-2789: The BMP image parser in Sun Java Development Kit (JDK) before 1.5.0_11-b03 and 1.6.x before 1.6.0_01
The BMP image parser in Sun Java Development Kit (JDK) before 1.5.0_11-b03 and 1.6.x before 1.6.0_01-b06, and Sun Java Runtime Environment in JDK and JRE 6, JDK and JRE 5.0 Update 10 and earlier, SDK and JRE 1.4.2_14 and earlier, and SDK and JRE 1.3.1_19 and earlier, when running on Unix/Linux systems, allows remote attackers to cause a denial of serv
nvd
CVE-2008-3106P4MEDIUMCVSS 4.3≤ 5.0≤ 6+2 more2008-07-09
CVE-2008-3106 [MEDIUM] CVE-2008-3106: Unspecified vulnerability in Sun Java Runtime Environment (JRE) in JDK and JRE 6 Update 6 and earlie
Unspecified vulnerability in Sun Java Runtime Environment (JRE) in JDK and JRE 6 Update 6 and earlier and JDK and JRE 5.0 Update 15 and earlier allows remote attackers to access URLs via unknown vectors involving processing of XML data by an untrusted (1) application or (2) applet, a different vulnerability than CVE-2008-3105.
nvd
CVE-2010-4447P4MEDIUMCVSS 4.3≤ 1.6.0v1.6.0+2 more2011-02-17
CVE-2010-4447 [MEDIUM] CVE-2010-4447: Unspecified vulnerability in the Java Runtime Environment (JRE) in Oracle Java SE and Java for Busin
Unspecified vulnerability in the Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 23 and earlier, 5.0 Update 27 and earlier, and 1.4.2_29 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality via unknown vectors related to Deployment, a different vulnerability than C
nvd
CVE-2013-2467P4MEDIUMCVSS 6.9v1.5.02013-06-18
CVE-2013-2467 [MEDIUM] CVE-2013-2467: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 5.0 Upda
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 5.0 Update 45 and earlier allows local users to affect confidentiality, integrity, and availability via unknown vectors related to the Java installer.
nvd
CVE-2008-3114P4MEDIUMCVSS 5.0≤ 5.0≤ 6+2 more2008-07-09
CVE-2008-3114 [MEDIUM] CWE-200 CVE-2008-3114: Unspecified vulnerability in Sun Java Web Start in JDK and JRE 6 before Update 7, JDK and JRE 5.0 be
Unspecified vulnerability in Sun Java Web Start in JDK and JRE 6 before Update 7, JDK and JRE 5.0 before Update 16, and SDK and JRE 1.4.x before 1.4.2_18 allows context-dependent attackers to obtain sensitive information (the cache location) via an untrusted application, aka CR 6704074.
nvd
CVE-2009-1190P4MEDIUMCVSS 5.0≤ 1.5.0v1.1.0+77 more2009-04-27
CVE-2009-1190 [MEDIUM] CVE-2009-1190: Algorithmic complexity vulnerability in the java.util.regex.Pattern.compile method in Sun Java Devel
Algorithmic complexity vulnerability in the java.util.regex.Pattern.compile method in Sun Java Development Kit (JDK) before 1.6, when used with spring.jar in SpringSource Spring Framework 1.1.0 through 2.5.6 and 3.0.0.M1 through 3.0.0.M2 and dm Server 1.0.0 through 1.0.2, allows remote attackers to cause a denial of service (CPU consumption) via serializable
nvd
CVE-2002-0058P4MEDIUMCVSS 5.0v1.1.82002-03-15
CVE-2002-0058 [MEDIUM] CVE-2002-0058: Vulnerability in Java Runtime Environment (JRE) allows remote malicious web sites to hijack or sniff
Vulnerability in Java Runtime Environment (JRE) allows remote malicious web sites to hijack or sniff a web client's sessions, when an HTTP proxy is being used, via a Java applet that redirects the session to another server, as seen in (1) Netscape 6.0 through 6.1 and 4.79 and earlier, (2) Microsoft VM build 3802 and earlier as used in Internet Explorer 4.x an
nvd
CVE-2006-0616P4MEDIUMCVSS 4.0≤ 1.5.02006-02-09
CVE-2006-0616 [MEDIUM] CVE-2006-0616: Unspecified vulnerability in Sun Java JDK and JRE 5.0 Update 4 and earlier allows remote attackers t
Unspecified vulnerability in Sun Java JDK and JRE 5.0 Update 4 and earlier allows remote attackers to bypass Java sandbox security and obtain privileges via unspecified vectors involving the reflection APIs, aka the "fourth issue."
nvd
CVE-2007-5232P4MEDIUMCVSS 4.0v1.5.0v1.6.02007-10-05
CVE-2007-5232 [MEDIUM] CVE-2007-5232: Sun Java Runtime Environment (JRE) in JDK and JRE 6 Update 2 and earlier, JDK and JRE 5.0 Update 12
Sun Java Runtime Environment (JRE) in JDK and JRE 6 Update 2 and earlier, JDK and JRE 5.0 Update 12 and earlier, SDK and JRE 1.4.2_15 and earlier, and SDK and JRE 1.3.1_20 and earlier, when applet caching is enabled, allows remote attackers to violate the security model for an applet's outbound connections via a DNS rebinding attack.
nvd
CVE-2010-4468P4MEDIUMCVSS 4.0≤ 1.6.0v1.6.0+2 more2011-02-17
CVE-2010-4468 [MEDIUM] CVE-2010-4468: Unspecified vulnerability in the Java Runtime Environment (JRE) in Oracle Java SE and Java for Busin
Unspecified vulnerability in the Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 23 and earlier, and 5.0 Update 27 and earlier, allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality and integrity via unknown vectors related to JDBC.
nvd