Sun Jdk vulnerabilities
392 known vulnerabilities affecting sun/jdk.
Total CVEs
392
CISA KEV
0
Public exploits
27
Exploited in wild
12
Severity breakdown
CRITICAL151HIGH70MEDIUM149LOW20
Vulnerabilities
Page 19 of 20
CVE-2013-5797P4LOWCVSS 3.5v1.5.0v1.6.02013-10-16
CVE-2013-5797 [LOW] CVE-2013-5797: Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u
Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, JRockit R28.2.8 and earlier, JRockit R27.7.6 and earlier, and JavaFX 2.2.40 and earlier allows remote authenticated users to affect integrity via unknown vectors related to Javadoc.
nvd
CVE-2008-1194P4MEDIUMCVSS 4.3v1.5.0v1.6.02008-03-06
CVE-2008-1194 [MEDIUM] CVE-2008-1194: Multiple unspecified vulnerabilities in the color management library in Sun JDK and JRE 6 Update 4 a
Multiple unspecified vulnerabilities in the color management library in Sun JDK and JRE 6 Update 4 and earlier, and 5.0 Update 14 and earlier, allows remote attackers to cause a denial of service (crash) via unknown vectors.
nvd
CVE-2006-5201P4MEDIUMCVSS 4.0v1.5.02006-10-10
CVE-2006-5201 [MEDIUM] CVE-2006-5201: Multiple packages on Sun Solaris, including (1) NSS; (2) Java JDK and JRE 5.0 Update 8 and earlier,
Multiple packages on Sun Solaris, including (1) NSS; (2) Java JDK and JRE 5.0 Update 8 and earlier, SDK and JRE 1.4.x up to 1.4.2_12, and SDK and JRE 1.3.x up to 1.3.1_19; (3) JSSE 1.0.3_03 and earlier; (4) IPSec/IKE; (5) Secure Global Desktop; and (6) StarOffice, when using an RSA key with exponent 3, removes PKCS-1 padding before generating a hash, which all
nvd
CVE-2007-5239P4MEDIUMCVSS 4.0v1.5.0v1.6.02007-10-06
CVE-2007-5239 [MEDIUM] CWE-264 CVE-2007-5239: Java Web Start in Sun JDK and JRE 6 Update 2 and earlier, JDK and JRE 5.0 Update 12 and earlier, SDK
Java Web Start in Sun JDK and JRE 6 Update 2 and earlier, JDK and JRE 5.0 Update 12 and earlier, SDK and JRE 1.4.2_15 and earlier, and SDK and JRE 1.3.1_20 and earlier does not properly enforce access restrictions for untrusted (1) applications and (2) applets, which allows user-assisted remote attackers to copy or rename arbitrary files when local us
nvd
CVE-2013-5803P4LOWCVSS 2.6v1.6.0v1.5.02013-10-16
CVE-2013-5803 [LOW] CVE-2013-5803: Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u
Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, JRockit R28.2.8 and earlier, JRockit R27.7.6 and earlier, and Java SE Embedded 7u40 and earlier allows remote attackers to affect availability via vectors related to JGSS.
nvd
CVE-2012-5077P4LOWCVSS 2.6v1.6.0v1.6.0.200+37 more2012-10-16
CVE-2012-5077 [LOW] CVE-2012-5077: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier, 6 Update 35 and earlier, 5.0 Update 36 and earlier, and 1.4.2_38 and earlier allows remote attackers to affect confidentiality via unknown vectors related to Security.
nvd
CVE-2006-6009P4MEDIUMCVSS 5.0≤ 1.5.0v1.5.02006-11-21
CVE-2006-6009 [MEDIUM] CVE-2006-6009: Unspecified vulnerability in the Java Runtime Environment (JRE) Swing library in JDK and JRE 5.0 Upd
Unspecified vulnerability in the Java Runtime Environment (JRE) Swing library in JDK and JRE 5.0 Update 7 and earlier allows attackers to obtain certain information via unknown attack vectors, related to an untrusted applet accessing data in other applets.
nvd
CVE-2008-3110P4MEDIUMCVSS 4.3≤ 6v62008-07-09
CVE-2008-3110 [MEDIUM] CWE-264 CVE-2008-3110: Unspecified vulnerability in scripting language support in Sun Java Runtime Environment (JRE) in JDK
Unspecified vulnerability in scripting language support in Sun Java Runtime Environment (JRE) in JDK and JRE 6 Update 6 and earlier allows remote attackers to obtain sensitive information by using an applet to read information from another applet.
nvd
CVE-2006-6737P4MEDIUMCVSS 4.3v1.5.02006-12-26
CVE-2006-6737 [MEDIUM] CVE-2006-6737: Unspecified vulnerability in Sun Java Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 U
Unspecified vulnerability in Sun Java Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 5 and earlier, Java System Development Kit (SDK) and JRE 1.4.2_10 and earlier 1.4.x versions, and SDK and JRE 1.3.1_18 and earlier allows attackers to use untrusted applets to "access data in other applets," aka "The first issue."
nvd
CVE-2006-6736P4MEDIUMCVSS 4.3v1.5.02006-12-26
CVE-2006-6736 [MEDIUM] CVE-2006-6736: Unspecified vulnerability in Sun Java Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 U
Unspecified vulnerability in Sun Java Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 6 and earlier, Java System Development Kit (SDK) and JRE 1.4.2_12 and earlier 1.4.x versions, and SDK and JRE 1.3.1_18 and earlier allows attackers to use untrusted applets to "access data in other applets," aka "The second issue."
nvd
CVE-2013-2418P4MEDIUMCVSS 4.6v1.6.02013-04-17
CVE-2013-2418 [MEDIUM] CVE-2013-2418: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier and 6 Update 43 and earlier allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Deployment.
nvd
CVE-2013-5772P4LOWCVSS 2.6v1.6.02013-10-16
CVE-2013-5772 [LOW] CVE-2013-5772: Unspecified vulnerability in the Java SE component in Oracle Java SE Java SE 7u40 and earlier and Ja
Unspecified vulnerability in the Java SE component in Oracle Java SE Java SE 7u40 and earlier and Java SE 6u60 and earlier allows remote attackers to affect integrity via unknown vectors related to jhat.
nvd
CVE-2012-3216P4LOWCVSS 2.6v1.6.0v1.6.0.200+37 more2012-10-16
CVE-2012-3216 [LOW] CVE-2012-3216: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier, 6 Update 35 and earlier, 5.0 Update 36 and earlier, and 1.4.2_38 and earlier allows remote attackers to affect confidentiality via unknown vectors related to Libraries.
nvd
CVE-2011-3553P4LOWCVSS 3.5v1.7.0≤ 1.6.0+1 more2011-10-19
CVE-2011-3553 [LOW] CVE-2011-3553: Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7,
Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7, 6 Update 27 and earlier, and JRockit R28.1.4 and earlier allows remote authenticated users to affect confidentiality, related to JAXWS.
nvd
CVE-2011-3552P4LOWCVSS 2.6≤ 1.6.0v1.6.0+37 more2011-10-19
CVE-2011-3552 [LOW] CVE-2011-3552: Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7,
Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7, 6 Update 27 and earlier, 5.0 Update 31 and earlier, and 1.4.2_33 and earlier allows remote attackers to affect integrity via unknown vectors related to Networking.
nvd
CVE-2004-2540P4MEDIUMCVSS 5.0v1.4v1.4.0_01+13 more2004-12-31
CVE-2004-2540 [MEDIUM] CVE-2004-2540: readObject in (1) Java Runtime Environment (JRE) and (2) Software Development Kit (SDK) 1.4.0 throug
readObject in (1) Java Runtime Environment (JRE) and (2) Software Development Kit (SDK) 1.4.0 through 1.4.2_05 allows remote attackers to cause a denial of service (JVM unresponsive) via crafted serialized data.
nvd
CVE-2010-4472P4LOWCVSS 2.6≤ 1.6.0v1.6.02011-02-17
CVE-2010-4472 [LOW] CVE-2010-4472: Unspecified vulnerability in the Java Runtime Environment (JRE) in Oracle Java SE and Java for Busin
Unspecified vulnerability in the Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 23 and earlier allows remote attackers to affect availability, related to XML Digital Signature and unspecified APIs. NOTE: the previous information was obtained from the February 2011 CPU. Oracle has not commented on claims from a downstream vendor t
nvd
CVE-2010-3560P4LOWCVSS 2.6≤ 1.6.0v1.6.02010-10-19
CVE-2010-3560 [LOW] CVE-2010-3560: Unspecified vulnerability in the Networking component in Oracle Java SE and Java for Business 6 Upda
Unspecified vulnerability in the Networking component in Oracle Java SE and Java for Business 6 Update 21 allows remote attackers to affect confidentiality via unknown vectors.
nvd
CVE-2012-5085P4UNKNOWNCVSS 0.0v1.6.0v1.6.0.200+37 more2012-10-16
CVE-2012-5085 [NONE] CVE-2012-5085: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier, 6 Update 35 and earlier, 5.0 Update 36 and earlier, and 1.4.2_38 and earlier allows remote authenticated users to have an unspecified impact via unknown vectors related to Networking. NOTE: the Oracle CPU states that this issue has a 0.0 CVSS scor
nvd
CVE-2007-5273P4LOWCVSS 2.6v1.5.0v1.6.02007-10-08
CVE-2007-5273 [LOW] CVE-2007-5273: Sun Java Runtime Environment (JRE) in JDK and JRE 6 Update 2 and earlier, JDK and JRE 5.0 Update 12
Sun Java Runtime Environment (JRE) in JDK and JRE 6 Update 2 and earlier, JDK and JRE 5.0 Update 12 and earlier, SDK and JRE 1.4.2_15 and earlier, and SDK and JRE 1.3.1_20 and earlier, when an HTTP proxy server is used, allows remote attackers to violate the security model for an applet's outbound connections via a multi-pin DNS rebinding attack in which the appl
nvd