cbcvebase.

Sun Jdk vulnerabilities

392 known vulnerabilities affecting sun/jdk.

Total CVEs
392
CISA KEV
0
Public exploits
27
Exploited in wild
12
Severity breakdown
CRITICAL151HIGH70MEDIUM149LOW20

Vulnerabilities

Page 2 of 20
CVE-2004-1029P3CRITICALCVSS 9.3PoCv1.3.1_01v1.3.1_01a+21 more2005-03-01
CVE-2004-1029 [CRITICAL] CWE-264 CVE-2004-1029: The Sun Java Plugin capability in Java 2 Runtime Environment (JRE) 1.4.2_01, 1.4.2_04, and possibly The Sun Java Plugin capability in Java 2 Runtime Environment (JRE) 1.4.2_01, 1.4.2_04, and possibly earlier versions, does not properly restrict access between Javascript and Java applets during data transfer, which allows remote attackers to load unsafe classes and execute arbitrary code by using the reflection API to access private Java packages.
nvd
CVE-2012-0551P3MEDIUMCVSS 5.8PoCv1.6.02012-05-03
CVE-2012-0551 [MEDIUM] CVE-2012-0551: Unspecified vulnerability in the Java Runtime Environment (JRE) in Oracle Java SE 7 update 4 and ear Unspecified vulnerability in the Java Runtime Environment (JRE) in Oracle Java SE 7 update 4 and earlier and 6 update 32 and earlier, and the GlassFish Enterprise Server component in Oracle Sun Products Suite GlassFish Enterprise Server 3.1.1, allows remote attackers to affect confidentiality and integrity via unknown vectors related to Web Container or Deplo
nvd
CVE-2007-2788P3MEDIUMCVSS 6.8PoCv1.5.0v1.6.02007-05-22
CVE-2007-2788 [MEDIUM] CWE-189 CVE-2007-2788: Integer overflow in the embedded ICC profile image parser in Sun Java Development Kit (JDK) before 1 Integer overflow in the embedded ICC profile image parser in Sun Java Development Kit (JDK) before 1.5.0_11-b03 and 1.6.x before 1.6.0_01-b06, and Sun Java Runtime Environment in JDK and JRE 6, JDK and JRE 5.0 Update 10 and earlier, SDK and JRE 1.4.2_14 and earlier, and SDK and JRE 1.3.1_20 and earlier, allows remote attackers to execute arbitrary cod
nvd
CVE-2013-2419P3MEDIUMCVSS 5.0PoCv1.6.0v1.5.02013-04-17
CVE-2013-2419 [MEDIUM] CVE-2013-2419: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, 6 Update 43 and earlier, and 5.0 Update 41 and earlier; and OpenJDK 6 and 7; allows remote attackers to affect availability via unknown vectors related to 2D. NOTE: the previous information is from the April 2013 CPU. Oracle has not commented o
nvd
CVE-2007-4381P3CRITICALCVSS 9.3PoC≤ 1.5.02007-08-17
CVE-2007-4381 [CRITICAL] CVE-2007-4381: Unspecified vulnerability in the font parsing implementation in Sun JDK and JRE 5.0 Update 9 and ear Unspecified vulnerability in the font parsing implementation in Sun JDK and JRE 5.0 Update 9 and earlier, and SDK and JRE 1.4.2_14 and earlier, allows remote attackers to perform unauthorized actions via an applet that grants certain privileges to itself.
nvd
CVE-2010-3573P3MEDIUMCVSS 5.1PoC≤ 1.6.0v1.6.0+2 more2010-10-19
CVE-2010-3573 [MEDIUM] CVE-2010-3573: Unspecified vulnerability in the Networking component in Oracle Java SE and Java for Business 6 Upda Unspecified vulnerability in the Networking component in Oracle Java SE and Java for Business 6 Update 21 and 5.0 Update 25 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the October 2010 CPU. Oracle has not commented on claims from a reliable downstream vend
nvd
CVE-2010-4476P3MEDIUMCVSS 5.0PoC≤ 1.6.0v1.6.0+2 more2011-02-17
CVE-2010-4476 [MEDIUM] CVE-2010-4476: The Double.parseDouble method in Java Runtime Environment (JRE) in Oracle Java SE and Java for Busin The Double.parseDouble method in Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 23 and earlier, 5.0 Update 27 and earlier, and 1.4.2_29 and earlier, as used in OpenJDK, Apache, JBossweb, and other products, allows remote attackers to cause a denial of service via a crafted string that triggers an infinite loop of estimations d
nvd
CVE-2003-1123P3HIGHCVSS 7.5PoCv1.2.2v1.2.2_10+11 more2003-12-31
CVE-2003-1123 [HIGH] CVE-2003-1123: Sun Java Runtime Environment (JRE) and SDK 1.4.0_01 and earlier allows untrusted applets to access c Sun Java Runtime Environment (JRE) and SDK 1.4.0_01 and earlier allows untrusted applets to access certain information within trusted applets, which allows attackers to bypass the restrictions of the Java security model.
nvd
CVE-2007-0243P3MEDIUMCVSS 6.8PoC≤ 1.5.0v1.5.02007-01-17
CVE-2007-0243 [MEDIUM] CWE-119 CVE-2007-0243: Buffer overflow in Sun JDK and Java Runtime Environment (JRE) 5.0 Update 9 and earlier, SDK and JRE Buffer overflow in Sun JDK and Java Runtime Environment (JRE) 5.0 Update 9 and earlier, SDK and JRE 1.4.2_12 and earlier, and SDK and JRE 1.3.1_18 and earlier allows applets to gain privileges via a GIF image with a block with a 0 width field, which triggers memory corruption.
nvd
CVE-2013-1537P3CRITICALCVSS 10.0v1.6.0v1.5.02013-04-17
CVE-2013-1537 [CRITICAL] CVE-2013-1537: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, 6 Update 43 and earlier, and 5.0 Update 41 and earlier; and OpenJDK 6 and 7; allows remote attackers to affect confidentiality, integrity, and availability via vectors related to RMI. NOTE: the previous information is from the April 2013 CPU.
nvd
CVE-2013-2432P3CRITICALCVSS 10.0v1.6.0v1.5.02013-04-17
CVE-2013-2432 [CRITICAL] CVE-2013-2432: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, 6 Update 43 and earlier, 5.0 Update 41 and earlier, and JavaFX 2.2.7 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D, a different vulnerability than CVE-2013-2394 an
nvd
CVE-2013-0809P3CRITICALCVSS 10.0v1.6.0v1.5.02013-03-05
CVE-2013-0809 [CRITICAL] CVE-2013-0809: Unspecified vulnerability in the 2D component in the Java Runtime Environment (JRE) component in Ora Unspecified vulnerability in the 2D component in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 15 and earlier, 6 Update 41 and earlier, and 5.0 Update 40 and earlier allows remote attackers to execute arbitrary code via unknown vectors, a different vulnerability than CVE-2013-1493.
nvd
CVE-2013-5782P3CRITICALCVSS 10.0v1.5.0v1.6.02013-10-16
CVE-2013-5782 [CRITICAL] CVE-2013-5782: Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, JRockit R28.2.8 and earlier, JRockit R27.7.6 and earlier, and Java SE Embedded 7u40 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D.
nvd
CVE-2012-1541P3CRITICALCVSS 10.0v1.6.02013-02-02
CVE-2012-1541 [CRITICAL] CVE-2012-1541: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 throug Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11 and 6 through Update 38 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment, a different vulnerability than other CVEs listed in the February 2013 CPU. NOTE: the previous informa
nvd
CVE-2013-5832P3CRITICALCVSS 9.3v1.6.02013-10-16
CVE-2013-5832 [CRITICAL] CVE-2013-5832: Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, and Java SE Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, and Java SE Embedded 7u40 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment, a different vulnerability than CVE-2013-5787, CVE-2013-5789, CVE-2013-5824, and CVE-2013-5852.
nvd
CVE-2013-0442P3CRITICALCVSS 10.0v1.6.0v1.5.0+35 more2013-02-02
CVE-2013-0442 [CRITICAL] CVE-2013-0442: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 throug Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, 5.0 through Update 38, and 1.4.2_40 and earlier, and OpenJDK 6 and 7, allows remote attackers to affect confidentiality, integrity, and availability via vectors related to AWT. NOTE: the previous information is from the Febru
nvd
CVE-2013-2468P3CRITICALCVSS 10.0v1.6.02013-06-18
CVE-2013-2468 [CRITICAL] CVE-2013-2468: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier and 6 Update 45 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment, a different vulnerability than CVE-2013-2442 and CVE-2013-2466.
nvd
CVE-2008-3112P3CRITICALCVSS 10.0≤ 5.0≤ 6+2 more2008-07-09
CVE-2008-3112 [CRITICAL] CWE-264 CVE-2008-3112: Directory traversal vulnerability in Sun Java Web Start in JDK and JRE 6 before Update 7, JDK and JR Directory traversal vulnerability in Sun Java Web Start in JDK and JRE 6 before Update 7, JDK and JRE 5.0 before Update 16, and SDK and JRE 1.4.x before 1.4.2_18 allows remote attackers to create arbitrary files via the writeManifest method in the CacheEntry class, aka CR 6703909.
nvd
CVE-2013-2466P3CRITICALCVSS 10.0v1.6.02013-06-18
CVE-2013-2466 [CRITICAL] CVE-2013-2466: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier and 6 Update 45 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment, a different vulnerability than CVE-2013-2442 and CVE-2013-2468.
nvd
CVE-2013-1481P3CRITICALCVSS 10.0v1.6.0v1.5.0+35 more2013-02-02
CVE-2013-1481 [CRITICAL] CVE-2013-1481: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 6 throug Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 6 through Update 38, 5.0 through Update 38, and 1.4.2_40 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Sound.
nvd
Sun Jdk vulnerabilities | cvebase