cbcvebase.

Sun Jdk vulnerabilities

392 known vulnerabilities affecting sun/jdk.

Total CVEs
392
CISA KEV
0
Public exploits
27
Exploited in wild
12
Severity breakdown
CRITICAL151HIGH70MEDIUM149LOW20

Vulnerabilities

Page 20 of 20
CVE-2011-0865P4LOWCVSS 2.6≤ 1.4.2_31v1.4.2+34 more2011-06-14
CVE-2011-0865 [LOW] CVE-2011-0865: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 6 Update Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 6 Update 25 and earlier, 5.0 Update 29 and earlier, and 1.4.2_31 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect integrity via unknown vectors related to Deserialization.
nvd
CVE-2000-1099P4MEDIUMCVSS 5.1≤ 1.2.1v1.2.1+1 more2001-01-09
CVE-2000-1099 [MEDIUM] CVE-2000-1099: Java Runtime Environment in Java Development Kit (JDK) 1.2.2_05 and earlier can allow an untrusted J Java Runtime Environment in Java Development Kit (JDK) 1.2.2_05 and earlier can allow an untrusted Java class to call into a disallowed class, which could allow an attacker to escape the Java sandbox and conduct unauthorized activities.
nvd
CVE-2011-3561P4LOWCVSS 1.8v1.7.0v1.6.02011-10-19
CVE-2011-3561 [LOW] CVE-2011-3561: Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7, Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7, 6 Update 27 and earlier, and JavaFX 2.0 allows remote attackers to affect confidentiality via unknown vectors related to Deployment.
nvd
CVE-2013-2451P4LOWCVSS 3.7v1.6.02013-06-18
CVE-2013-2451 [LOW] CVE-2013-2451: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier and 6 Update 45 and earlier, and OpenJDK 7, allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Networking. NOTE: the previous information is from the June 2013 CPU. Oracle has not commented on c
nvd
CVE-2012-1720P4LOWCVSS 3.7≤ 1.5.0≤ 1.4.2_372012-06-16
CVE-2012-1720 [LOW] CVE-2012-1720: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update 4 and earlier, 6 update 32 and earlier, 5 update 35 and earlier, and 1.4.2_37 and earlier, when running on Solaris, allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Networking.
nvd
CVE-2010-4448P4LOWCVSS 2.6≤ 1.6.0v1.6.0+2 more2011-02-17
CVE-2010-4448 [LOW] CVE-2010-4448: Unspecified vulnerability in the Java Runtime Environment (JRE) in Oracle Java SE and Java for Busin Unspecified vulnerability in the Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 23 and earlier, 5.0 Update 27 and earlier, and 1.4.2_29 earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect integrity via unknown vectors related to Networking. NOTE: the previous information was obtained f
nvd
CVE-2003-1156P4MEDIUMCVSS 4.6v1.4.2v1.4.2_022003-12-31
CVE-2003-1156 [MEDIUM] CVE-2003-1156: Java Runtime Environment (JRE) and Software Development Kit (SDK) 1.4.2 through 1.4.2_02 allows loca Java Runtime Environment (JRE) and Software Development Kit (SDK) 1.4.2 through 1.4.2_02 allows local users to overwrite arbitrary files via a symlink attack on (1) unpack.log, as created by the unpack program, or (2) .mailcap1 and .mime.types1, as created by the RPM program.
nvd
CVE-2010-4450P4LOWCVSS 3.7≤ 1.6.0v1.6.0+2 more2011-02-17
CVE-2010-4450 [LOW] CVE-2010-4450: Unspecified vulnerability in the Java Runtime Environment (JRE) in Oracle Java SE and Java for Busin Unspecified vulnerability in the Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 23 and earlier for Solaris and Linux; 5.0 Update 27 and earlier for Solaris and Linux; and 1.4.2_29 and earlier for Solaris and Linux allows local standalone applications to affect confidentiality, integrity, and availability via unknown vectors relat
nvd
CVE-2007-5238P4LOWCVSS 2.6v1.5.0v1.6.02007-10-06
CVE-2007-5238 [LOW] CWE-264 CVE-2007-5238: Java Web Start in Sun JDK and JRE 6 Update 2 and earlier, JDK and JRE 5.0 Update 12 and earlier, and Java Web Start in Sun JDK and JRE 6 Update 2 and earlier, JDK and JRE 5.0 Update 12 and earlier, and SDK and JRE 1.4.2_15 and earlier does not properly enforce access restrictions for untrusted applications, which allows user-assisted remote attackers to obtain sensitive information (the Java Web Start cache location) via an untrusted application, aka "t
nvd
CVE-2013-1500P4LOWCVSS 3.6v1.6.0v1.5.02013-06-18
CVE-2013-1500 [LOW] CVE-2013-1500: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier, and OpenJDK 7, allows local users to affect confidentiality and integrity via unknown vectors related to 2D. NOTE: the previous information is from the June 2013 CPU. Oracle has not commented
nvd
CVE-2007-5274P4LOWCVSS 2.6≤ 1.6.0v1.5.0+2 more2007-10-08
CVE-2007-5274 [LOW] CVE-2007-5274: Sun Java Runtime Environment (JRE) in JDK and JRE 6 Update 2 and earlier, JDK and JRE 5.0 Update 12 Sun Java Runtime Environment (JRE) in JDK and JRE 6 Update 2 and earlier, JDK and JRE 5.0 Update 12 and earlier, SDK and JRE 1.4.2_15 and earlier, and SDK and JRE 1.3.1_20 and earlier, when Firefox or Opera is used, allows remote attackers to violate the security model for JavaScript outbound connections via a multi-pin DNS rebinding attack dependent on the LiveC
nvd
CVE-2010-4474P4LOWCVSS 2.1≤ 1.6.0v1.6.02011-02-17
CVE-2010-4474 [LOW] CVE-2010-4474: Unspecified vulnerability in the Java DB component in Oracle Java SE and Java for Business 6 Update Unspecified vulnerability in the Java DB component in Oracle Java SE and Java for Business 6 Update 23, and, and earlier allows local users to affect confidentiality via unknown vectors related to Security, a similar vulnerability to CVE-2009-4269.
nvd
Sun Jdk vulnerabilities | cvebase