Sun Jdk vulnerabilities
392 known vulnerabilities affecting sun/jdk.
Total CVEs
392
CISA KEV
0
Public exploits
27
Exploited in wild
12
Severity breakdown
CRITICAL151HIGH70MEDIUM149LOW20
Vulnerabilities
Page 5 of 20
CVE-2013-1569P3CRITICALCVSS 10.0v1.6.0v1.5.02013-04-17
CVE-2013-1569 [CRITICAL] CVE-2013-1569: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, 6 Update 43 and earlier, and 5.0 Update 41 and earlier; and OpenJDK 6 and 7; allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D. NOTE: the previous information is from the April 20
nvd
CVE-2011-3551P3CRITICALCVSS 9.3v1.7.0≤ 1.6.0+1 more2011-10-19
CVE-2011-3551 [CRITICAL] CVE-2011-3551: Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7,
Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7, 6 Update 27 and earlier, and JRockit R28.1.4 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D.
nvd
CVE-2013-2383P3CRITICALCVSS 10.0v1.6.0v1.5.02013-04-17
CVE-2013-2383 [CRITICAL] CVE-2013-2383: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, 6 Update 43 and earlier, and 5.0 Update 41 and earlier; and OpenJDK 6 and 7; allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D, a different vulnerability than CVE-2013-1569, CVE-2
nvd
CVE-2013-2384P3CRITICALCVSS 10.0v1.6.0v1.5.02013-04-17
CVE-2013-2384 [CRITICAL] CVE-2013-2384: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, 6 Update 43 and earlier, and 5.0 Update 41 and earlier; and OpenJDK 6 and 7; allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D, a different vulnerability than CVE-2013-1569, CVE-2
nvd
CVE-2012-3342P3CRITICALCVSS 10.0v1.6.02013-02-02
CVE-2012-3342 [CRITICAL] CVE-2012-3342: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 throug
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11 and 6 through Update 38 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment, a different vulnerability than other CVEs listed in the February 2013 CPU.
nvd
CVE-2013-0446P3CRITICALCVSS 10.0v1.6.02013-02-02
CVE-2013-0446 [CRITICAL] CVE-2013-0446: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 throug
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11 and 6 through Update 38 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment, a different vulnerability than other CVEs listed in the February 2013 CPU.
nvd
CVE-2013-1480P3CRITICALCVSS 10.0v1.6.0v1.5.0+35 more2013-02-02
CVE-2013-1480 [CRITICAL] CVE-2013-1480: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 throug
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, 5.0 through Update 38, and 1.4.2_40 and earlier, and OpenJDK 6 and 7, allows remote attackers to affect confidentiality, integrity, and availability via vectors related to AWT. NOTE: the previous information is from the Febru
nvd
CVE-2013-0428P3CRITICALCVSS 10.0v1.6.0v1.5.0+35 more2013-02-02
CVE-2013-0428 [CRITICAL] CVE-2013-0428: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 throug
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, 5.0 through Update 38, and 1.4.2_40 and earlier, and OpenJDK 6 and 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries, a different vulnerability than CVE
nvd
CVE-2013-2473P3CRITICALCVSS 10.0v1.6.0v1.5.02013-06-18
CVE-2013-2473 [CRITICAL] CVE-2013-2473: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier, and OpenJDK 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D. NOTE: the previous information is from the June 2013 CPU.
nvd
CVE-2013-2459P3CRITICALCVSS 10.0v1.6.0v1.5.02013-06-18
CVE-2013-2459 [CRITICAL] CVE-2013-2459: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier, and OpenJDK 7, allows remote attackers to affect confidentiality, integrity, and availability via vectors related to AWT. NOTE: the previous information is from the June 2013 CPU. Oracle
nvd
CVE-2010-3562P3CRITICALCVSS 10.0≤ 1.6.0v1.6.0+38 more2010-10-19
CVE-2010-3562 [CRITICAL] CVE-2010-3562: Unspecified vulnerability in the 2D component in Oracle Java SE and Java for Business 6 Update 21, 5
Unspecified vulnerability in the 2D component in Oracle Java SE and Java for Business 6 Update 21, 5.0 Update 25, 1.4.2_27, and 1.3.1_28 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the October 2010 CPU. Oracle has not commented on claims from a reliable
nvd
CVE-2010-3555P3CRITICALCVSS 9.3≤ 1.6.0v1.6.02010-10-19
CVE-2010-3555 [CRITICAL] CVE-2010-3555: Unspecified vulnerability in the Deployment component in Oracle Java SE and Java for Business 6 Upda
Unspecified vulnerability in the Deployment component in Oracle Java SE and Java for Business 6 Update 21 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the January 2011 CPU. Oracle has not commented on claims from a reliable third party coordinator that th
nvd
CVE-2013-1487P3CRITICALCVSS 10.0v1.6.02013-02-20
CVE-2013-1487 [CRITICAL] CVE-2013-1487: Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE 7 Update 13 an
Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE 7 Update 13 and earlier and 6 Update 39 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment.
nvd
CVE-2013-2394P3HIGHCVSS 7.6v1.6.0v1.5.02013-04-17
CVE-2013-2394 [HIGH] CVE-2013-2394: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, 6 Update 43 and earlier, 5.0 Update 41 and earlier, and JavaFX 2.2.7 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D, a different vulnerability than CVE-2013-2432 and CV
nvd
CVE-2010-4454P3CRITICALCVSS 10.0≤ 1.6.0v1.6.0+2 more2011-02-17
CVE-2010-4454 [CRITICAL] CVE-2010-4454: Unspecified vulnerability in the Java Runtime Environment (JRE) in Oracle Java SE and Java for Busin
Unspecified vulnerability in the Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 23 and earlier, 5.0 Update 27 and earlier, and 1.4.2_29 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Sound and unspecified APIs, a different vulnerability than CVE-2010-
nvd
CVE-2010-4462P3CRITICALCVSS 10.0≤ 1.6.0v1.6.0+2 more2011-02-17
CVE-2010-4462 [CRITICAL] CVE-2010-4462: Unspecified vulnerability in the Java Runtime Environment (JRE) in Oracle Java SE and Java for Busin
Unspecified vulnerability in the Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 23 and earlier, 5.0 Update 27 and earlier, and 1.4.2_29 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Sound and unspecified APIs, a different vulnerability than CVE-2010-
nvd
CVE-2010-4473P3CRITICALCVSS 10.0≤ 1.6.0v1.6.0+2 more2011-02-17
CVE-2010-4473 [CRITICAL] CVE-2010-4473: Unspecified vulnerability in the Java Runtime Environment (JRE) in Oracle Java SE and Java for Busin
Unspecified vulnerability in the Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 23 and earlier, 5.0 Update 27 and earlier, and 1.4.2_29 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Sound and unspecified APIs, a different vulnerability than CVE-2010-
nvd
CVE-2013-2463P3CRITICALCVSS 10.0v1.6.0v1.5.02013-06-18
CVE-2013-2463 [CRITICAL] CVE-2013-2463: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier, and OpenJDK 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D. NOTE: the previous information is from the June 2013 CPU.
nvd
CVE-2008-5359P3CRITICALCVSS 9.3v1.5.0v1.6.02008-12-05
CVE-2008-5359 [CRITICAL] CWE-119 CVE-2008-5359: Buffer overflow in Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK a
Buffer overflow in Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; SDK and JRE 1.4.2_18 and earlier; and SDK and JRE 1.3.1_23 and earlier might allow remote attackers to execute arbitrary code, related to a ConvolveOp operation in the Java AWT library.
nvd
CVE-2009-1096P3CRITICALCVSS 10.0≤ 1.5.0v1.5.0+2 more2009-03-25
CVE-2009-1096 [CRITICAL] CWE-119 CVE-2009-1096: Buffer overflow in unpack200 in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 5.0
Buffer overflow in unpack200 in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 17 and earlier, and 6 Update 12 and earlier, allows remote attackers to access files or execute arbitrary code via a JAR file with crafted Pack200 headers.
nvd