Sun Jdk vulnerabilities

392 known vulnerabilities affecting sun/jdk.

Total CVEs
392
CISA KEV
0
Public exploits
27
Exploited in wild
1
Severity breakdown
CRITICAL151HIGH70MEDIUM149LOW20

Vulnerabilities

Page 5 of 20
CVE-2013-2429HIGHCVSS 7.6v1.6.0v1.5.02013-04-17
CVE-2013-2429 [HIGH] CVE-2013-2429: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, 6 Update 43 and earlier, and 5.0 Update 41 and earlier; and OpenJDK 6 and 7; allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to ImageIO. NOTE: the previous information is from the April 2
nvd
CVE-2013-2430HIGHCVSS 7.6v1.6.0v1.5.02013-04-17
CVE-2013-2430 [HIGH] CVE-2013-2430: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, 6 Update 43 and earlier, and 5.0 Update 41 and earlier; JavaFX 2.2.7 and earlier; and OpenJDK 6 and 7 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to ImageIO. NOTE: the previous inform
nvd
CVE-2013-1540MEDIUMCVSS 4.3v1.6.02013-04-17
CVE-2013-1540 [MEDIUM] CVE-2013-1540: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier and 6 Update 43 and earlier allows remote attackers to affect integrity via unknown vectors related to Deployment, a different vulnerability than CVE-2013-2433.
nvd
CVE-2013-2424MEDIUMCVSS 5.0v1.6.0v1.5.02013-04-17
CVE-2013-2424 [MEDIUM] CVE-2013-2424: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, 6 Update 43 and earlier, and 5.0 Update 41 and earlier; and OpenJDK 6 and 7; allows remote attackers to affect confidentiality via vectors related to JMX. NOTE: the previous information is from the April 2013 CPU. Oracle has not commented on cl
nvd
CVE-2013-2419MEDIUMCVSS 5.0PoCv1.6.0v1.5.02013-04-17
CVE-2013-2419 [MEDIUM] CVE-2013-2419: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, 6 Update 43 and earlier, and 5.0 Update 41 and earlier; and OpenJDK 6 and 7; allows remote attackers to affect availability via unknown vectors related to 2D. NOTE: the previous information is from the April 2013 CPU. Oracle has not commented o
nvd
CVE-2013-2418MEDIUMCVSS 4.6v1.6.02013-04-17
CVE-2013-2418 [MEDIUM] CVE-2013-2418: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier and 6 Update 43 and earlier allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Deployment.
nvd
CVE-2013-2417MEDIUMCVSS 5.0v1.6.0v1.5.02013-04-17
CVE-2013-2417 [MEDIUM] CVE-2013-2417: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, 6 Update 43 and earlier, and 5.0 Update 41 and earlier; and OpenJDK 6 and 7; allows remote attackers to affect availability via unknown vectors related to Networking. NOTE: the previous information is from the April 2013 CPU. Oracle has not com
nvd
CVE-2013-2439MEDIUMCVSS 6.9v1.6.0v1.5.02013-04-17
CVE-2013-2439 [MEDIUM] CVE-2013-2439: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, 6 Update 43 and earlier, 5.0 Update 41 and earlier, and JavaFX 2.2.7 and earlier allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Install.
nvd
CVE-2013-2433MEDIUMCVSS 4.3v1.6.02013-04-17
CVE-2013-2433 [MEDIUM] CVE-2013-2433: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier and 6 Update 43 and earlier allows remote attackers to affect integrity via unknown vectors related to Deployment, a different vulnerability than CVE-2013-1540.
nvd
CVE-2013-0809CRITICALCVSS 10.0v1.6.0v1.5.02013-03-05
CVE-2013-0809 [CRITICAL] CVE-2013-0809: Unspecified vulnerability in the 2D component in the Java Runtime Environment (JRE) component in Ora Unspecified vulnerability in the 2D component in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 15 and earlier, 6 Update 41 and earlier, and 5.0 Update 40 and earlier allows remote attackers to execute arbitrary code via unknown vectors, a different vulnerability than CVE-2013-1493.
nvd
CVE-2013-1493CRITICALCVSS 10.0ExploitedPoCv1.6.0v1.5.02013-03-05
CVE-2013-1493 [CRITICAL] CWE-119 CVE-2013-1493: The color management (CMM) functionality in the 2D component in Oracle Java SE 7 Update 15 and earli The color management (CMM) functionality in the 2D component in Oracle Java SE 7 Update 15 and earlier, 6 Update 41 and earlier, and 5.0 Update 40 and earlier allows remote attackers to execute arbitrary code or cause a denial of service (crash) via an image with crafted raster parameters, which triggers (1) an out-of-bounds read or (2) memory corru
nvd
CVE-2013-1487CRITICALCVSS 10.0v1.6.02013-02-20
CVE-2013-1487 [CRITICAL] CVE-2013-1487: Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE 7 Update 13 an Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE 7 Update 13 and earlier and 6 Update 39 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment.
nvd
CVE-2013-1486CRITICALCVSS 10.0v1.6.0v1.5.02013-02-20
CVE-2013-1486 [CRITICAL] CVE-2013-1486: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 13 and earlier, 6 Update 39 and earlier, and 5.0 Update 39 and earlier allows remote attackers to affect confidentiality, integrity, and availability via vectors related to JMX.
nvd
CVE-2012-3213CRITICALCVSS 10.0v1.6.02013-02-02
CVE-2012-3213 [CRITICAL] CVE-2012-3213: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 throug Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11 and 6 through Update 38 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Scripting.
nvd
CVE-2013-1481CRITICALCVSS 10.0v1.6.0v1.5.0+35 more2013-02-02
CVE-2013-1481 [CRITICAL] CVE-2013-1481: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 6 throug Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 6 through Update 38, 5.0 through Update 38, and 1.4.2_40 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Sound.
nvd
CVE-2013-1478CRITICALCVSS 10.0v1.6.0v1.5.0+35 more2013-02-02
CVE-2013-1478 [CRITICAL] CVE-2013-1478: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 throug Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, 5.0 through Update 38, and 1.4.2_40 and earlier, and OpenJDK 6 and 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D. NOTE: the previous information is from th
nvd
CVE-2013-0446CRITICALCVSS 10.0v1.6.02013-02-02
CVE-2013-0446 [CRITICAL] CVE-2013-0446: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 throug Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11 and 6 through Update 38 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment, a different vulnerability than other CVEs listed in the February 2013 CPU.
nvd
CVE-2013-0450CRITICALCVSS 10.0v1.6.0v1.5.02013-02-02
CVE-2013-0450 [CRITICAL] CVE-2013-0450: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 throug Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, and 5.0 through Update 38, and OpenJDK 6 and 7, allows remote attackers to affect confidentiality, integrity, and availability via vectors related to JMX. NOTE: the previous information is from the February 2013 CPU. Oracle h
nvd
CVE-2012-3342CRITICALCVSS 10.0v1.6.02013-02-02
CVE-2012-3342 [CRITICAL] CVE-2012-3342: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 throug Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11 and 6 through Update 38 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment, a different vulnerability than other CVEs listed in the February 2013 CPU.
nvd
CVE-2012-1541CRITICALCVSS 10.0v1.6.02013-02-02
CVE-2012-1541 [CRITICAL] CVE-2012-1541: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 throug Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11 and 6 through Update 38 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment, a different vulnerability than other CVEs listed in the February 2013 CPU. NOTE: the previous informa
nvd