Sun Jdk vulnerabilities
392 known vulnerabilities affecting sun/jdk.
Total CVEs
392
CISA KEV
0
Public exploits
27
Exploited in wild
12
Severity breakdown
CRITICAL151HIGH70MEDIUM149LOW20
Vulnerabilities
Page 7 of 20
CVE-2013-1563P3HIGHCVSS 7.6v1.6.02013-04-17
CVE-2013-1563 [HIGH] CVE-2013-1563: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, 6 Update 43 and earlier, and JavaFX 2.2.7 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Install.
nvd
CVE-2010-3553P3CRITICALCVSS 10.0≤ 1.6.0v1.6.0+38 more2010-10-19
CVE-2010-3553 [CRITICAL] CVE-2010-3553: Unspecified vulnerability in the Swing component in Oracle Java SE and Java for Business 6 Update 21
Unspecified vulnerability in the Swing component in Oracle Java SE and Java for Business 6 Update 21, 5.0 Update 25, 1.4.2_27, and 1.3.1_28 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the October 2010 CPU. Oracle has not commented on claims from a reliab
nvd
CVE-2007-5689P3CRITICALCVSS 10.0≤ 1.6.0v1.5.0+1 more2007-10-29
CVE-2007-5689 [CRITICAL] CVE-2007-5689: The Java Virtual Machine (JVM) in Sun Java Runtime Environment (JRE) in SDK and JRE 1.3.x through 1.
The Java Virtual Machine (JVM) in Sun Java Runtime Environment (JRE) in SDK and JRE 1.3.x through 1.3.1_20 and 1.4.x through 1.4.2_15, and JDK and JRE 5.x through 5.0 Update 12 and 6.x through 6 Update 2, allows remote attackers to execute arbitrary programs, or read or modify arbitrary files, via applets that grant privileges to themselves.
nvd
CVE-2012-5084P3HIGHCVSS 7.6v1.6.0v1.6.0.200+37 more2012-10-16
CVE-2012-5084 [HIGH] CVE-2012-5084: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier, 6 Update 35 and earlier, 5.0 Update 36 and earlier, and 1.4.2_38 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Swing.
nvd
CVE-2012-5068P3HIGHCVSS 7.5v1.6.0v1.6.0.200+1 more2012-10-16
CVE-2012-5068 [HIGH] CVE-2012-5068: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier, and 6 Update 35 and earlier, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries.
nvd
CVE-2012-0504P3CRITICALCVSS 9.3v1.6.02012-02-15
CVE-2012-0504 [CRITICAL] CVE-2012-0504: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, and 6 Update 30 and earlier, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Install and the Java Update mechanism.
nvd
CVE-2009-3865P3CRITICALCVSS 9.3v1.6.02009-11-05
CVE-2009-3865 [CRITICAL] CWE-94 CVE-2009-3865: The launch method in the Deployment Toolkit plugin in Java Runtime Environment (JRE) in Sun Java SE
The launch method in the Deployment Toolkit plugin in Java Runtime Environment (JRE) in Sun Java SE in JDK and JRE 6 before Update 17 allows remote attackers to execute arbitrary commands via a crafted web page, aka Bug Id 6869752.
nvd
CVE-2010-0841P3HIGHCVSS 7.5≤ 1.6.0v1.6.0+2 more2010-04-01
CVE-2010-0841 [HIGH] CVE-2010-0841: Unspecified vulnerability in the ImageIO component in Oracle Java SE and Java for Business 6 Update
Unspecified vulnerability in the ImageIO component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, and 1.4.2_25 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the March 2010 CPU. Oracle has not commented on claims from a reliable researcher t
nvd
CVE-2010-3566P3CRITICALCVSS 10.0≤ 1.6.0v1.6.0+2 more2010-10-19
CVE-2010-3566 [CRITICAL] CVE-2010-3566: Unspecified vulnerability in the 2D component in Oracle Java SE and Java for Business 6 Update 21, 5
Unspecified vulnerability in the 2D component in Oracle Java SE and Java for Business 6 Update 21, 5.0 Update and 25 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the October 2010 CPU. Oracle has not commented on claims from a reliable researcher that this
nvd
CVE-2010-3567P3CRITICALCVSS 10.0≤ 1.6.0v1.6.0+2 more2010-10-19
CVE-2010-3567 [CRITICAL] CVE-2010-3567: Unspecified vulnerability in the 2D component in Oracle Java SE and Java for Business 6 Update 21, a
Unspecified vulnerability in the 2D component in Oracle Java SE and Java for Business 6 Update 21, and 5.0 Update 25 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the October 2010 CPU. Oracle has not commented on claims from a reliable downstream vendor th
nvd
CVE-2010-3568P3CRITICALCVSS 10.0≤ 1.6.0v1.6.0+2 more2010-10-19
CVE-2010-3568 [CRITICAL] CVE-2010-3568: Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for B
Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 21, 5.0 Update 25, and 1.4.2_27 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the October 2010 CPU. Oracle has not commented on claims from
nvd
CVE-2009-3866P3CRITICALCVSS 9.3v1.6.02009-11-05
CVE-2009-3866 [CRITICAL] CWE-264 CVE-2009-3866: The Java Web Start Installer in Sun Java SE in JDK and JRE 6 before Update 17 does not properly use
The Java Web Start Installer in Sun Java SE in JDK and JRE 6 before Update 17 does not properly use security model permissions when removing installer extensions, which allows remote attackers to execute arbitrary code by modifying a certain JNLP file to have a URL field that points to an unintended trusted application, aka Bug Id 6872824.
nvd
CVE-2013-5802P3HIGHCVSS 7.5v1.5.0v1.6.02013-10-16
CVE-2013-5802 [HIGH] CVE-2013-5802: Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u
Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, JRockit R28.2.8 and earlier, JRockit R27.7.6 and earlier, and Java SE Embedded 7u40 and earlier allows remote attackers to affect confidentiality, integrity, and availability via vectors related to JAXP.
nvd
CVE-2010-4465P3CRITICALCVSS 10.0≤ 1.6.0v1.6.0+2 more2011-02-17
CVE-2010-4465 [CRITICAL] CVE-2010-4465: Unspecified vulnerability in the Java Runtime Environment (JRE) in Oracle Java SE and Java for Busin
Unspecified vulnerability in the Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 23 and earlier, 5.0 Update 27 and earlier, and 1.4.2_29 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality, integrity, and availability via unknown vectors related to Swing. NOTE:
nvd
CVE-2011-3521P3CRITICALCVSS 10.0v1.7.0≤ 1.6.0+3 more2011-10-19
CVE-2011-3521 [CRITICAL] CVE-2011-3521: Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE, 7
Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE, 7, 6 Update 27 and earlier, and 5.0 Update 31 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality, integrity, and availability via unknown vectors related to Deserialization.
nvd
CVE-2013-5852P3HIGHCVSS 7.6v1.6.02013-10-16
CVE-2013-5852 [HIGH] CVE-2013-5852: Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, and Java SE
Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, and Java SE Embedded 7u40 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment, a different vulnerability than CVE-2013-5787, CVE-2013-5789, CVE-2013-5824, and CVE-2013-5832.
nvd
CVE-2012-3159P3HIGHCVSS 7.5v1.6.0v1.6.0.200+1 more2012-10-16
CVE-2012-3159 [HIGH] CVE-2012-3159: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier, and 6 Update 35 and earlier, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment, a different vulnerability than CVE-2012-1533.
nvd
CVE-2010-3550P3CRITICALCVSS 9.3≤ 1.6.0v1.6.0+2 more2010-10-19
CVE-2010-3550 [CRITICAL] CVE-2010-3550: Unspecified vulnerability in the Java Web Start component in Oracle Java SE and Java for Business 6
Unspecified vulnerability in the Java Web Start component in Oracle Java SE and Java for Business 6 Update 21 and 5.0 Update 25 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.
nvd
CVE-2010-0849P3HIGHCVSS 7.5≤ 1.6.0v1.6.0+37 more2010-04-01
CVE-2010-0849 [HIGH] CVE-2010-0849: Unspecified vulnerability in the Java 2D component in Oracle Java SE and Java for Business 6 Update
Unspecified vulnerability in the Java 2D component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, 1.4.2_25, and 1.3.1_27 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the March 2010 CPU. Oracle has not commented on claims from a reliable re
nvd
CVE-2010-0846P3HIGHCVSS 7.5≤ 1.6.0v1.6.0+37 more2010-04-01
CVE-2010-0846 [HIGH] CVE-2010-0846: Unspecified vulnerability in the ImageIO component in Oracle Java SE and Java for Business 6 Update
Unspecified vulnerability in the ImageIO component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, 1.4.2_25, and 1.3.1_27 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the March 2010 CPU. Oracle has not commented on claims from a reliable re
nvd