cbcvebase.

Sun Jdk vulnerabilities

392 known vulnerabilities affecting sun/jdk.

Total CVEs
392
CISA KEV
0
Public exploits
27
Exploited in wild
12
Severity breakdown
CRITICAL151HIGH70MEDIUM149LOW20

Vulnerabilities

Page 8 of 20
CVE-2008-3113P3CRITICALCVSS 10.0≤ 5.0v5.02008-07-09
CVE-2008-3113 [CRITICAL] CWE-264 CVE-2008-3113: Unspecified vulnerability in Sun Java Web Start in JDK and JRE 5.0 before Update 16 and SDK and JRE Unspecified vulnerability in Sun Java Web Start in JDK and JRE 5.0 before Update 16 and SDK and JRE 1.4.x before 1.4.2_18 allows remote attackers to create or delete arbitrary files via an untrusted application, aka CR 6704077.
nvd
CVE-2010-3565P3CRITICALCVSS 10.0≤ 1.6.0v1.6.0+2 more2010-10-19
CVE-2010-3565 [CRITICAL] CVE-2010-3565: Unspecified vulnerability in the 2D component in Oracle Java SE and Java for Business 6 Update 21, 5 Unspecified vulnerability in the 2D component in Oracle Java SE and Java for Business 6 Update 21, 5.0 Update 25, and 1.4.2_27 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the October 2010 CPU. Oracle has not commented on claims from a reliable researcher
nvd
CVE-2008-2086P3CRITICALCVSS 9.3≤ 5.0≤ 6+2 more2008-12-05
CVE-2008-2086 [CRITICAL] CWE-94 CVE-2008-2086: Sun Java Web Start and Java Plug-in for JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update Sun Java Web Start and Java Plug-in for JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier allow remote attackers to execute arbitrary code via a crafted jnlp file that modifies the (1) java.home, (2) java.ext.dirs, or (3) user.home System Properties, aka "Java Web Start File Inclusion" and
nvd
CVE-2009-1097P3CRITICALCVSS 9.3≤ 1.6.0v1.6.02009-03-25
CVE-2009-1097 [CRITICAL] CWE-119 CVE-2009-1097: Multiple buffer overflows in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 6 Upda Multiple buffer overflows in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 6 Update 12 and earlier allow remote attackers to access files or execute arbitrary code via (1) a crafted PNG image that triggers an integer overflow during memory allocation for display on the splash screen, aka CR 6804996; and (2) a crafted GIF image fro
nvd
CVE-2008-1188P3CRITICALCVSS 9.3v1.5.0v1.6.02008-03-06
CVE-2008-1188 [CRITICAL] CWE-119 CVE-2008-1188: Multiple buffer overflows in the useEncodingDecl function in Java Web Start in Sun JDK and JRE 6 Upd Multiple buffer overflows in the useEncodingDecl function in Java Web Start in Sun JDK and JRE 6 Update 4 and earlier, and 5.0 Update 14 and earlier, allow remote attackers to execute arbitrary code via a JNLP file with (1) a long key name in the xml header or (2) a long charset value, different issues than CVE-2008-1189, aka "The first two issues."
nvd
CVE-2011-0871P3CRITICALCVSS 10.0≤ 1.4.2_31v1.4.2+34 more2011-06-14
CVE-2011-0871 [CRITICAL] CVE-2011-0871: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 6 Update Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 6 Update 25 and earlier, 5.0 Update 29 and earlier, and 1.4.2_31 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality, integrity, and availability via unknown vectors related to Swing.
nvd
CVE-2011-0815P3CRITICALCVSS 10.0≤ 1.4.2_31v1.4.2+34 more2011-06-14
CVE-2011-0815 [CRITICAL] CVE-2011-0815: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 6 Update Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 6 Update 25 and earlier, 5.0 Update 29 and earlier, and 1.4.2_31 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality, integrity, and availability via unknown vectors related to AWT.
nvd
CVE-2011-3554P3CRITICALCVSS 10.0≤ 1.6.0v1.6.0+3 more2011-10-19
CVE-2011-3554 [CRITICAL] CVE-2011-3554: Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7, Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7, 6 Update 27 and earlier, 5.0 Update 31 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality, integrity, and availability via unknown vectors.
nvd
CVE-2011-3548P3CRITICALCVSS 10.0≤ 1.6.0v1.6.0+37 more2011-10-19
CVE-2011-3548 [CRITICAL] CVE-2011-3548: Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7, Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7, 6 Update 27 and earlier, 5.0 Update 31 and earlier, and 1.4.2_33 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality, integrity, and availability, related to AWT.
nvd
CVE-2011-3549P3CRITICALCVSS 10.0≤ 1.6.0v1.6.0+36 more2011-10-19
CVE-2011-3549 [CRITICAL] CVE-2011-3549: Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 6 Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 6 Update 27 and earlier, 5.0 Update 31 and earlier, and 1.4.2_33 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality, integrity, and availability via unknown vectors related to Swing.
nvd
CVE-2013-0419P3HIGHCVSS 7.6v1.6.02013-02-02
CVE-2013-0419 [HIGH] CVE-2013-0419: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 throug Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11 and 6 through Update 38 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment, a different vulnerability than other CVEs listed in the February 2013 CPU.
nvd
CVE-2013-0423P3HIGHCVSS 7.6v1.6.02013-02-02
CVE-2013-0423 [HIGH] CVE-2013-0423: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 throug Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11 and 6 through Update 38 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment, a different vulnerability than other CVEs listed in the February 2013 CPU.
nvd
CVE-2013-0429P3HIGHCVSS 7.6v1.6.0v1.5.02013-02-02
CVE-2013-0429 [HIGH] CVE-2013-0429: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 throug Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, and 5.0 through Update 38, and OpenJDK 6 and 7, allows remote attackers to affect confidentiality, integrity, and availability via vectors related to CORBA. NOTE: the previous information is from the February 2013 CPU. Oracle has
nvd
CVE-2010-0843P3HIGHCVSS 7.5v1.5.0v1.6.02010-04-01
CVE-2010-0843 [HIGH] CVE-2010-0843: Unspecified vulnerability in the Sound component in Oracle Java SE and Java for Business 6 Update 18 Unspecified vulnerability in the Sound component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, 1.4.2_25, and 1.3.1_27 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the March 2010 CPU. Oracle has not commented on claims from a reliable res
nvd
CVE-2008-5358P3CRITICALCVSS 9.3≤ 6v62008-12-05
CVE-2008-5358 [CRITICAL] CWE-119 CVE-2008-5358: Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier might allow remote attack Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier might allow remote attackers to execute arbitrary code via a crafted GIF file that triggers memory corruption during display of the splash screen, possibly related to splashscreen.dll.
nvd
CVE-2010-0847P3HIGHCVSS 7.5≤ 1.6.0v1.6.0+37 more2010-04-01
CVE-2010-0847 [HIGH] CVE-2010-0847: Unspecified vulnerability in the Java 2D component in Oracle Java SE and Java for Business 6 Update Unspecified vulnerability in the Java 2D component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, 1.4.2_25, and 1.3.1_27 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the March 2010 CPU. Oracle has not commented on claims from a reliable re
nvd
CVE-2008-1195P3CRITICALCVSS 9.3v1.5.0v1.6.02008-03-06
CVE-2008-1195 [CRITICAL] CWE-254 CVE-2008-1195: Unspecified vulnerability in Sun JDK and Java Runtime Environment (JRE) 6 Update 4 and earlier and 5 Unspecified vulnerability in Sun JDK and Java Runtime Environment (JRE) 6 Update 4 and earlier and 5.0 Update 14 and earlier; and SDK and JRE 1.4.2_16 and earlier; allows remote attackers to access arbitrary network services on the local host via unspecified vectors related to JavaScript and Java APIs.
nvd
CVE-2008-5354P3CRITICALCVSS 9.3≤ 5.0≤ 6+2 more2008-12-05
CVE-2008-5354 [CRITICAL] CWE-119 CVE-2008-5354: Stack-based buffer overflow in Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and ea Stack-based buffer overflow in Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier allows locally-launched and possibly remote untrusted Java applications to execute arbitrary code via a JAR file with a long Main-Class manifest entry.
nvd
CVE-2011-0864P3CRITICALCVSS 10.0≤ 1.4.2_31v1.4.2+34 more2011-06-14
CVE-2011-0864 [CRITICAL] CVE-2011-0864: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 6 Update Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 6 Update 25 and earlier, 5.0 Update 29 and earlier, and 1.4.2_31 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality, integrity, and availability via unknown vectors related to HotSpot.
nvd
CVE-2008-5343P3CRITICALCVSS 9.0≤ 5.0≤ 6+2 more2008-12-05
CVE-2008-5343 [CRITICAL] CVE-2008-5343: Java Web Start (JWS) and Java Plug-in with Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Java Web Start (JWS) and Java Plug-in with Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier allows remote attackers to make unauthorized network connections and hijack HTTP sessions via a crafted file that validates as both a GIF and a Java JAR file, aka "GIFAR" and CR 6707535.
nvd
Sun Jdk vulnerabilities | cvebase