Sun Jdk vulnerabilities
392 known vulnerabilities affecting sun/jdk.
Total CVEs
392
CISA KEV
0
Public exploits
27
Exploited in wild
12
Severity breakdown
CRITICAL151HIGH70MEDIUM149LOW20
Vulnerabilities
Page 9 of 20
CVE-2008-5357P3CRITICALCVSS 9.3v1.5.0v1.6.02008-12-05
CVE-2008-5357 [CRITICAL] CWE-189 CVE-2008-5357: Integer overflow in Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK
Integer overflow in Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; SDK and JRE 1.4.2_18 and earlier; and SDK and JRE 1.3.1_23 and earlier might allow remote attackers to execute arbitrary code via a crafted TrueType font file, which triggers a heap-based buffer overflow.
nvd
CVE-2013-2430P3HIGHCVSS 7.6v1.6.0v1.5.02013-04-17
CVE-2013-2430 [HIGH] CVE-2013-2430: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, 6 Update 43 and earlier, and 5.0 Update 41 and earlier; JavaFX 2.2.7 and earlier; and OpenJDK 6 and 7 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to ImageIO. NOTE: the previous inform
nvd
CVE-2013-2448P3HIGHCVSS 7.6v1.6.0v1.5.02013-06-18
CVE-2013-2448 [HIGH] CVE-2013-2448: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier, and OpenJDK 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Sound. NOTE: the previous information is from the June 2013 CPU.
nvd
CVE-2007-3504P3CRITICALCVSS 9.3≤ 1.5.02007-06-30
CVE-2007-3504 [CRITICAL] CWE-22 CVE-2007-3504: Directory traversal vulnerability in the PersistenceService in Sun Java Web Start in JDK and JRE 5.0
Directory traversal vulnerability in the PersistenceService in Sun Java Web Start in JDK and JRE 5.0 Update 11 and earlier, and Java Web Start in SDK and JRE 1.4.2_13 and earlier, for Windows allows remote attackers to perform unauthorized actions via an application that grants file overwrite privileges to itself. NOTE: this can be leveraged to execu
nvd
CVE-2008-3108P3CRITICALCVSS 10.0v1.5.02008-07-09
CVE-2008-3108 [CRITICAL] CWE-119 CVE-2008-3108: Buffer overflow in Sun Java Runtime Environment (JRE) in JDK and JRE 5.0 before Update 10, SDK and J
Buffer overflow in Sun Java Runtime Environment (JRE) in JDK and JRE 5.0 before Update 10, SDK and JRE 1.4.x before 1.4.2_18, and SDK and JRE 1.3.x before 1.3.1_23 allows context-dependent attackers to gain privileges via unspecified vectors related to font processing.
nvd
CVE-2008-5340P3CRITICALCVSS 10.0≤ 5.0≤ 6+2 more2008-12-05
CVE-2008-5340 [CRITICAL] CWE-264 CVE-2008-5340: Unspecified vulnerability in Java Web Start (JWS) and Java Plug-in with Sun JDK and JRE 6 Update 10
Unspecified vulnerability in Java Web Start (JWS) and Java Plug-in with Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier allows untrusted JWS applications to gain privileges to access local files or applications via unknown vectors, aka 6727081.
nvd
CVE-2008-3107P3CRITICALCVSS 10.0≤ 5.0≤ 6+2 more2008-07-09
CVE-2008-3107 [CRITICAL] CWE-264 CVE-2008-3107: Unspecified vulnerability in the Virtual Machine in Sun Java Runtime Environment (JRE) in JDK and JR
Unspecified vulnerability in the Virtual Machine in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 7, JDK and JRE 5.0 before Update 16, and SDK and JRE 1.4.x before 1.4.2_18 allows context-dependent attackers to gain privileges via an untrusted (1) application or (2) applet, as demonstrated by an application or applet that grants
nvd
CVE-2010-4422P3HIGHCVSS 7.6≤ 1.6.0v1.6.02011-02-17
CVE-2010-4422 [HIGH] CVE-2010-4422: Unspecified vulnerability in the Java Runtime Environment (JRE) in Oracle Java SE and Java for Busin
Unspecified vulnerability in the Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 23 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment.
nvd
CVE-2011-0863P3CRITICALCVSS 10.0≤ 1.6.0v1.6.02011-06-14
CVE-2011-0863 [CRITICAL] CVE-2011-0863: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 6 Update
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 6 Update 25 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality, integrity, and availability via unknown vectors related to Deployment.
nvd
CVE-2010-4469P3CRITICALCVSS 10.0≤ 1.6.0v1.6.0+2 more2011-02-17
CVE-2010-4469 [CRITICAL] CVE-2010-4469: Unspecified vulnerability in the Java Runtime Environment (JRE) in Oracle Java SE and Java for Busin
Unspecified vulnerability in the Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 23 and earlier, 5.0 Update 27 and earlier, and 1.4.2_29 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality, integrity, and availability via unknown vectors related to HotSpot. NOTE
nvd
CVE-2010-4467P3CRITICALCVSS 10.0v1.6.02011-02-17
CVE-2010-4467 [CRITICAL] CVE-2010-4467: Unspecified vulnerability in the Java Runtime Environment (JRE) in Oracle Java SE and Java for Busin
Unspecified vulnerability in the Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 10 through 6 Update 23 allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality, integrity, and availability via unknown vectors related to Deployment.
nvd
CVE-2011-0817P3CRITICALCVSS 10.0≤ 1.6.0v1.6.02011-06-14
CVE-2011-0817 [CRITICAL] CVE-2011-0817: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 6 Update
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 6 Update 25 and earlier, when running on Windows, allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality, integrity, and availability via unknown vectors related to Deployment.
nvd
CVE-2012-1711P3HIGHCVSS 7.5≤ 1.5.0≤ 1.4.2_372012-06-16
CVE-2012-1711 [HIGH] CVE-2012-1711: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update 4 and earlier, 6 update 32 and earlier, 5 update 35 and earlier, and 1.4.2_37 and earlier allows remote attackers to affect confidentiality, integrity, and availability, related to CORBA.
nvd
CVE-2008-5356P3CRITICALCVSS 9.3≤ 5.0≤ 6+2 more2008-12-05
CVE-2008-5356 [CRITICAL] CWE-119 CVE-2008-5356: Heap-based buffer overflow in Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and ear
Heap-based buffer overflow in Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier might allow remote attackers to execute arbitrary code via a crafted TrueType font file.
nvd
CVE-2013-2445P3HIGHCVSS 7.8v1.6.0v1.5.02013-06-18
CVE-2013-2445 [HIGH] CVE-2013-2445: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier, and OpenJDK 7, allows remote attackers to affect availability via unknown vectors related to Hotspot. NOTE: the previous information is from the June 2013 CPU. Oracle has not commented on cl
nvd
CVE-2013-0351P3HIGHCVSS 7.5v1.6.02013-02-02
CVE-2013-0351 [HIGH] CVE-2013-0351: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 throug
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11 and 6 through Update 38 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment, a different vulnerability than other CVEs listed in the February 2013 CPU.
nvd
CVE-2013-2429P3HIGHCVSS 7.6v1.6.0v1.5.02013-04-17
CVE-2013-2429 [HIGH] CVE-2013-2429: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, 6 Update 43 and earlier, and 5.0 Update 41 and earlier; and OpenJDK 6 and 7; allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to ImageIO. NOTE: the previous information is from the April 2
nvd
CVE-2009-2673P3HIGHCVSS 7.5≤ 6v5.0+1 more2009-08-05
CVE-2009-2673 [HIGH] CWE-264 CVE-2009-2673: The proxy mechanism implementation in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Upd
The proxy mechanism implementation in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15, and JDK and JRE 5.0 before Update 20, allows remote attackers to bypass intended access restrictions and connect to arbitrary sites via unspecified vectors, related to a declaration that lacks the final keyword.
nvd
CVE-2010-0844P3HIGHCVSS 7.5≤ 1.6.0v1.6.0+37 more2010-04-01
CVE-2010-0844 [HIGH] CVE-2010-0844: Unspecified vulnerability in the Sound component in Oracle Java SE and Java for Business 6 Update 18
Unspecified vulnerability in the Sound component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, 1.4.2_25, and 1.3.1_27 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the March 2010 CPU. Oracle has not commented on claims from a reliable res
nvd
CVE-2009-3868P3CRITICALCVSS 9.3v1.5.0v1.6.02009-11-05
CVE-2009-3868 [CRITICAL] CWE-119 CVE-2009-3868: Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x b
Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK and JRE 1.4.x before 1.4.2_24 does not properly parse color profiles, which allows remote attackers to gain privileges via a crafted image file, aka Bug Id 6862970.
nvd