Sun Jre vulnerabilities
423 known vulnerabilities affecting sun/jre.
Total CVEs
423
CISA KEV
2
actively exploited
Public exploits
36
Exploited in wild
13
Severity breakdown
CRITICAL162HIGH77MEDIUM162LOW20
Vulnerabilities
Page 10 of 22
CVE-2010-4467P3CRITICALCVSS 10.0v1.6.02011-02-17
CVE-2010-4467 [CRITICAL] CVE-2010-4467: Unspecified vulnerability in the Java Runtime Environment (JRE) in Oracle Java SE and Java for Busin
Unspecified vulnerability in the Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 10 through 6 Update 23 allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality, integrity, and availability via unknown vectors related to Deployment.
nvd
CVE-2011-0817P3CRITICALCVSS 10.0≤ 1.6.0v1.6.02011-06-14
CVE-2011-0817 [CRITICAL] CVE-2011-0817: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 6 Update
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 6 Update 25 and earlier, when running on Windows, allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality, integrity, and availability via unknown vectors related to Deployment.
nvd
CVE-2012-1711P3HIGHCVSS 7.5≤ 1.5.0≤ 1.4.2_372012-06-16
CVE-2012-1711 [HIGH] CVE-2012-1711: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update 4 and earlier, 6 update 32 and earlier, 5 update 35 and earlier, and 1.4.2_37 and earlier allows remote attackers to affect confidentiality, integrity, and availability, related to CORBA.
nvd
CVE-2008-5356P3CRITICALCVSS 9.3≤ 1.4.2_18≤ 5.0+20 more2008-12-05
CVE-2008-5356 [CRITICAL] CWE-119 CVE-2008-5356: Heap-based buffer overflow in Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and ear
Heap-based buffer overflow in Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier might allow remote attackers to execute arbitrary code via a crafted TrueType font file.
nvd
CVE-2013-2445P3HIGHCVSS 7.8v1.6.0v1.5.02013-06-18
CVE-2013-2445 [HIGH] CVE-2013-2445: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier, and OpenJDK 7, allows remote attackers to affect availability via unknown vectors related to Hotspot. NOTE: the previous information is from the June 2013 CPU. Oracle has not commented on cl
nvd
CVE-2013-0351P3HIGHCVSS 7.5v1.6.02013-02-02
CVE-2013-0351 [HIGH] CVE-2013-0351: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 throug
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11 and 6 through Update 38 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment, a different vulnerability than other CVEs listed in the February 2013 CPU.
nvd
CVE-2013-2429P3HIGHCVSS 7.6v1.6.0v1.5.02013-04-17
CVE-2013-2429 [HIGH] CVE-2013-2429: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, 6 Update 43 and earlier, and 5.0 Update 41 and earlier; and OpenJDK 6 and 7; allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to ImageIO. NOTE: the previous information is from the April 2
nvd
CVE-2007-2435P3CRITICALCVSS 10.0≤ 1.4.2≤ 1.5.02007-05-02
CVE-2007-2435 [CRITICAL] CWE-264 CVE-2007-2435: Sun Java Web Start in JDK and JRE 5.0 Update 10 and earlier, and Java Web Start in SDK and JRE 1.4.2
Sun Java Web Start in JDK and JRE 5.0 Update 10 and earlier, and Java Web Start in SDK and JRE 1.4.2_13 and earlier, allows remote attackers to perform unauthorized actions via an application that grants privileges to itself, related to "Incorrect Use of System Classes" and probably related to support for JNLP files.
nvd
CVE-2009-2673P3HIGHCVSS 7.5≤ 6v5.0+1 more2009-08-05
CVE-2009-2673 [HIGH] CWE-264 CVE-2009-2673: The proxy mechanism implementation in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Upd
The proxy mechanism implementation in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15, and JDK and JRE 5.0 before Update 20, allows remote attackers to bypass intended access restrictions and connect to arbitrary sites via unspecified vectors, related to a declaration that lacks the final keyword.
nvd
CVE-2010-0844P3HIGHCVSS 7.5≤ 1.6.0v1.6.0+56 more2010-04-01
CVE-2010-0844 [HIGH] CVE-2010-0844: Unspecified vulnerability in the Sound component in Oracle Java SE and Java for Business 6 Update 18
Unspecified vulnerability in the Sound component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, 1.4.2_25, and 1.3.1_27 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the March 2010 CPU. Oracle has not commented on claims from a reliable res
nvd
CVE-2009-3868P3CRITICALCVSS 9.3v1.5.0v1.6.0+66 more2009-11-05
CVE-2009-3868 [CRITICAL] CWE-119 CVE-2009-3868: Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x b
Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK and JRE 1.4.x before 1.4.2_24 does not properly parse color profiles, which allows remote attackers to gain privileges via a crafted image file, aka Bug Id 6862970.
nvd
CVE-2009-3872P3CRITICALCVSS 9.3v1.5.0v1.6.0+66 more2009-11-05
CVE-2009-3872 [CRITICAL] CVE-2009-3872: Unspecified vulnerability in the JPEG JFIF Decoder in Sun Java SE in JDK and JRE 5.0 before Update 2
Unspecified vulnerability in the JPEG JFIF Decoder in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to gain privileges via a crafted image file, aka Bug Id 6862969.
nvd
CVE-2010-4463P3CRITICALCVSS 10.0v1.6.02011-02-17
CVE-2010-4463 [CRITICAL] CVE-2010-4463: Unspecified vulnerability in the Java Runtime Environment (JRE) in Oracle Java SE and Java for Busin
Unspecified vulnerability in the Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 21 through 6 Update 23 allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality, integrity, and availability via unknown vectors related to Deployment.
nvd
CVE-2011-3557P3MEDIUMCVSS 6.8v1.7.0≤ 1.6.0+37 more2011-10-19
CVE-2011-3557 [MEDIUM] CVE-2011-3557: Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7,
Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7, 6 Update 27 and earlier, 5.0 Update 31 and earlier, 1.4.2_33 and earlier, and JRockit R28.1.4 and earlier allows remote attackers to affect confidentiality, integrity, and availability, related to RMI, a different vulnerability than CVE-2011-3556.
nvd
CVE-2009-2675P3CRITICALCVSS 10.0≤ 6v5.0+1 more2009-08-05
CVE-2009-2675 [CRITICAL] CWE-264 CVE-2009-2675: Integer overflow in the unpack200 utility in Sun Java Runtime Environment (JRE) in JDK and JRE 6 bef
Integer overflow in the unpack200 utility in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15, and JDK and JRE 5.0 before Update 20, allows context-dependent attackers to gain privileges via unspecified length fields in the header of a Pack200-compressed JAR file, which leads to a heap-based buffer overflow during decompression.
nvd
CVE-2008-3111P3CRITICALCVSS 10.0v1.4v1.4.2_01+18 more2008-07-09
CVE-2008-3111 [CRITICAL] CWE-20 CVE-2008-3111: Multiple buffer overflows in Sun Java Web Start in JDK and JRE 6 before Update 4, JDK and JRE 5.0 be
Multiple buffer overflows in Sun Java Web Start in JDK and JRE 6 before Update 4, JDK and JRE 5.0 before Update 16, and SDK and JRE 1.4.x before 1.4.2_18 allow context-dependent attackers to gain privileges via an untrusted application, as demonstrated by (a) an application that grants itself privileges to (1) read local files, (2) write to local fil
nvd
CVE-2008-3103P3CRITICALCVSS 9.3≤ 5.0≤ 6+2 more2008-07-09
CVE-2008-3103 [CRITICAL] CWE-264 CVE-2008-3103: Unspecified vulnerability in the Java Management Extensions (JMX) management agent in Sun Java Runti
Unspecified vulnerability in the Java Management Extensions (JMX) management agent in Sun Java Runtime Environment (JRE) in JDK and JRE 6 Update 6 and earlier and JDK and JRE 5.0 Update 15 and earlier, when local monitoring is enabled, allows remote attackers to "perform unauthorized operations" via unspecified vectors.
nvd
CVE-2009-2674P3HIGHCVSS 7.5v62009-08-05
CVE-2009-2674 [HIGH] CWE-264 CVE-2009-2674: Integer overflow in javaws.exe in Sun Java Web Start in Sun Java Runtime Environment (JRE) in JDK an
Integer overflow in javaws.exe in Sun Java Web Start in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15 allows context-dependent attackers to execute arbitrary code via a crafted JPEG image that is not properly handled during display to a splash screen, which triggers a heap-based buffer overflow.
nvd
CVE-2010-3570P3HIGHCVSS 7.6≤ 1.6.0v1.6.02010-10-19
CVE-2010-3570 [HIGH] CVE-2010-3570: Unspecified vulnerability in the Deployment Toolkit component in Oracle Java SE and Java for Busines
Unspecified vulnerability in the Deployment Toolkit component in Oracle Java SE and Java for Business 6 Update 21 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.
nvd
CVE-2010-4451P3HIGHCVSS 7.6≤ 1.6.0v1.6.02011-02-17
CVE-2010-4451 [HIGH] CVE-2010-4451: Unspecified vulnerability in the Java Runtime Environment (JRE) in Oracle Java SE and Java for Busin
Unspecified vulnerability in the Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 23 and earlier for Windows, when using Java Update, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Install.
nvd