Sun Jre vulnerabilities
423 known vulnerabilities affecting sun/jre.
Total CVEs
423
CISA KEV
2
actively exploited
Public exploits
36
Exploited in wild
13
Severity breakdown
CRITICAL162HIGH77MEDIUM162LOW20
Vulnerabilities
Page 11 of 22
CVE-2010-3561P3HIGHCVSS 7.5≤ 1.6.0v1.6.0+2 more2010-10-19
CVE-2010-3561 [HIGH] CVE-2010-3561: Unspecified vulnerability in the CORBA component in Oracle Java SE and Java for Business 6 Update 21
Unspecified vulnerability in the CORBA component in Oracle Java SE and Java for Business 6 Update 21 and 5.0 Update 25 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the October 2010 CPU. Oracle has not commented on claims from a reliable downstream vendor that
nvd
CVE-2008-0657P3CRITICALCVSS 10.0≤ 1.5.0≤ 1.6.02008-02-07
CVE-2008-0657 [CRITICAL] CWE-264 CVE-2008-0657: Multiple unspecified vulnerabilities in the Java Runtime Environment in Sun JDK and JRE 6 Update 1 a
Multiple unspecified vulnerabilities in the Java Runtime Environment in Sun JDK and JRE 6 Update 1 and earlier, and 5.0 Update 13 and earlier, allow context-dependent attackers to gain privileges via an untrusted (1) application or (2) applet, as demonstrated by an application or applet that grants itself privileges to (a) read local files, (b) writ
nvd
CVE-2009-3873P3CRITICALCVSS 9.3v1.5.0v1.6.0+66 more2009-11-05
CVE-2009-3873 [CRITICAL] CWE-119 CVE-2009-3873: The JPEG Image Writer in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Updat
The JPEG Image Writer in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to gain privileges via a crafted image file, related to a "quantization problem," aka Bug Id 6862968.
nvd
CVE-2008-5352P3CRITICALCVSS 9.3≤ 5.0≤ 6+2 more2008-12-05
CVE-2008-5352 [CRITICAL] CWE-189 CVE-2008-5352: Integer overflow in the JAR unpacking utility (unpack200) in the unpack library (unpack.dll) in Java
Integer overflow in the JAR unpacking utility (unpack200) in the unpack library (unpack.dll) in Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier, and JDK and JRE 5.0 Update 16 and earlier, allows untrusted applications and applets to gain privileges via a Pack200 compressed JAR file that triggers a heap-based buffer overflo
nvd
CVE-2008-1185P3CRITICALCVSS 9.3v1.4.2v1.4.2_1+17 more2008-03-06
CVE-2008-1185 [CRITICAL] CWE-264 CVE-2008-1185: Unspecified vulnerability in the Virtual Machine for Sun Java Runtime Environment (JRE) and JDK 6 Up
Unspecified vulnerability in the Virtual Machine for Sun Java Runtime Environment (JRE) and JDK 6 Update 4 and earlier, 5.0 Update 14 and earlier, and SDK/JRE 1.4.2_16 and earlier allows remote attackers to gain privileges via an untrusted application or applet, a different issue than CVE-2008-1186, aka "the first issue."
nvd
CVE-2008-1186P3CRITICALCVSS 9.3v1.4.2v1.4.2_1+16 more2008-03-06
CVE-2008-1186 [CRITICAL] CVE-2008-1186: Unspecified vulnerability in the Virtual Machine for Sun Java Runtime Environment (JRE) and JDK 5.0
Unspecified vulnerability in the Virtual Machine for Sun Java Runtime Environment (JRE) and JDK 5.0 Update 13 and earlier, and SDK/JRE 1.4.2_16 and earlier, allows remote attackers to gain privileges via an untrusted application or applet, a different issue than CVE-2008-1185, aka "the second issue."
nvd
CVE-2010-0837P3HIGHCVSS 7.5≤ 1.6.0v1.6.0+2 more2010-04-01
CVE-2010-0837 [HIGH] CVE-2010-0837: Unspecified vulnerability in the Pack200 component in Oracle Java SE and Java for Business 6 Update
Unspecified vulnerability in the Pack200 component in Oracle Java SE and Java for Business 6 Update 18, 5.0, Update, and 23 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.
nvd
CVE-2010-0850P3HIGHCVSS 7.5≤ 1.3.1_27v1.3.0+26 more2010-04-01
CVE-2010-0850 [HIGH] CVE-2010-0850: Unspecified vulnerability in the Java 2D component in Oracle Java SE and Java for Business 1.3.1_27
Unspecified vulnerability in the Java 2D component in Oracle Java SE and Java for Business 1.3.1_27 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.
nvd
CVE-2013-5804P3MEDIUMCVSS 6.4v1.6.0v1.5.02013-10-16
CVE-2013-5804 [MEDIUM] CVE-2013-5804: Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u
Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, JRockit R28.2.8 and earlier, and JRockit R27.7.6 and earlier allows remote attackers to affect confidentiality and integrity via unknown vectors related to Javadoc.
nvd
CVE-2008-3115P3HIGHCVSS 7.5≤ 6v5.0+1 more2008-07-09
CVE-2008-3115 [HIGH] CWE-16 CVE-2008-3115: Secure Static Versioning in Sun Java JDK and JRE 6 Update 6 and earlier, and 5.0 Update 6 through 15
Secure Static Versioning in Sun Java JDK and JRE 6 Update 6 and earlier, and 5.0 Update 6 through 15, does not properly prevent execution of applets on older JRE releases, which might allow remote attackers to exploit vulnerabilities in these older releases.
nvd
CVE-2012-0547P4UNKNOWNCVSS 0.0PoCv1.6.02012-08-30
CVE-2012-0547 [NONE] CVE-2012-0547: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier, and 6 Update 34 and earlier, has no impact and remote attack vectors involving AWT and "a security-in-depth issue that is not directly exploitable but which can be used to aggravate security vulnerabilities that can be directly exploited." NOTE: t
nvd
CVE-2010-0848P3HIGHCVSS 7.5≤ 1.6.0v1.6.0+56 more2010-04-01
CVE-2010-0848 [HIGH] CVE-2010-0848: Unspecified vulnerability in the Java 2D component in Oracle Java SE and Java for Business 6 Update
Unspecified vulnerability in the Java 2D component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, 1.4.2_25, and 1.3.1_27 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.
nvd
CVE-2010-0839P3HIGHCVSS 7.5≤ 1.6.0v1.6.0+56 more2010-04-01
CVE-2010-0839 [HIGH] CVE-2010-0839: Unspecified vulnerability in the Sound component in Oracle Java SE and Java for Business 6 Update 18
Unspecified vulnerability in the Sound component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, 1.4.2_25, and 1.3.1_27 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.
nvd
CVE-2008-5344P3HIGHCVSS 7.5≤ 1.4.2_18≤ 5.0+20 more2008-12-05
CVE-2008-5344 [HIGH] CVE-2008-5344: Unspecified vulnerability in Java Web Start (JWS) and Java Plug-in with Sun JDK and JRE 6 Update 10
Unspecified vulnerability in Java Web Start (JWS) and Java Plug-in with Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier allows untrusted applets to read arbitrary files and make unauthorized network connections via unknown vectors related to applet classloading, aka 6716217.
nvd
CVE-2011-0866P3HIGHCVSS 7.6≤ 1.4.2_31v1.4.2+34 more2011-06-14
CVE-2011-0866 [HIGH] CVE-2011-0866: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 6 Update
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 6 Update 25 and earlier, 5.0 Update 29 and earlier, and 1.4.2_31 and earlier, when running on Windows, allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality, integrity, and availability via unknown vectors related to Jav
nvd
CVE-2007-3716P3CRITICALCVSS 9.3≤ 62007-07-11
CVE-2007-3716 [CRITICAL] CVE-2007-3716: The Java XML Digital Signature implementation in Sun JDK and JRE 6 before Update 2 does not properly
The Java XML Digital Signature implementation in Sun JDK and JRE 6 before Update 2 does not properly process XSLT stylesheets in XSLT transforms in XML signatures, which allows context-dependent attackers to execute arbitrary code via a crafted stylesheet, a related issue to CVE-2007-3715.
nvd
CVE-2013-5783P3MEDIUMCVSS 6.4v1.6.0v1.5.02013-10-16
CVE-2013-5783 [MEDIUM] CVE-2013-5783: Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u
Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, and Java SE Embedded 7u40 and earlier allows remote attackers to affect confidentiality and integrity via unknown vectors related to Swing.
nvd
CVE-2012-5071P3MEDIUMCVSS 6.4v1.6.0v1.5.02012-10-16
CVE-2012-5071 [MEDIUM] CVE-2012-5071: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier, 6 Update 35 and earlier, and 5.0 Update 36 and earlier allows remote attackers to affect confidentiality and integrity, related to JMX.
nvd
CVE-2009-1719P3HIGHCVSS 7.5v1.5.0v1.5.0_11-b032009-06-16
CVE-2009-1719 [HIGH] CWE-94 CVE-2009-1719: The Aqua Look and Feel for Java implementation in Java 1.5 on Mac OS X 10.5 allows remote attackers
The Aqua Look and Feel for Java implementation in Java 1.5 on Mac OS X 10.5 allows remote attackers to execute arbitrary code via a call to the undocumented apple.laf.CColourUIResource constructor with a crafted value in the first argument, which is dereferenced as a pointer.
nvd
CVE-2010-0087P3HIGHCVSS 7.5≤ 1.6.0v1.6.0+56 more2010-04-01
CVE-2010-0087 [HIGH] CVE-2010-0087: Unspecified vulnerability in the Java Web Start, Java Plug-in component in Oracle Java SE and Java f
Unspecified vulnerability in the Java Web Start, Java Plug-in component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, 1.4.2_25, and 1.3.1_27 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.
nvd