Sun Jre vulnerabilities
423 known vulnerabilities affecting sun/jre.
Total CVEs
423
CISA KEV
2
actively exploited
Public exploits
36
Exploited in wild
13
Severity breakdown
CRITICAL162HIGH77MEDIUM162LOW20
Vulnerabilities
Page 12 of 22
CVE-2011-3516P3HIGHCVSS 7.6≤ 1.6.0v1.6.02011-10-19
CVE-2011-3516 [HIGH] CVE-2011-3516: Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 6
Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 6 Update 27 and earlier, when running on Windows, allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality, integrity, and availability via unknown vectors related to Deployment.
nvd
CVE-2012-0503P3HIGHCVSS 7.5≤ 1.4.2_35v1.4.2+37 more2012-02-15
CVE-2012-0503 [HIGH] CVE-2012-0503: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, 5.0 Update 33 and earlier, and 1.4.2_35 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality, integrity, and availability, related to I18n.
nvd
CVE-2012-0505P3HIGHCVSS 7.5≤ 1.4.2_35v1.4.2+37 more2012-02-15
CVE-2012-0505 [HIGH] CVE-2012-0505: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, 5 Update 33 and earlier, and 1.4.2_35 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality, integrity, and availability via unknown vectors related to Seriali
nvd
CVE-2011-0786P3HIGHCVSS 7.6≤ 1.6.0v1.6.02011-06-14
CVE-2011-0786 [HIGH] CVE-2011-0786: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 6 Update
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 6 Update 25 and earlier, when running on Windows, allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality, integrity, and availability via unknown vectors related to Deployment, a different vulnerability than CVE-2011-0788
nvd
CVE-2011-0788P3HIGHCVSS 7.6≤ 1.6.0v1.6.02011-06-14
CVE-2011-0788 [HIGH] CVE-2011-0788: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 6 Update
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 6 Update 25 and earlier, when running on Windows, allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality, integrity, and availability via unknown vectors related to Deployment, a different vulnerability than CVE-2011-0786
nvd
CVE-2012-1695P3MEDIUMCVSS 6.8v5.0v62012-05-03
CVE-2012-1695 [MEDIUM] CVE-2012-1695: Unspecified vulnerability in the Oracle JRockit component in Oracle Fusion Middleware 28.2.2 and ear
Unspecified vulnerability in the Oracle JRockit component in Oracle Fusion Middleware 28.2.2 and earlier, and JDK/JRE 5 and 6 27.7.1 and earlier, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.
nvd
CVE-2012-4416P3MEDIUMCVSS 6.4v1.6.02012-10-16
CVE-2012-4416 [MEDIUM] CVE-2012-4416: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier, and 6 Update 35 and earlier, allows remote attackers to affect confidentiality and integrity via unknown vectors related to Hotspot.
nvd
CVE-2008-1189P3MEDIUMCVSS 6.8v1.4.2v1.4.2_1+17 more2008-03-06
CVE-2008-1189 [MEDIUM] CVE-2008-1189: Buffer overflow in Java Web Start in Sun JDK and JRE 6 Update 4 and earlier, 5.0 Update 14 and earli
Buffer overflow in Java Web Start in Sun JDK and JRE 6 Update 4 and earlier, 5.0 Update 14 and earlier, and SDK/JRE 1.4.2_16 and earlier allows remote attackers to execute arbitrary code via unknown vectors, a different issue than CVE-2008-1188, aka the "third" issue.
nvd
CVE-2005-3904P3HIGHCVSS 7.5v1.3.0v1.3.1+11 more2005-11-30
CVE-2005-3904 [HIGH] CVE-2005-3904: Unspecified vulnerability in Java Management Extensions (JMX) in Java JDK and JRE 5.0 Update 3, 1.4.
Unspecified vulnerability in Java Management Extensions (JMX) in Java JDK and JRE 5.0 Update 3, 1.4.2 and later, 1.3.1 and later allows remote attackers to escape the Java sandbox and access arbitrary files or execute arbitrary application via unknown attack vectors.
nvd
CVE-2008-5345P3HIGHCVSS 7.5v1.3.1v1.3.1_2+42 more2008-12-05
CVE-2008-5345 [HIGH] CVE-2008-5345: Unspecified vulnerability in Java Runtime Environment (JRE) with Sun JDK and JRE 6 Update 10 and ear
Unspecified vulnerability in Java Runtime Environment (JRE) with Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; SDK and JRE 1.4.2_18 and earlier; and SDK and JRE 1.3.1_23 and earlier allows code that is loaded from a local filesystem to read arbitrary files and make unauthorized connections to localhost via unknown vectors.
nvd
CVE-2008-5351P3HIGHCVSS 7.5≤ 1.4.2_18≤ 5.0+20 more2008-12-05
CVE-2008-5351 [HIGH] CWE-264 CVE-2008-5351: Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 1
Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier accepts UTF-8 encodings that are not the "shortest" form, which makes it easier for attackers to bypass protection mechanisms for other applications that rely on shortest-form UTF-8 encodings.
nvd
CVE-2011-3550P3HIGHCVSS 7.6v1.7.0≤ 1.6.0+1 more2011-10-19
CVE-2011-3550 [HIGH] CVE-2011-3550: Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7,
Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7, 6 Update 27 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality, integrity, and availability, related to AWT.
nvd
CVE-2004-2764P3CRITICALCVSS 10.0v1.4.0v1.4.0_01+32 more2009-06-02
CVE-2004-2764 [CRITICAL] CWE-264 CVE-2004-2764: Sun SDK and Java Runtime Environment (JRE) 1.4.2 through 1.4.2_04, 1.4.1 through 1.4.1_07, and 1.4.0
Sun SDK and Java Runtime Environment (JRE) 1.4.2 through 1.4.2_04, 1.4.1 through 1.4.1_07, and 1.4.0 through 1.4.0_04 allows untrusted applets and unprivileged servlets to gain privileges and read data from other applets via unspecified vectors related to classes in the XSLT processor, aka "XML sniffing."
nvd
CVE-2002-2072P4MEDIUMCVSS 5.0PoCv1.2.2v1.3.12002-12-31
CVE-2002-2072 [MEDIUM] CVE-2002-2072: java.security.AccessController in Sun Java Virtual Machine (JVM) in JRE 1.2.2 and 1.3.1 allows remot
java.security.AccessController in Sun Java Virtual Machine (JVM) in JRE 1.2.2 and 1.3.1 allows remote attackers to cause a denial of service (JVM crash) via a Java program that calls the doPrivileged method with a null argument.
nvd
CVE-2011-3563P3MEDIUMCVSS 6.4≤ 1.4.2_35v1.4.2+37 more2012-02-15
CVE-2011-3563 [MEDIUM] CVE-2011-3563: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, 5.0 Update 33 and earlier, and 1.4.2_35 and earlier allows remote attackers to affect confidentiality and availability via unknown vectors related to Sound.
nvd
CVE-2009-2672P3HIGHCVSS 7.5≤ 6v5.0+1 more2009-08-05
CVE-2009-2672 [HIGH] CWE-264 CVE-2009-2672: The proxy mechanism implementation in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Upd
The proxy mechanism implementation in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15, and JDK and JRE 5.0 before Update 20, does not prevent access to browser cookies by untrusted (1) applets and (2) Java Web Start applications, which allows remote attackers to hijack web sessions via unspecified vectors.
nvd
CVE-2008-5347P3HIGHCVSS 7.5≤ 6v62008-12-05
CVE-2008-5347 [HIGH] CWE-264 CVE-2008-5347: Multiple unspecified vulnerabilities in Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update
Multiple unspecified vulnerabilities in Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier allow untrusted applets and applications to gain privileges via vectors related to access to inner classes in the (1) JAX-WS and (2) JAXB packages.
nvd
CVE-2013-2407P3MEDIUMCVSS 6.4v1.6.02013-06-18
CVE-2013-2407 [MEDIUM] CVE-2013-2407: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier and 6 Update 45 and earlier, and OpenJDK 7, allows remote attackers to affect confidentiality and availability via unknown vectors related to Libraries. NOTE: the previous information is from the June 2013 CPU. Oracle has not commented on claims
nvd
CVE-2013-0432P3MEDIUMCVSS 6.4v1.6.0v1.5.0+38 more2013-02-02
CVE-2013-0432 [MEDIUM] CVE-2013-0432: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 throug
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, 5.0 through Update 38, and 1.4.2_40 and earlier, and OpenJDK 6 and 7, allows remote attackers to affect confidentiality and integrity via vectors related to AWT. NOTE: the previous information is from the February 2013 CPU. Ora
nvd
CVE-2006-6745P3CRITICALCVSS 9.3v1.4.1v1.4.2+14 more2006-12-26
CVE-2006-6745 [CRITICAL] CVE-2006-6745: Multiple unspecified vulnerabilities in Sun Java Development Kit (JDK) and Java Runtime Environment
Multiple unspecified vulnerabilities in Sun Java Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 7 and earlier, and Java System Development Kit (SDK) and JRE 1.4.2_12 and earlier 1.4.x versions, allow attackers to develop Java applets or applications that are able to gain privileges, related to serialization in JRE.
nvd