Sun Jre vulnerabilities
423 known vulnerabilities affecting sun/jre.
Total CVEs
423
CISA KEV
2
actively exploited
Public exploits
36
Exploited in wild
3
Severity breakdown
CRITICAL162HIGH77MEDIUM162LOW20
Vulnerabilities
Page 13 of 22
CVE-2010-3572CRITICALCVSS 10.0≤ 1.6.0v1.6.0+59 more2010-10-19
CVE-2010-3572 [CRITICAL] CVE-2010-3572: Unspecified vulnerability in the Sound component in Oracle Java SE and Java for Business 6 Update 21
Unspecified vulnerability in the Sound component in Oracle Java SE and Java for Business 6 Update 21, 5.0 Update 25, 1.4.2_27, and 1.3.1_28 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.
nvd
CVE-2010-3552CRITICALCVSS 10.0PoC≤ 1.6.0v1.6.02010-10-19
CVE-2010-3552 [CRITICAL] CVE-2010-3552: Unspecified vulnerability in the New Java Plug-in component in Oracle Java SE and Java for Business
Unspecified vulnerability in the New Java Plug-in component in Oracle Java SE and Java for Business 6 Update 21 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.
nvd
CVE-2010-3562CRITICALCVSS 10.0≤ 1.6.0v1.6.0+59 more2010-10-19
CVE-2010-3562 [CRITICAL] CVE-2010-3562: Unspecified vulnerability in the 2D component in Oracle Java SE and Java for Business 6 Update 21, 5
Unspecified vulnerability in the 2D component in Oracle Java SE and Java for Business 6 Update 21, 5.0 Update 25, 1.4.2_27, and 1.3.1_28 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the October 2010 CPU. Oracle has not commented on claims from a reliable
nvd
CVE-2010-3574CRITICALCVSS 10.0≤ 1.6.0v1.6.0+59 more2010-10-19
CVE-2010-3574 [CRITICAL] CVE-2010-3574: Unspecified vulnerability in the Networking component in Oracle Java SE and Java for Business 6 Upda
Unspecified vulnerability in the Networking component in Oracle Java SE and Java for Business 6 Update 21, 5.0 Update 25, 1.4.2_27, and 1.3.1_28 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the October 2010 CPU. Oracle has not commented on claims from a r
nvd
CVE-2010-3561HIGHCVSS 7.5≤ 1.6.0v1.6.0+2 more2010-10-19
CVE-2010-3561 [HIGH] CVE-2010-3561: Unspecified vulnerability in the CORBA component in Oracle Java SE and Java for Business 6 Update 21
Unspecified vulnerability in the CORBA component in Oracle Java SE and Java for Business 6 Update 21 and 5.0 Update 25 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the October 2010 CPU. Oracle has not commented on claims from a reliable downstream vendor that
nvd
CVE-2010-3570HIGHCVSS 7.6≤ 1.6.0v1.6.02010-10-19
CVE-2010-3570 [HIGH] CVE-2010-3570: Unspecified vulnerability in the Deployment Toolkit component in Oracle Java SE and Java for Busines
Unspecified vulnerability in the Deployment Toolkit component in Oracle Java SE and Java for Business 6 Update 21 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.
nvd
CVE-2010-3541MEDIUMCVSS 5.1≤ 1.6.0v1.6.0+59 more2010-10-19
CVE-2010-3541 [MEDIUM] CVE-2010-3541: Unspecified vulnerability in the Networking component in Oracle Java SE and Java for Business 6 Upda
Unspecified vulnerability in the Networking component in Oracle Java SE and Java for Business 6 Update 21, 5.0 Update 25, 1.4.2_27, and 1.3.1_28 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the October 2010 CPU. Oracle has not commented on claims from a rel
nvd
CVE-2010-3573MEDIUMCVSS 5.1PoC≤ 1.6.0v1.6.0+2 more2010-10-19
CVE-2010-3573 [MEDIUM] CVE-2010-3573: Unspecified vulnerability in the Networking component in Oracle Java SE and Java for Business 6 Upda
Unspecified vulnerability in the Networking component in Oracle Java SE and Java for Business 6 Update 21 and 5.0 Update 25 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the October 2010 CPU. Oracle has not commented on claims from a reliable downstream vend
nvd
CVE-2010-3551MEDIUMCVSS 5.0≤ 1.6.0v1.6.0+30 more2010-10-19
CVE-2010-3551 [MEDIUM] CVE-2010-3551: Unspecified vulnerability in the Networking component in Oracle Java SE and Java for Business 6 Upda
Unspecified vulnerability in the Networking component in Oracle Java SE and Java for Business 6 Update 21, 5.0 Update 25, and 1.4.2_27 allows remote attackers to affect confidentiality via unknown vectors.
nvd
CVE-2010-3549MEDIUMCVSS 6.8≤ 1.6.0v1.6.0+59 more2010-10-19
CVE-2010-3549 [MEDIUM] CVE-2010-3549: Unspecified vulnerability in the Networking component in Oracle Java SE and Java for Business 6 Upda
Unspecified vulnerability in the Networking component in Oracle Java SE and Java for Business 6 Update 21, 5.0 Update 25, 1.4.2_27, and 1.3.1_28 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the October 2010 CPU. Oracle has not commented on claims from a rel
nvd
CVE-2010-3548MEDIUMCVSS 5.0≤ 1.6.0v1.6.0+30 more2010-10-19
CVE-2010-3548 [MEDIUM] CVE-2010-3548: Unspecified vulnerability in the Java Naming and Directory Interface (JNDI) component in Oracle Java
Unspecified vulnerability in the Java Naming and Directory Interface (JNDI) component in Oracle Java SE and Java for Business 6 Update 21, 5.0 Update 25, and 1.4.2_27 allows remote attackers to affect confidentiality via unknown vectors. NOTE: the previous information was obtained from the October 2010 CPU. Oracle has not commented on claims from a reliable d
nvd
CVE-2010-3557MEDIUMCVSS 6.8≤ 1.6.0v1.6.0+59 more2010-10-19
CVE-2010-3557 [MEDIUM] CVE-2010-3557: Unspecified vulnerability in the Swing component in Oracle Java SE and Java for Business 6 Update 21
Unspecified vulnerability in the Swing component in Oracle Java SE and Java for Business 6 Update 21, 5.0 Update 25, 1.4.2_27, and 1.3.1_28 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the October 2010 CPU. Oracle has not commented on claims from a reliable
nvd
CVE-2010-3560LOWCVSS 2.6≤ 1.6.0v1.6.02010-10-19
CVE-2010-3560 [LOW] CVE-2010-3560: Unspecified vulnerability in the Networking component in Oracle Java SE and Java for Business 6 Upda
Unspecified vulnerability in the Networking component in Oracle Java SE and Java for Business 6 Update 21 allows remote attackers to affect confidentiality via unknown vectors.
nvd
CVE-2010-0886CRITICALCVSS 10.0PoCv1.6.02010-04-20
CVE-2010-0886 [CRITICAL] CVE-2010-0886: Unspecified vulnerability in the Java Deployment Toolkit component in Oracle Java SE and Java for Bu
Unspecified vulnerability in the Java Deployment Toolkit component in Oracle Java SE and Java for Business JDK and JRE 6 Update 10 through 19 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.
nvd
CVE-2010-0844HIGHCVSS 7.5≤ 1.6.0v1.6.0+56 more2010-04-01
CVE-2010-0844 [HIGH] CVE-2010-0844: Unspecified vulnerability in the Sound component in Oracle Java SE and Java for Business 6 Update 18
Unspecified vulnerability in the Sound component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, 1.4.2_25, and 1.3.1_27 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the March 2010 CPU. Oracle has not commented on claims from a reliable res
nvd
CVE-2010-0843HIGHCVSS 7.5v1.3.1_27v1.4.2_25+2 more2010-04-01
CVE-2010-0843 [HIGH] CVE-2010-0843: Unspecified vulnerability in the Sound component in Oracle Java SE and Java for Business 6 Update 18
Unspecified vulnerability in the Sound component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, 1.4.2_25, and 1.3.1_27 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the March 2010 CPU. Oracle has not commented on claims from a reliable res
nvd
CVE-2010-0837HIGHCVSS 7.5≤ 1.6.0v1.6.0+2 more2010-04-01
CVE-2010-0837 [HIGH] CVE-2010-0837: Unspecified vulnerability in the Pack200 component in Oracle Java SE and Java for Business 6 Update
Unspecified vulnerability in the Pack200 component in Oracle Java SE and Java for Business 6 Update 18, 5.0, Update, and 23 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.
nvd
CVE-2010-0087HIGHCVSS 7.5≤ 1.6.0v1.6.0+56 more2010-04-01
CVE-2010-0087 [HIGH] CVE-2010-0087: Unspecified vulnerability in the Java Web Start, Java Plug-in component in Oracle Java SE and Java f
Unspecified vulnerability in the Java Web Start, Java Plug-in component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, 1.4.2_25, and 1.3.1_27 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.
nvd
CVE-2010-0846HIGHCVSS 7.5≤ 1.6.0v1.6.0+56 more2010-04-01
CVE-2010-0846 [HIGH] CVE-2010-0846: Unspecified vulnerability in the ImageIO component in Oracle Java SE and Java for Business 6 Update
Unspecified vulnerability in the ImageIO component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, 1.4.2_25, and 1.3.1_27 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the March 2010 CPU. Oracle has not commented on claims from a reliable re
nvd
CVE-2010-0848HIGHCVSS 7.5≤ 1.6.0v1.6.0+56 more2010-04-01
CVE-2010-0848 [HIGH] CVE-2010-0848: Unspecified vulnerability in the Java 2D component in Oracle Java SE and Java for Business 6 Update
Unspecified vulnerability in the Java 2D component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, 1.4.2_25, and 1.3.1_27 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.
nvd