cbcvebase.

Sun Jre vulnerabilities

423 known vulnerabilities affecting sun/jre.

Total CVEs
423
CISA KEV
2
actively exploited
Public exploits
36
Exploited in wild
13
Severity breakdown
CRITICAL162HIGH77MEDIUM162LOW20

Vulnerabilities

Page 13 of 22
CVE-2010-0088P3MEDIUMCVSS 6.8≤ 1.6.0v1.6.0+56 more2010-04-01
CVE-2010-0088 [MEDIUM] CVE-2010-0088: Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for B Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, 1.4.2_25, and 1.3.1_27 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors, a different vulnerability than CVE-2010-0085.
nvd
CVE-2010-0095P3MEDIUMCVSS 6.8≤ 1.6.0v1.6.0+28 more2010-04-01
CVE-2010-0095 [MEDIUM] CVE-2010-0095: Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for B Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, and 1.4.2_25 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors, a different vulnerability than CVE-2010-0093.
nvd
CVE-2013-3829P3MEDIUMCVSS 6.4v1.6.0v1.5.02013-10-16
CVE-2013-3829 [MEDIUM] CVE-2013-3829: Unspecified vulnerability in the Java SE, Java SE Embedded component in Oracle Java SE Java SE 7u40 Unspecified vulnerability in the Java SE, Java SE Embedded component in Oracle Java SE Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, and Java SE Embedded 7u40 and earlier allows remote attackers to affect confidentiality and integrity via unknown vectors related to Libraries.
nvd
CVE-2013-5812P3MEDIUMCVSS 6.4v1.6.02013-10-16
CVE-2013-5812 [MEDIUM] CVE-2013-5812: Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, and Java SE Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, and Java SE Embedded 7u40 and earlier allows remote attackers to affect confidentiality and availability via unknown vectors related to Deployment.
nvd
CVE-2005-3905P3HIGHCVSS 7.5v1.3.0v1.3.1+11 more2005-11-30
CVE-2005-3905 [HIGH] CVE-2005-3905: Unspecified vulnerability in reflection APIs in Java SDK and JRE 1.3.1_15 and earlier, 1.4.2_08 and Unspecified vulnerability in reflection APIs in Java SDK and JRE 1.3.1_15 and earlier, 1.4.2_08 and earlier, and JDK and JRE 5.0 Update 3 and earlier allows remote attackers to escape the Java sandbox and access arbitrary files or execute arbitrary application via unknown attack vectors, a different vulnerability than CVE-2005-3906. NOTE: this is associated with
nvd
CVE-2008-3109P3HIGHCVSS 7.5≤ 6v62008-07-09
CVE-2008-3109 [HIGH] CWE-264 CVE-2008-3109: Unspecified vulnerability in scripting language support in Sun Java Runtime Environment (JRE) in JDK Unspecified vulnerability in scripting language support in Sun Java Runtime Environment (JRE) in JDK and JRE 6 Update 6 and earlier allows context-dependent attackers to gain privileges via an untrusted (1) application or (2) applet, as demonstrated by an application or applet that grants itself privileges to (a) read local files, (b) write to local fil
nvd
CVE-2002-0076P4HIGHCVSS 7.5v1.1.8v1.2.2+2 more2002-03-19
CVE-2002-0076 [HIGH] CVE-2002-0076: Java Runtime Environment (JRE) Bytecode Verifier allows remote attackers to escape the Java sandbox Java Runtime Environment (JRE) Bytecode Verifier allows remote attackers to escape the Java sandbox and execute commands via an applet containing an illegal cast operation, as seen in (1) Microsoft VM build 3802 and earlier as used in Internet Explorer 4.x and 5.x, (2) Netscape 6.2.1 and earlier, and possibly other implementations that use vulnerable versions of
nvd
CVE-2009-3881P3HIGHCVSS 7.5≤ 1.5.0≤ 1.6.0+2 more2009-11-09
CVE-2009-3881 [HIGH] CWE-200 CVE-2009-3881: Sun Java SE 5.0 before Update 22 and 6 before Update 17, and OpenJDK, does not prevent the existence Sun Java SE 5.0 before Update 22 and 6 before Update 17, and OpenJDK, does not prevent the existence of children of a resurrected ClassLoader, which allows remote attackers to gain privileges via unspecified vectors, related to an "information leak vulnerability," aka Bug Id 6636650.
nvd
CVE-2006-6731P3CRITICALCVSS 9.3v1.3.1v1.3.1_2+30 more2006-12-26
CVE-2006-6731 [CRITICAL] CVE-2006-6731: Multiple buffer overflows in Sun Java Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 U Multiple buffer overflows in Sun Java Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 7 and earlier, Java System Development Kit (SDK) and JRE 1.4.2_12 and earlier 1.4.x versions, and SDK and JRE 1.3.1_18 and earlier allow attackers to develop Java applets that read, write, or execute local files, possibly related to (1) integer overflow
nvd
CVE-2010-3549P3MEDIUMCVSS 6.8≤ 1.6.0v1.6.0+59 more2010-10-19
CVE-2010-3549 [MEDIUM] CVE-2010-3549: Unspecified vulnerability in the Networking component in Oracle Java SE and Java for Business 6 Upda Unspecified vulnerability in the Networking component in Oracle Java SE and Java for Business 6 Update 21, 5.0 Update 25, 1.4.2_27, and 1.3.1_28 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the October 2010 CPU. Oracle has not commented on claims from a rel
nvd
CVE-2008-3105P3HIGHCVSS 8.3≤ 6v62008-07-09
CVE-2008-3105 [HIGH] CWE-264 CVE-2008-3105: Unspecified vulnerability in the JAX-WS client and service in Sun Java Runtime Environment (JRE) in Unspecified vulnerability in the JAX-WS client and service in Sun Java Runtime Environment (JRE) in JDK and JRE 6 Update 6 and earlier allows remote attackers to access URLs or cause a denial of service via unknown vectors involving "processing of XML data" by a trusted application.
nvd
CVE-2008-1196P3MEDIUMCVSS 6.8v1.4.2v1.4.2_1+17 more2008-03-06
CVE-2008-1196 [MEDIUM] CWE-119 CVE-2008-1196: Stack-based buffer overflow in Java Web Start (javaws.exe) in Sun JDK and JRE 6 Update 4 and earlier Stack-based buffer overflow in Java Web Start (javaws.exe) in Sun JDK and JRE 6 Update 4 and earlier and 5.0 Update 14 and earlier; and SDK and JRE 1.4.2_16 and earlier; allows remote attackers to execute arbitrary code via a crafted JNLP file.
nvd
CVE-2005-3907P3HIGHCVSS 7.5v1.3.0v1.3.1+11 more2005-11-30
CVE-2005-3907 [HIGH] CVE-2005-3907: Unspecified vulnerability in Java Runtime Environment in Java JDK and JRE 5.0 Update 3 and earlier a Unspecified vulnerability in Java Runtime Environment in Java JDK and JRE 5.0 Update 3 and earlier allows remote attackers to escape the Java sandbox and access arbitrary files or execute arbitrary applications via unknown attack vectors involving untrusted Java applets.
nvd
CVE-2008-0628P3HIGHCVSS 7.8≤ 1.6.02008-02-06
CVE-2008-0628 [HIGH] CWE-264 CVE-2008-0628: The XML parsing code in Sun Java Runtime Environment JDK and JRE 6 Update 3 and earlier processes ex The XML parsing code in Sun Java Runtime Environment JDK and JRE 6 Update 3 and earlier processes external entity references even when the "external general entities" property is false, which allows remote attackers to conduct XML external entity (XXE) attacks and cause a denial of service or access restricted resources.
nvd
CVE-2009-2676P3MEDIUMCVSS 6.8≤ 1.5.0≤ 1.6.0+25 more2009-08-05
CVE-2009-2676 [MEDIUM] CVE-2009-2676: Unspecified vulnerability in JNLPAppletlauncher in Sun Java SE, and SE for Business, in JDK and JRE Unspecified vulnerability in JNLPAppletlauncher in Sun Java SE, and SE for Business, in JDK and JRE 6 Update 14 and earlier and JDK and JRE 5.0 Update 19 and earlier; and Java SE for Business in SDK and JRE 1.4.2_21 and earlier; allows remote attackers to create or modify arbitrary files via vectors involving an untrusted Java applet that accesses an old versi
nvd
CVE-2010-3557P3MEDIUMCVSS 6.8≤ 1.6.0v1.6.0+59 more2010-10-19
CVE-2010-3557 [MEDIUM] CVE-2010-3557: Unspecified vulnerability in the Swing component in Oracle Java SE and Java for Business 6 Update 21 Unspecified vulnerability in the Swing component in Oracle Java SE and Java for Business 6 Update 21, 5.0 Update 25, 1.4.2_27, and 1.3.1_28 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the October 2010 CPU. Oracle has not commented on claims from a reliable
nvd
CVE-2009-1106P3MEDIUMCVSS 6.4v1.6.02009-03-25
CVE-2009-1106 [MEDIUM] CWE-20 CVE-2009-1106: The Java Plug-in in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 6 Update 12, 11 The Java Plug-in in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 6 Update 12, 11, and 10 does not properly parse crossdomain.xml files, which allows remote attackers to bypass intended access restrictions and connect to arbitrary sites via unknown vectors, aka CR 6798948.
nvd
CVE-2013-2454P3MEDIUMCVSS 5.8v1.6.0v1.5.02013-06-18
CVE-2013-2454 [MEDIUM] CVE-2013-2454: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier, and OpenJDK 7, allows remote attackers to affect confidentiality and integrity via vectors related to JDBC. NOTE: the previous information is from the June 2013 CPU. Oracle has not comment
nvd
CVE-2005-3906P3HIGHCVSS 7.5v1.3.0v1.3.1+11 more2005-11-30
CVE-2005-3906 [HIGH] CVE-2005-3906: Multiple unspecified vulnerabilities in reflection APIs in Java SDK and JRE 1.4.2_08 and earlier and Multiple unspecified vulnerabilities in reflection APIs in Java SDK and JRE 1.4.2_08 and earlier and JDK and JRE 5.0 Update 3 and earlier allow remote attackers to escape the Java sandbox and access arbitrary files or execute arbitrary applications via unknown attack vectors, a different set of vulnerabilities than CVE-2005-3905. NOTE: this is associated with t
nvd
CVE-2012-5069P3MEDIUMCVSS 5.8v1.6.0v1.5.02012-10-16
CVE-2012-5069 [MEDIUM] CVE-2012-5069: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier, 6 Update 35 and earlier, and 5.0 Update 36 and earlier allows remote attackers to affect confidentiality and integrity via unknown vectors related to Concurrency.
nvd