Sun Jre vulnerabilities
423 known vulnerabilities affecting sun/jre.
Total CVEs
423
CISA KEV
2
actively exploited
Public exploits
36
Exploited in wild
3
Severity breakdown
CRITICAL162HIGH77MEDIUM162LOW20
Vulnerabilities
Page 15 of 22
CVE-2009-3883HIGHCVSS 7.5≤ 1.5.0v1.5.0+2 more2009-11-09
CVE-2009-3883 [HIGH] CWE-200 CVE-2009-3883: Multiple unspecified vulnerabilities in the Windows Pluggable Look and Feel (PL&F) feature in the Sw
Multiple unspecified vulnerabilities in the Windows Pluggable Look and Feel (PL&F) feature in the Swing implementation in Sun Java SE 5.0 before Update 22 and 6 before Update 17, and OpenJDK, have unknown impact and remote attack vectors, related to "information leaks in mutable variables," aka Bug Id 6657138.
nvd
CVE-2009-3879HIGHCVSS 7.5≤ 1.5.0≤ 1.6.0+2 more2009-11-09
CVE-2009-3879 [HIGH] CVE-2009-3879: Multiple unspecified vulnerabilities in the (1) X11 and (2) Win32GraphicsDevice subsystems in Sun Ja
Multiple unspecified vulnerabilities in the (1) X11 and (2) Win32GraphicsDevice subsystems in Sun Java SE 5.0 before Update 22 and 6 before Update 17, and OpenJDK, have unknown impact and attack vectors, related to failure to clone arrays that are returned by the getConfigurations function, aka Bug Id 6822057.
nvd
CVE-2009-3886HIGHCVSS 7.5≤ 1.6.0v1.6.02009-11-09
CVE-2009-3886 [HIGH] CVE-2009-3886: The Java Web Start implementation in Sun Java SE 6 before Update 17 does not properly handle the int
The Java Web Start implementation in Sun Java SE 6 before Update 17 does not properly handle the interaction between a signed JAR file and a JNLP (1) application or (2) applet, which has unspecified impact and attack vectors, related to a "regression," aka Bug Id 6870531.
nvd
CVE-2009-3881HIGHCVSS 7.5≤ 1.5.0≤ 1.6.0+2 more2009-11-09
CVE-2009-3881 [HIGH] CWE-200 CVE-2009-3881: Sun Java SE 5.0 before Update 22 and 6 before Update 17, and OpenJDK, does not prevent the existence
Sun Java SE 5.0 before Update 22 and 6 before Update 17, and OpenJDK, does not prevent the existence of children of a resurrected ClassLoader, which allows remote attackers to gain privileges via unspecified vectors, related to an "information leak vulnerability," aka Bug Id 6636650.
nvd
CVE-2009-3729MEDIUMCVSS 5.0≤ 1.5.0≤ 1.6.0+2 more2009-11-09
CVE-2009-3729 [MEDIUM] CVE-2009-3729: Unspecified vulnerability in the TrueType font parsing functionality in Sun Java SE 5.0 before Updat
Unspecified vulnerability in the TrueType font parsing functionality in Sun Java SE 5.0 before Update 22 and 6 before Update 17 allows remote attackers to cause a denial of service (application crash) via a certain test suite, aka Bug Id 6815780.
nvd
CVE-2009-3885MEDIUMCVSS 5.0≤ 1.5.0≤ 1.6.0+4 more2009-11-09
CVE-2009-3885 [MEDIUM] CVE-2009-3885: Sun Java SE 5.0 before Update 22 and 6 before Update 17 on Windows allows remote attackers to cause
Sun Java SE 5.0 before Update 22 and 6 before Update 17 on Windows allows remote attackers to cause a denial of service via a BMP file containing a link to a UNC share pathname for an International Color Consortium (ICC) profile file, probably a related issue to CVE-2007-2789, aka Bug Id 6632445.
nvd
CVE-2009-3884MEDIUMCVSS 5.0≤ 1.5.0≤ 1.6.0+2 more2009-11-09
CVE-2009-3884 [MEDIUM] CVE-2009-3884: The TimeZone.getTimeZone method in Sun Java SE 5.0 before Update 22 and 6 before Update 17, and Open
The TimeZone.getTimeZone method in Sun Java SE 5.0 before Update 22 and 6 before Update 17, and OpenJDK, allows remote attackers to determine the existence of local files via vectors related to handling of zoneinfo (aka tz) files, aka Bug Id 6824265.
nvd
CVE-2009-3728MEDIUMCVSS 5.0v1.5.0v1.6.02009-11-09
CVE-2009-3728 [MEDIUM] CWE-22 CVE-2009-3728: Directory traversal vulnerability in the ICC_Profile.getInstance method in Java Runtime Environment
Directory traversal vulnerability in the ICC_Profile.getInstance method in Java Runtime Environment (JRE) in Sun Java SE 5.0 before Update 22 and 6 before Update 17, and OpenJDK, allows remote attackers to determine the existence of local International Color Consortium (ICC) profile files via a .. (dot dot) in a pathname, aka Bug Id 6631533.
nvd
CVE-2009-3880MEDIUMCVSS 5.0≤ 1.5.0≤ 1.6.0+2 more2009-11-09
CVE-2009-3880 [MEDIUM] CWE-264 CVE-2009-3880: The Abstract Window Toolkit (AWT) in Java Runtime Environment (JRE) in Sun Java SE 5.0 before Update
The Abstract Window Toolkit (AWT) in Java Runtime Environment (JRE) in Sun Java SE 5.0 before Update 22 and 6 before Update 17, and OpenJDK, does not properly restrict the objects that may be sent to loggers, which allows attackers to obtain sensitive information via vectors related to the implementation of Component, KeyboardFocusManager, and Default
nvd
CVE-2009-3869CRITICALCVSS 9.3PoCv1.5.0v1.6.0+66 more2009-11-05
CVE-2009-3869 [CRITICAL] CWE-119 CVE-2009-3869: Stack-based buffer overflow in the setDiffICM function in the Abstract Window Toolkit (AWT) in Java
Stack-based buffer overflow in the setDiffICM function in the Abstract Window Toolkit (AWT) in Java Runtime Environment (JRE) in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to execute arbitrary code via a crafted argum
nvd
CVE-2009-3868CRITICALCVSS 9.3v1.5.0v1.6.0+66 more2009-11-05
CVE-2009-3868 [CRITICAL] CWE-119 CVE-2009-3868: Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x b
Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK and JRE 1.4.x before 1.4.2_24 does not properly parse color profiles, which allows remote attackers to gain privileges via a crafted image file, aka Bug Id 6862970.
nvd
CVE-2009-3871CRITICALCVSS 9.3v1.5.0v1.6.0+66 more2009-11-05
CVE-2009-3871 [CRITICAL] CWE-119 CVE-2009-3871: Heap-based buffer overflow in the setBytePixels function in the Abstract Window Toolkit (AWT) in Jav
Heap-based buffer overflow in the setBytePixels function in the Abstract Window Toolkit (AWT) in Java Runtime Environment (JRE) in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to execute arbitrary code via crafted argu
nvd
CVE-2009-3866CRITICALCVSS 9.3v1.6.02009-11-05
CVE-2009-3866 [CRITICAL] CWE-264 CVE-2009-3866: The Java Web Start Installer in Sun Java SE in JDK and JRE 6 before Update 17 does not properly use
The Java Web Start Installer in Sun Java SE in JDK and JRE 6 before Update 17 does not properly use security model permissions when removing installer extensions, which allows remote attackers to execute arbitrary code by modifying a certain JNLP file to have a URL field that points to an unintended trusted application, aka Bug Id 6872824.
nvd
CVE-2009-3867CRITICALCVSS 9.3PoCv1.5.0v1.6.0+66 more2009-11-05
CVE-2009-3867 [CRITICAL] CWE-119 CVE-2009-3867: Stack-based buffer overflow in the HsbParser.getSoundBank function in Sun Java SE in JDK and JRE 5.0
Stack-based buffer overflow in the HsbParser.getSoundBank function in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to execute arbitrary code via a long file: URL in an argument, aka Bug Id 6854303.
nvd
CVE-2009-3874CRITICALCVSS 9.3v1.5.0v1.6.0+66 more2009-11-05
CVE-2009-3874 [CRITICAL] CWE-189 CVE-2009-3874: Integer overflow in the JPEGImageReader implementation in the ImageI/O component in Sun Java SE in J
Integer overflow in the JPEGImageReader implementation in the ImageI/O component in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to execute arbitrary code via large subsample dimensions in a JPEG file that triggers a heap-based buffer overflow, aka Bug
nvd
CVE-2009-3872CRITICALCVSS 9.3v1.5.0v1.6.0+66 more2009-11-05
CVE-2009-3872 [CRITICAL] CVE-2009-3872: Unspecified vulnerability in the JPEG JFIF Decoder in Sun Java SE in JDK and JRE 5.0 before Update 2
Unspecified vulnerability in the JPEG JFIF Decoder in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to gain privileges via a crafted image file, aka Bug Id 6862969.
nvd
CVE-2009-3865CRITICALCVSS 9.3v1.6.02009-11-05
CVE-2009-3865 [CRITICAL] CWE-94 CVE-2009-3865: The launch method in the Deployment Toolkit plugin in Java Runtime Environment (JRE) in Sun Java SE
The launch method in the Deployment Toolkit plugin in Java Runtime Environment (JRE) in Sun Java SE in JDK and JRE 6 before Update 17 allows remote attackers to execute arbitrary commands via a crafted web page, aka Bug Id 6869752.
nvd
CVE-2009-3873CRITICALCVSS 9.3v1.5.0v1.6.0+66 more2009-11-05
CVE-2009-3873 [CRITICAL] CWE-119 CVE-2009-3873: The JPEG Image Writer in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Updat
The JPEG Image Writer in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to gain privileges via a crafted image file, related to a "quantization problem," aka Bug Id 6862968.
nvd
CVE-2009-3864HIGHCVSS 7.5v1.5.0v1.6.02009-11-05
CVE-2009-3864 [HIGH] CVE-2009-3864: The Java Update functionality in Java Runtime Environment (JRE) in Sun Java SE in JDK and JRE 5.0 be
The Java Update functionality in Java Runtime Environment (JRE) in Sun Java SE in JDK and JRE 5.0 before Update 22 and JDK and JRE 6 before Update 17, when a non-English version of Windows is used, does not retrieve available new JRE versions, which allows remote attackers to leverage vulnerabilities in older releases of this software, aka Bug Id 6869694.
nvd
CVE-2009-3877MEDIUMCVSS 5.0v1.4.2_1v1.4.2_2+66 more2009-11-05
CVE-2009-3877 [MEDIUM] CWE-399 CVE-2009-3877: Unspecified vulnerability in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before U
Unspecified vulnerability in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to cause a denial of service (memory consumption) via crafted HTTP headers, which are not properly parsed by the ASN.1 DER input stream parser, ak
nvd