Sun Jre vulnerabilities
423 known vulnerabilities affecting sun/jre.
Total CVEs
423
CISA KEV
2
actively exploited
Public exploits
36
Exploited in wild
13
Severity breakdown
CRITICAL162HIGH77MEDIUM162LOW20
Vulnerabilities
Page 15 of 22
CVE-2013-2437P4MEDIUMCVSS 5.0v1.6.02013-06-18
CVE-2013-2437 [MEDIUM] CVE-2013-2437: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier and 6 Update 45 and earlier allows remote attackers to affect confidentiality via unknown vectors related to Deployment.
nvd
CVE-2013-2417P4MEDIUMCVSS 5.0v1.6.0v1.5.02013-04-17
CVE-2013-2417 [MEDIUM] CVE-2013-2417: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, 6 Update 43 and earlier, and 5.0 Update 41 and earlier; and OpenJDK 6 and 7; allows remote attackers to affect availability via unknown vectors related to Networking. NOTE: the previous information is from the April 2013 CPU. Oracle has not com
nvd
CVE-2013-0434P4MEDIUMCVSS 5.0v1.6.0v1.5.0+38 more2013-02-02
CVE-2013-0434 [MEDIUM] CVE-2013-0434: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 throug
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, 5.0 through Update 38, and 1.4.2_40 and earlier, and OpenJDK 6 and 7, allows remote attackers to affect confidentiality via vectors related to JAXP. NOTE: the previous information is from the February 2013 CPU. Oracle has not c
nvd
CVE-2013-2457P4MEDIUMCVSS 5.0v1.6.0v1.5.02013-06-18
CVE-2013-2457 [MEDIUM] CVE-2013-2457: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier, and OpenJDK 7, allows remote attackers to affect integrity via vectors related to JMX. NOTE: the previous information is from the June 2013 CPU. Oracle has not commented on claims from ano
nvd
CVE-2012-1718P4MEDIUMCVSS 5.0≤ 1.5.0≤ 1.4.2_372012-06-16
CVE-2012-1718 [MEDIUM] CVE-2012-1718: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update 4 and earlier, 6 update 32 and earlier, 5 update 35 and earlier, and 1.4.2_37 and earlier allows remote attackers to affect availability via unknown vectors related to Security.
nvd
CVE-2012-5075P4MEDIUMCVSS 5.0v1.6.0v1.5.02012-10-16
CVE-2012-5075 [MEDIUM] CVE-2012-5075: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier, 6 Update 35 and earlier, and 5.0 Update 36 and earlier allows remote attackers to affect confidentiality, related to JMX.
nvd
CVE-2012-1719P4MEDIUMCVSS 5.0v1.6.0≤ 1.5.0+39 more2012-06-16
CVE-2012-1719 [MEDIUM] CVE-2012-1719: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update 4 and earlier, 6 update 32 and earlier, 5 update 35 and earlier, and 1.4.2_37 and earlier allows remote attackers to affect integrity, related to CORBA.
nvd
CVE-2010-3541P4MEDIUMCVSS 5.1≤ 1.6.0v1.6.0+59 more2010-10-19
CVE-2010-3541 [MEDIUM] CVE-2010-3541: Unspecified vulnerability in the Networking component in Oracle Java SE and Java for Business 6 Upda
Unspecified vulnerability in the Networking component in Oracle Java SE and Java for Business 6 Update 21, 5.0 Update 25, 1.4.2_27, and 1.3.1_28 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the October 2010 CPU. Oracle has not commented on claims from a rel
nvd
CVE-2010-0093P4MEDIUMCVSS 5.1≤ 1.6.0v1.6.0+28 more2010-04-01
CVE-2010-0093 [MEDIUM] CVE-2010-0093: Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for B
Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, and 1.4.2_25 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors, a different vulnerability than CVE-2010-0095.
nvd
CVE-2010-0085P4MEDIUMCVSS 5.1≤ 1.6.0v1.6.0+56 more2010-04-01
CVE-2010-0085 [MEDIUM] CVE-2010-0085: Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for B
Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, 1.4.2_25, and 1.3.1_27 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors, a different vulnerability than CVE-2010-0088.
nvd
CVE-2009-3875P4MEDIUMCVSS 5.0v1.4.2_1v1.4.2_2+66 more2009-11-05
CVE-2009-3875 [MEDIUM] CWE-310 CVE-2009-3875: The MessageDigest.isEqual function in Java Runtime Environment (JRE) in Sun Java SE in JDK and JRE 5
The MessageDigest.isEqual function in Java Runtime Environment (JRE) in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to spoof HMAC-based digital signatures, and possibly bypass authentication, via unspecified vectors rel
nvd
CVE-2008-1191P4MEDIUMCVSS 6.8≤ 6_update_42008-03-06
CVE-2008-1191 [MEDIUM] CVE-2008-1191: Unspecified vulnerability in Java Web Start in Sun JDK and JRE 6 Update 4 and earlier allows remote
Unspecified vulnerability in Java Web Start in Sun JDK and JRE 6 Update 4 and earlier allows remote attackers to create arbitrary files via an untrusted application, a different issue than CVE-2008-1190, aka "The fifth issue."
nvd
CVE-2008-5346P4HIGHCVSS 7.1v1.3.1v1.3.1_2+41 more2008-12-05
CVE-2008-5346 [HIGH] CWE-200 CVE-2008-5346: Unspecified vulnerability in Java Runtime Environment (JRE) for Sun JDK and JRE 5.0 Update 16 and ea
Unspecified vulnerability in Java Runtime Environment (JRE) for Sun JDK and JRE 5.0 Update 16 and earlier; SDK and JRE 1.4.2_18 and earlier; and SDK and JRE 1.3.1_23 or earlier allows untrusted applets and applications to read arbitrary memory via a crafted ZIP file.
nvd
CVE-2009-3886P4HIGHCVSS 7.5≤ 1.6.0v1.6.02009-11-09
CVE-2009-3886 [HIGH] CVE-2009-3886: The Java Web Start implementation in Sun Java SE 6 before Update 17 does not properly handle the int
The Java Web Start implementation in Sun Java SE 6 before Update 17 does not properly handle the interaction between a signed JAR file and a JNLP (1) application or (2) applet, which has unspecified impact and attack vectors, related to a "regression," aka Bug Id 6870531.
nvd
CVE-2013-1473P4MEDIUMCVSS 5.0v1.6.02013-02-02
CVE-2013-1473 [MEDIUM] CVE-2013-1473: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 throug
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11 and 6 through Update 38 allows remote attackers to affect integrity via unknown vectors related to Deployment.
nvd
CVE-2013-0435P4MEDIUMCVSS 5.0v1.6.02013-02-02
CVE-2013-0435 [MEDIUM] CVE-2013-0435: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 throug
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11 and 6 through Update 38, and OpenJDK 6 and 7, allows remote attackers to affect confidentiality via vectors related to JAX-WS. NOTE: the previous information is from the February 2013 CPU. Oracle has not commented on claims from another vendor that
nvd
CVE-2013-2450P4MEDIUMCVSS 5.0v1.6.0v1.5.02013-06-18
CVE-2013-2450 [MEDIUM] CVE-2013-2450: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier, and OpenJDK 7, allows remote attackers to affect availability via unknown vectors related to Serialization. NOTE: the previous information is from the June 2013 CPU. Oracle has not comment
nvd
CVE-2013-0433P4MEDIUMCVSS 5.0v1.6.0v1.5.02013-02-02
CVE-2013-0433 [MEDIUM] CVE-2013-0433: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 throug
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, and 5.0 through Update 38, and OpenJDK 6 and 7, allows remote attackers to affect integrity via unknown vectors related to Networking. NOTE: the previous information is from the February 2013 CPU. Oracle has not commented on cl
nvd
CVE-2007-3698P4HIGHCVSS 7.8v1.4.2_11v1.4.2_12+4 more2007-07-11
CVE-2007-3698 [HIGH] CVE-2007-3698: The Java Secure Socket Extension (JSSE) in Sun JDK and JRE 6 Update 1 and earlier, JDK and JRE 5.0 U
The Java Secure Socket Extension (JSSE) in Sun JDK and JRE 6 Update 1 and earlier, JDK and JRE 5.0 Updates 7 through 11, and SDK and JRE 1.4.2_11 through 1.4.2_14, when using JSSE for SSL/TLS support, allows remote attackers to cause a denial of service (CPU consumption) via certain SSL/TLS handshake requests.
nvd
CVE-2013-2412P4MEDIUMCVSS 5.0v1.6.02013-06-18
CVE-2013-2412 [MEDIUM] CVE-2013-2412: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier and 6 Update 45 and earlier, and OpenJDK 7, allows remote attackers to affect confidentiality via unknown vectors related to Serviceability. NOTE: the previous information is from the June 2013 CPU. Oracle has not commented on claims from anothe
nvd