cbcvebase.

Sun Jre vulnerabilities

423 known vulnerabilities affecting sun/jre.

Total CVEs
423
CISA KEV
2
actively exploited
Public exploits
36
Exploited in wild
13
Severity breakdown
CRITICAL162HIGH77MEDIUM162LOW20

Vulnerabilities

Page 2 of 22
CVE-2010-0838P2HIGHCVSS 7.5PoC≤ 1.6.0v1.6.0+2 more2010-04-01
CVE-2010-0838 [HIGH] CVE-2010-0838: Unspecified vulnerability in the Java 2D component in Oracle Java SE and Java for Business 6 Update Unspecified vulnerability in the Java 2D component in Oracle Java SE and Java for Business 6 Update 18, 5.0, Update, and 23 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the March 2010 CPU. Oracle has not commented on claims from a reliable researcher that this
nvd
CVE-2008-1193P3CRITICALCVSS 9.3PoCv1.5.0v1.6.02008-03-06
CVE-2008-1193 [CRITICAL] CWE-264 CVE-2008-1193: Unspecified vulnerability in Java Runtime Environment Image Parsing Library in Sun JDK and JRE 6 Upd Unspecified vulnerability in Java Runtime Environment Image Parsing Library in Sun JDK and JRE 6 Update 4 and earlier, and 5.0 Update 14 and earlier, allows remote attackers to gain privileges via an untrusted application.
nvd
CVE-2004-1029P3CRITICALCVSS 9.3PoCv1.3.0v1.3.1+16 more2005-03-01
CVE-2004-1029 [CRITICAL] CWE-264 CVE-2004-1029: The Sun Java Plugin capability in Java 2 Runtime Environment (JRE) 1.4.2_01, 1.4.2_04, and possibly The Sun Java Plugin capability in Java 2 Runtime Environment (JRE) 1.4.2_01, 1.4.2_04, and possibly earlier versions, does not properly restrict access between Javascript and Java applets during data transfer, which allows remote attackers to load unsafe classes and execute arbitrary code by using the reflection API to access private Java packages.
nvd
CVE-2009-1672P3CRITICALCVSS 9.3PoCv62009-05-18
CVE-2009-1672 [CRITICAL] CWE-119 CVE-2009-1672: The Deployment Toolkit ActiveX control in deploytk.dll 6.0.130.3 in Sun Java SE Runtime Environment The Deployment Toolkit ActiveX control in deploytk.dll 6.0.130.3 in Sun Java SE Runtime Environment (aka JRE) 6 Update 13 allows remote attackers to (1) execute arbitrary code via a .jnlp URL in the argument to the launch method, and might allow remote attackers to launch JRE installation processes via the (2) installLatestJRE or (3) installJRE metho
nvd
CVE-2009-1671P3CRITICALCVSS 9.3PoCv62009-05-18
CVE-2009-1671 [CRITICAL] CWE-119 CVE-2009-1671: Multiple buffer overflows in the Deployment Toolkit ActiveX control in deploytk.dll 6.0.130.3 in Sun Multiple buffer overflows in the Deployment Toolkit ActiveX control in deploytk.dll 6.0.130.3 in Sun Java SE Runtime Environment (aka JRE) 6 Update 13 allow remote attackers to execute arbitrary code via a long string argument to the (1) setInstallerType, (2) setAdditionalPackages, (3) compareVersion, (4) getStaticCLSID, or (5) launch method.
nvd
CVE-2007-5019P3CRITICALCVSS 10.0PoCv1.6.0_0v1.6.0_102007-09-20
CVE-2007-5019 [CRITICAL] CWE-119 CVE-2007-5019: Buffer overflow in the Sun Java Web Start ActiveX control in Java Runtime Environment (JRE) 1.6.0_X Buffer overflow in the Sun Java Web Start ActiveX control in Java Runtime Environment (JRE) 1.6.0_X allows remote attackers to have an unknown impact via a long argument to the dnsResolve (isInstalled.dnsResolve) method.
nvd
CVE-2012-0551P3MEDIUMCVSS 5.8PoCv1.6.02012-05-03
CVE-2012-0551 [MEDIUM] CVE-2012-0551: Unspecified vulnerability in the Java Runtime Environment (JRE) in Oracle Java SE 7 update 4 and ear Unspecified vulnerability in the Java Runtime Environment (JRE) in Oracle Java SE 7 update 4 and earlier and 6 update 32 and earlier, and the GlassFish Enterprise Server component in Oracle Sun Products Suite GlassFish Enterprise Server 3.1.1, allows remote attackers to affect confidentiality and integrity via unknown vectors related to Web Container or Deplo
nvd
CVE-2007-2788P3MEDIUMCVSS 6.8PoCv1.3.1v1.3.1_2+35 more2007-05-22
CVE-2007-2788 [MEDIUM] CWE-189 CVE-2007-2788: Integer overflow in the embedded ICC profile image parser in Sun Java Development Kit (JDK) before 1 Integer overflow in the embedded ICC profile image parser in Sun Java Development Kit (JDK) before 1.5.0_11-b03 and 1.6.x before 1.6.0_01-b06, and Sun Java Runtime Environment in JDK and JRE 6, JDK and JRE 5.0 Update 10 and earlier, SDK and JRE 1.4.2_14 and earlier, and SDK and JRE 1.3.1_20 and earlier, allows remote attackers to execute arbitrary cod
nvd
CVE-2013-2419P3MEDIUMCVSS 5.0PoCv1.6.0v1.5.02013-04-17
CVE-2013-2419 [MEDIUM] CVE-2013-2419: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, 6 Update 43 and earlier, and 5.0 Update 41 and earlier; and OpenJDK 6 and 7; allows remote attackers to affect availability via unknown vectors related to 2D. NOTE: the previous information is from the April 2013 CPU. Oracle has not commented o
nvd
CVE-2007-3655P3MEDIUMCVSS 6.8PoCv1.5.0v1.6.02007-07-10
CVE-2007-3655 [MEDIUM] CWE-119 CVE-2007-3655: Stack-based buffer overflow in javaws.exe in Sun Java Web Start in JRE 5.0 Update 11 and earlier, an Stack-based buffer overflow in javaws.exe in Sun Java Web Start in JRE 5.0 Update 11 and earlier, and 6.0 Update 1 and earlier, allows remote attackers to execute arbitrary code via a long codebase attribute in a JNLP file.
nvd
CVE-2007-4381P3CRITICALCVSS 9.3PoC≤ 1.4.22007-08-17
CVE-2007-4381 [CRITICAL] CVE-2007-4381: Unspecified vulnerability in the font parsing implementation in Sun JDK and JRE 5.0 Update 9 and ear Unspecified vulnerability in the font parsing implementation in Sun JDK and JRE 5.0 Update 9 and earlier, and SDK and JRE 1.4.2_14 and earlier, allows remote attackers to perform unauthorized actions via an applet that grants certain privileges to itself.
nvd
CVE-2003-0896P3HIGHCVSS 7.5PoC≤ 1.4.12003-11-17
CVE-2003-0896 [HIGH] CVE-2003-0896: The loadClass method of the sun.applet.AppletClassLoader class in the Java Virtual Machine (JVM) in The loadClass method of the sun.applet.AppletClassLoader class in the Java Virtual Machine (JVM) in Sun SDK and JRE 1.4.1_03 and earlier allows remote attackers to bypass sandbox restrictions and execute arbitrary code via a loaded class name that contains "/" (slash) instead of "." (dot) characters, which bypasses a call to the Security Manager's checkPackageAc
nvd
CVE-2010-3573P3MEDIUMCVSS 5.1PoC≤ 1.6.0v1.6.0+2 more2010-10-19
CVE-2010-3573 [MEDIUM] CVE-2010-3573: Unspecified vulnerability in the Networking component in Oracle Java SE and Java for Business 6 Upda Unspecified vulnerability in the Networking component in Oracle Java SE and Java for Business 6 Update 21 and 5.0 Update 25 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the October 2010 CPU. Oracle has not commented on claims from a reliable downstream vend
nvd
CVE-2010-4476P3MEDIUMCVSS 5.0PoC≤ 1.6.0v1.6.0+32 more2011-02-17
CVE-2010-4476 [MEDIUM] CVE-2010-4476: The Double.parseDouble method in Java Runtime Environment (JRE) in Oracle Java SE and Java for Busin The Double.parseDouble method in Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 23 and earlier, 5.0 Update 27 and earlier, and 1.4.2_29 and earlier, as used in OpenJDK, Apache, JBossweb, and other products, allows remote attackers to cause a denial of service via a crafted string that triggers an infinite loop of estimations d
nvd
CVE-2003-1123P3HIGHCVSS 7.5PoCv1.2.2v1.2.2_003+7 more2003-12-31
CVE-2003-1123 [HIGH] CVE-2003-1123: Sun Java Runtime Environment (JRE) and SDK 1.4.0_01 and earlier allows untrusted applets to access c Sun Java Runtime Environment (JRE) and SDK 1.4.0_01 and earlier allows untrusted applets to access certain information within trusted applets, which allows attackers to bypass the restrictions of the Java security model.
nvd
CVE-2007-0243P3MEDIUMCVSS 6.8PoC≤ 1.3.1v1.3.1+13 more2007-01-17
CVE-2007-0243 [MEDIUM] CWE-119 CVE-2007-0243: Buffer overflow in Sun JDK and Java Runtime Environment (JRE) 5.0 Update 9 and earlier, SDK and JRE Buffer overflow in Sun JDK and Java Runtime Environment (JRE) 5.0 Update 9 and earlier, SDK and JRE 1.4.2_12 and earlier, and SDK and JRE 1.3.1_18 and earlier allows applets to gain privileges via a GIF image with a block with a 0 width field, which triggers memory corruption.
nvd
CVE-2013-1537P3CRITICALCVSS 10.0v1.6.0v1.5.02013-04-17
CVE-2013-1537 [CRITICAL] CVE-2013-1537: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, 6 Update 43 and earlier, and 5.0 Update 41 and earlier; and OpenJDK 6 and 7; allows remote attackers to affect confidentiality, integrity, and availability via vectors related to RMI. NOTE: the previous information is from the April 2013 CPU.
nvd
CVE-2013-2432P3CRITICALCVSS 10.0v1.6.0v1.5.02013-04-17
CVE-2013-2432 [CRITICAL] CVE-2013-2432: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, 6 Update 43 and earlier, 5.0 Update 41 and earlier, and JavaFX 2.2.7 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D, a different vulnerability than CVE-2013-2394 an
nvd
CVE-2013-0809P3CRITICALCVSS 10.0v1.6.0v1.5.02013-03-05
CVE-2013-0809 [CRITICAL] CVE-2013-0809: Unspecified vulnerability in the 2D component in the Java Runtime Environment (JRE) component in Ora Unspecified vulnerability in the 2D component in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 15 and earlier, 6 Update 41 and earlier, and 5.0 Update 40 and earlier allows remote attackers to execute arbitrary code via unknown vectors, a different vulnerability than CVE-2013-1493.
nvd
CVE-2013-5782P3CRITICALCVSS 10.0v1.6.0v1.5.02013-10-16
CVE-2013-5782 [CRITICAL] CVE-2013-5782: Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, JRockit R28.2.8 and earlier, JRockit R27.7.6 and earlier, and Java SE Embedded 7u40 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D.
nvd
Sun Jre vulnerabilities | cvebase