Sun Jre vulnerabilities
423 known vulnerabilities affecting sun/jre.
Total CVEs
423
CISA KEV
2
actively exploited
Public exploits
36
Exploited in wild
13
Severity breakdown
CRITICAL162HIGH77MEDIUM162LOW20
Vulnerabilities
Page 20 of 22
CVE-2013-2467P4MEDIUMCVSS 6.9v1.5.02013-06-18
CVE-2013-2467 [MEDIUM] CVE-2013-2467: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 5.0 Upda
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 5.0 Update 45 and earlier allows local users to affect confidentiality, integrity, and availability via unknown vectors related to the Java installer.
nvd
CVE-2008-3114P4MEDIUMCVSS 5.0≤ 1.4.2_17≤ 5.0+20 more2008-07-09
CVE-2008-3114 [MEDIUM] CWE-200 CVE-2008-3114: Unspecified vulnerability in Sun Java Web Start in JDK and JRE 6 before Update 7, JDK and JRE 5.0 be
Unspecified vulnerability in Sun Java Web Start in JDK and JRE 6 before Update 7, JDK and JRE 5.0 before Update 16, and SDK and JRE 1.4.x before 1.4.2_18 allows context-dependent attackers to obtain sensitive information (the cache location) via an untrusted application, aka CR 6704074.
nvd
CVE-2002-0058P4MEDIUMCVSS 5.0v1.1.8v1.2.2+1 more2002-03-15
CVE-2002-0058 [MEDIUM] CVE-2002-0058: Vulnerability in Java Runtime Environment (JRE) allows remote malicious web sites to hijack or sniff
Vulnerability in Java Runtime Environment (JRE) allows remote malicious web sites to hijack or sniff a web client's sessions, when an HTTP proxy is being used, via a Java applet that redirects the session to another server, as seen in (1) Netscape 6.0 through 6.1 and 4.79 and earlier, (2) Microsoft VM build 3802 and earlier as used in Internet Explorer 4.x an
nvd
CVE-2006-0616P4MEDIUMCVSS 4.0≤ 1.5.02006-02-09
CVE-2006-0616 [MEDIUM] CVE-2006-0616: Unspecified vulnerability in Sun Java JDK and JRE 5.0 Update 4 and earlier allows remote attackers t
Unspecified vulnerability in Sun Java JDK and JRE 5.0 Update 4 and earlier allows remote attackers to bypass Java sandbox security and obtain privileges via unspecified vectors involving the reflection APIs, aka the "fourth issue."
nvd
CVE-2007-5232P4MEDIUMCVSS 4.0v1.3.0v1.3.1+15 more2007-10-05
CVE-2007-5232 [MEDIUM] CVE-2007-5232: Sun Java Runtime Environment (JRE) in JDK and JRE 6 Update 2 and earlier, JDK and JRE 5.0 Update 12
Sun Java Runtime Environment (JRE) in JDK and JRE 6 Update 2 and earlier, JDK and JRE 5.0 Update 12 and earlier, SDK and JRE 1.4.2_15 and earlier, and SDK and JRE 1.3.1_20 and earlier, when applet caching is enabled, allows remote attackers to violate the security model for an applet's outbound connections via a DNS rebinding attack.
nvd
CVE-2010-4468P4MEDIUMCVSS 4.0≤ 1.6.0v1.6.0+2 more2011-02-17
CVE-2010-4468 [MEDIUM] CVE-2010-4468: Unspecified vulnerability in the Java Runtime Environment (JRE) in Oracle Java SE and Java for Busin
Unspecified vulnerability in the Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 23 and earlier, and 5.0 Update 27 and earlier, allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality and integrity via unknown vectors related to JDBC.
nvd
CVE-2013-5797P4LOWCVSS 3.5v1.6.0v1.5.02013-10-16
CVE-2013-5797 [LOW] CVE-2013-5797: Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u
Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, JRockit R28.2.8 and earlier, JRockit R27.7.6 and earlier, and JavaFX 2.2.40 and earlier allows remote authenticated users to affect integrity via unknown vectors related to Javadoc.
nvd
CVE-2008-1194P4MEDIUMCVSS 4.3v1.5.0v1.6.02008-03-06
CVE-2008-1194 [MEDIUM] CVE-2008-1194: Multiple unspecified vulnerabilities in the color management library in Sun JDK and JRE 6 Update 4 a
Multiple unspecified vulnerabilities in the color management library in Sun JDK and JRE 6 Update 4 and earlier, and 5.0 Update 14 and earlier, allows remote attackers to cause a denial of service (crash) via unknown vectors.
nvd
CVE-2006-5201P4MEDIUMCVSS 4.0v1.3.1v1.3.1_2+31 more2006-10-10
CVE-2006-5201 [MEDIUM] CVE-2006-5201: Multiple packages on Sun Solaris, including (1) NSS; (2) Java JDK and JRE 5.0 Update 8 and earlier,
Multiple packages on Sun Solaris, including (1) NSS; (2) Java JDK and JRE 5.0 Update 8 and earlier, SDK and JRE 1.4.x up to 1.4.2_12, and SDK and JRE 1.3.x up to 1.3.1_19; (3) JSSE 1.0.3_03 and earlier; (4) IPSec/IKE; (5) Secure Global Desktop; and (6) StarOffice, when using an RSA key with exponent 3, removes PKCS-1 padding before generating a hash, which all
nvd
CVE-2007-5239P4MEDIUMCVSS 4.0v1.3.0v1.3.1+15 more2007-10-06
CVE-2007-5239 [MEDIUM] CWE-264 CVE-2007-5239: Java Web Start in Sun JDK and JRE 6 Update 2 and earlier, JDK and JRE 5.0 Update 12 and earlier, SDK
Java Web Start in Sun JDK and JRE 6 Update 2 and earlier, JDK and JRE 5.0 Update 12 and earlier, SDK and JRE 1.4.2_15 and earlier, and SDK and JRE 1.3.1_20 and earlier does not properly enforce access restrictions for untrusted (1) applications and (2) applets, which allows user-assisted remote attackers to copy or rename arbitrary files when local us
nvd
CVE-2013-5803P4LOWCVSS 2.6v1.6.0v1.5.02013-10-16
CVE-2013-5803 [LOW] CVE-2013-5803: Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u
Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, JRockit R28.2.8 and earlier, JRockit R27.7.6 and earlier, and Java SE Embedded 7u40 and earlier allows remote attackers to affect availability via vectors related to JGSS.
nvd
CVE-2012-5077P4LOWCVSS 2.6v1.6.0v1.5.0+37 more2012-10-16
CVE-2012-5077 [LOW] CVE-2012-5077: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier, 6 Update 35 and earlier, 5.0 Update 36 and earlier, and 1.4.2_38 and earlier allows remote attackers to affect confidentiality via unknown vectors related to Security.
nvd
CVE-2009-3729P4MEDIUMCVSS 5.0≤ 1.5.0≤ 1.6.0+2 more2009-11-09
CVE-2009-3729 [MEDIUM] CVE-2009-3729: Unspecified vulnerability in the TrueType font parsing functionality in Sun Java SE 5.0 before Updat
Unspecified vulnerability in the TrueType font parsing functionality in Sun Java SE 5.0 before Update 22 and 6 before Update 17 allows remote attackers to cause a denial of service (application crash) via a certain test suite, aka Bug Id 6815780.
nvd
CVE-2009-3885P4MEDIUMCVSS 5.0≤ 1.5.0≤ 1.6.0+4 more2009-11-09
CVE-2009-3885 [MEDIUM] CVE-2009-3885: Sun Java SE 5.0 before Update 22 and 6 before Update 17 on Windows allows remote attackers to cause
Sun Java SE 5.0 before Update 22 and 6 before Update 17 on Windows allows remote attackers to cause a denial of service via a BMP file containing a link to a UNC share pathname for an International Color Consortium (ICC) profile file, probably a related issue to CVE-2007-2789, aka Bug Id 6632445.
nvd
CVE-2006-6009P4MEDIUMCVSS 5.0≤ 1.5.0v1.5.02006-11-21
CVE-2006-6009 [MEDIUM] CVE-2006-6009: Unspecified vulnerability in the Java Runtime Environment (JRE) Swing library in JDK and JRE 5.0 Upd
Unspecified vulnerability in the Java Runtime Environment (JRE) Swing library in JDK and JRE 5.0 Update 7 and earlier allows attackers to obtain certain information via unknown attack vectors, related to an untrusted applet accessing data in other applets.
nvd
CVE-2008-3110P4MEDIUMCVSS 4.3≤ 6v62008-07-09
CVE-2008-3110 [MEDIUM] CWE-264 CVE-2008-3110: Unspecified vulnerability in scripting language support in Sun Java Runtime Environment (JRE) in JDK
Unspecified vulnerability in scripting language support in Sun Java Runtime Environment (JRE) in JDK and JRE 6 Update 6 and earlier allows remote attackers to obtain sensitive information by using an applet to read information from another applet.
nvd
CVE-2006-6737P4MEDIUMCVSS 4.3v1.3.1v1.3.1_2+28 more2006-12-26
CVE-2006-6737 [MEDIUM] CVE-2006-6737: Unspecified vulnerability in Sun Java Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 U
Unspecified vulnerability in Sun Java Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 5 and earlier, Java System Development Kit (SDK) and JRE 1.4.2_10 and earlier 1.4.x versions, and SDK and JRE 1.3.1_18 and earlier allows attackers to use untrusted applets to "access data in other applets," aka "The first issue."
nvd
CVE-2006-6736P4MEDIUMCVSS 4.3v1.3.1v1.3.1_2+30 more2006-12-26
CVE-2006-6736 [MEDIUM] CVE-2006-6736: Unspecified vulnerability in Sun Java Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 U
Unspecified vulnerability in Sun Java Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 6 and earlier, Java System Development Kit (SDK) and JRE 1.4.2_12 and earlier 1.4.x versions, and SDK and JRE 1.3.1_18 and earlier allows attackers to use untrusted applets to "access data in other applets," aka "The second issue."
nvd
CVE-2013-2418P4MEDIUMCVSS 4.6v1.6.02013-04-17
CVE-2013-2418 [MEDIUM] CVE-2013-2418: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier and 6 Update 43 and earlier allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Deployment.
nvd
CVE-2013-5772P4LOWCVSS 2.6v1.6.02013-10-16
CVE-2013-5772 [LOW] CVE-2013-5772: Unspecified vulnerability in the Java SE component in Oracle Java SE Java SE 7u40 and earlier and Ja
Unspecified vulnerability in the Java SE component in Oracle Java SE Java SE 7u40 and earlier and Java SE 6u60 and earlier allows remote attackers to affect integrity via unknown vectors related to jhat.
nvd