Sun Jre vulnerabilities
423 known vulnerabilities affecting sun/jre.
Total CVEs
423
CISA KEV
2
actively exploited
Public exploits
36
Exploited in wild
13
Severity breakdown
CRITICAL162HIGH77MEDIUM162LOW20
Vulnerabilities
Page 21 of 22
CVE-2012-3216P4LOWCVSS 2.6v1.6.0v1.5.0+37 more2012-10-16
CVE-2012-3216 [LOW] CVE-2012-3216: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier, 6 Update 35 and earlier, 5.0 Update 36 and earlier, and 1.4.2_38 and earlier allows remote attackers to affect confidentiality via unknown vectors related to Libraries.
nvd
CVE-2011-3553P4LOWCVSS 3.5v1.7.0≤ 1.6.0+1 more2011-10-19
CVE-2011-3553 [LOW] CVE-2011-3553: Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7,
Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7, 6 Update 27 and earlier, and JRockit R28.1.4 and earlier allows remote authenticated users to affect confidentiality, related to JAXWS.
nvd
CVE-2004-0651P4MEDIUMCVSS 5.0v1.4.2v1.4.2_32004-08-06
CVE-2004-0651 [MEDIUM] CVE-2004-0651: Unknown vulnerability in Sun Java Runtime Environment (JRE) 1.4.2 through 1.4.2_03 allows remote att
Unknown vulnerability in Sun Java Runtime Environment (JRE) 1.4.2 through 1.4.2_03 allows remote attackers to cause a denial of service (virtual machine hang).
nvd
CVE-2004-1503P4MEDIUMCVSS 5.0v1.4.2v1.5.02004-12-31
CVE-2004-1503 [MEDIUM] CVE-2004-1503: Integer overflow in the InitialDirContext in Java Runtime Environment (JRE) 1.4.2, 1.5.0 and possibl
Integer overflow in the InitialDirContext in Java Runtime Environment (JRE) 1.4.2, 1.5.0 and possibly other versions allows remote attackers to cause a denial of service (Java exception and failed DNS requests) via a large number of DNS requests, which causes the xid variable to wrap around and become negative.
nvd
CVE-2011-3552P4LOWCVSS 2.6≤ 1.6.0v1.6.0+37 more2011-10-19
CVE-2011-3552 [LOW] CVE-2011-3552: Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7,
Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7, 6 Update 27 and earlier, 5.0 Update 31 and earlier, and 1.4.2_33 and earlier allows remote attackers to affect integrity via unknown vectors related to Networking.
nvd
CVE-2004-2540P4MEDIUMCVSS 5.0v1.4v1.4.0_01+8 more2004-12-31
CVE-2004-2540 [MEDIUM] CVE-2004-2540: readObject in (1) Java Runtime Environment (JRE) and (2) Software Development Kit (SDK) 1.4.0 throug
readObject in (1) Java Runtime Environment (JRE) and (2) Software Development Kit (SDK) 1.4.0 through 1.4.2_05 allows remote attackers to cause a denial of service (JVM unresponsive) via crafted serialized data.
nvd
CVE-2010-4472P4LOWCVSS 2.6≤ 1.6.0v1.6.02011-02-17
CVE-2010-4472 [LOW] CVE-2010-4472: Unspecified vulnerability in the Java Runtime Environment (JRE) in Oracle Java SE and Java for Busin
Unspecified vulnerability in the Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 23 and earlier allows remote attackers to affect availability, related to XML Digital Signature and unspecified APIs. NOTE: the previous information was obtained from the February 2011 CPU. Oracle has not commented on claims from a downstream vendor t
nvd
CVE-2010-3560P4LOWCVSS 2.6≤ 1.6.0v1.6.02010-10-19
CVE-2010-3560 [LOW] CVE-2010-3560: Unspecified vulnerability in the Networking component in Oracle Java SE and Java for Business 6 Upda
Unspecified vulnerability in the Networking component in Oracle Java SE and Java for Business 6 Update 21 allows remote attackers to affect confidentiality via unknown vectors.
nvd
CVE-2012-5085P4UNKNOWNCVSS 0.0v1.6.0v1.5.0+37 more2012-10-16
CVE-2012-5085 [NONE] CVE-2012-5085: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier, 6 Update 35 and earlier, 5.0 Update 36 and earlier, and 1.4.2_38 and earlier allows remote authenticated users to have an unspecified impact via unknown vectors related to Networking. NOTE: the Oracle CPU states that this issue has a 0.0 CVSS scor
nvd
CVE-2007-5273P4LOWCVSS 2.6v1.3.0v1.3.1+15 more2007-10-08
CVE-2007-5273 [LOW] CVE-2007-5273: Sun Java Runtime Environment (JRE) in JDK and JRE 6 Update 2 and earlier, JDK and JRE 5.0 Update 12
Sun Java Runtime Environment (JRE) in JDK and JRE 6 Update 2 and earlier, JDK and JRE 5.0 Update 12 and earlier, SDK and JRE 1.4.2_15 and earlier, and SDK and JRE 1.3.1_20 and earlier, when an HTTP proxy server is used, allows remote attackers to violate the security model for an applet's outbound connections via a multi-pin DNS rebinding attack in which the appl
nvd
CVE-2011-0865P4LOWCVSS 2.6≤ 1.4.2_31v1.4.2+34 more2011-06-14
CVE-2011-0865 [LOW] CVE-2011-0865: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 6 Update
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 6 Update 25 and earlier, 5.0 Update 29 and earlier, and 1.4.2_31 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect integrity via unknown vectors related to Deserialization.
nvd
CVE-2011-3561P4LOWCVSS 1.8v1.7.0v1.6.02011-10-19
CVE-2011-3561 [LOW] CVE-2011-3561: Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7,
Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7, 6 Update 27 and earlier, and JavaFX 2.0 allows remote attackers to affect confidentiality via unknown vectors related to Deployment.
nvd
CVE-2013-2451P4LOWCVSS 3.7v1.6.02013-06-18
CVE-2013-2451 [LOW] CVE-2013-2451: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier and 6 Update 45 and earlier, and OpenJDK 7, allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Networking. NOTE: the previous information is from the June 2013 CPU. Oracle has not commented on c
nvd
CVE-2012-1720P4LOWCVSS 3.7≤ 1.5.0≤ 1.4.2_372012-06-16
CVE-2012-1720 [LOW] CVE-2012-1720: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update 4 and earlier, 6 update 32 and earlier, 5 update 35 and earlier, and 1.4.2_37 and earlier, when running on Solaris, allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Networking.
nvd
CVE-2003-1301P4MEDIUMCVSS 5.0v1.4.2v1.4.2_1+10 more2003-12-31
CVE-2003-1301 [MEDIUM] CVE-2003-1301: Sun Java Runtime Environment (JRE) 1.x before 1.4.2_11 and 1.5.x before 1.5.0_06, and as used in mul
Sun Java Runtime Environment (JRE) 1.x before 1.4.2_11 and 1.5.x before 1.5.0_06, and as used in multiple web browsers, allows remote attackers to cause a denial of service (application crash) via deeply nested object arrays, which are not properly handled by the garbage collector and trigger invalid memory accesses.
nvd
CVE-2010-4448P4LOWCVSS 2.6≤ 1.6.0v1.6.0+32 more2011-02-17
CVE-2010-4448 [LOW] CVE-2010-4448: Unspecified vulnerability in the Java Runtime Environment (JRE) in Oracle Java SE and Java for Busin
Unspecified vulnerability in the Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 23 and earlier, 5.0 Update 27 and earlier, and 1.4.2_29 earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect integrity via unknown vectors related to Networking. NOTE: the previous information was obtained f
nvd
CVE-2003-1156P4MEDIUMCVSS 4.6v1.4.22003-12-31
CVE-2003-1156 [MEDIUM] CVE-2003-1156: Java Runtime Environment (JRE) and Software Development Kit (SDK) 1.4.2 through 1.4.2_02 allows loca
Java Runtime Environment (JRE) and Software Development Kit (SDK) 1.4.2 through 1.4.2_02 allows local users to overwrite arbitrary files via a symlink attack on (1) unpack.log, as created by the unpack program, or (2) .mailcap1 and .mime.types1, as created by the RPM program.
nvd
CVE-2010-4450P4LOWCVSS 3.7≤ 1.6.0v1.6.0+32 more2011-02-17
CVE-2010-4450 [LOW] CVE-2010-4450: Unspecified vulnerability in the Java Runtime Environment (JRE) in Oracle Java SE and Java for Busin
Unspecified vulnerability in the Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 23 and earlier for Solaris and Linux; 5.0 Update 27 and earlier for Solaris and Linux; and 1.4.2_29 and earlier for Solaris and Linux allows local standalone applications to affect confidentiality, integrity, and availability via unknown vectors relat
nvd
CVE-2007-5238P4LOWCVSS 2.6v1.3.0v1.3.1+15 more2007-10-06
CVE-2007-5238 [LOW] CWE-264 CVE-2007-5238: Java Web Start in Sun JDK and JRE 6 Update 2 and earlier, JDK and JRE 5.0 Update 12 and earlier, and
Java Web Start in Sun JDK and JRE 6 Update 2 and earlier, JDK and JRE 5.0 Update 12 and earlier, and SDK and JRE 1.4.2_15 and earlier does not properly enforce access restrictions for untrusted applications, which allows user-assisted remote attackers to obtain sensitive information (the Java Web Start cache location) via an untrusted application, aka "t
nvd
CVE-2013-1500P4LOWCVSS 3.6v1.6.0v1.5.02013-06-18
CVE-2013-1500 [LOW] CVE-2013-1500: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier, and OpenJDK 7, allows local users to affect confidentiality and integrity via unknown vectors related to 2D. NOTE: the previous information is from the June 2013 CPU. Oracle has not commented
nvd