Sun Jre vulnerabilities
423 known vulnerabilities affecting sun/jre.
Total CVEs
423
CISA KEV
2
actively exploited
Public exploits
36
Exploited in wild
3
Severity breakdown
CRITICAL162HIGH77MEDIUM162LOW20
Vulnerabilities
Page 9 of 22
CVE-2012-0500CRITICALCVSS 10.0PoCv1.6.02012-02-15
CVE-2012-0500 [CRITICAL] CVE-2012-0500: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, and JavaFX 2.0.2 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality, integrity, and availability via unknown vectors related to Deployment.
nvd
CVE-2012-0504CRITICALCVSS 9.3v1.6.02012-02-15
CVE-2012-0504 [CRITICAL] CVE-2012-0504: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, and 6 Update 30 and earlier, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Install and the Java Update mechanism.
nvd
CVE-2012-0497CRITICALCVSS 10.0v1.6.02012-02-15
CVE-2012-0497 [CRITICAL] CVE-2012-0497: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, and 6 Update 30 and earlier, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D.
nvd
CVE-2012-0498CRITICALCVSS 10.0≤ 1.5.0v1.5.0+1 more2012-02-15
CVE-2012-0498 [CRITICAL] CVE-2012-0498: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, and 5.0 Update 33 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D.
nvd
CVE-2012-0503HIGHCVSS 7.5≤ 1.4.2_35v1.4.2+37 more2012-02-15
CVE-2012-0503 [HIGH] CVE-2012-0503: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, 5.0 Update 33 and earlier, and 1.4.2_35 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality, integrity, and availability, related to I18n.
nvd
CVE-2012-0505HIGHCVSS 7.5≤ 1.4.2_35v1.4.2+37 more2012-02-15
CVE-2012-0505 [HIGH] CVE-2012-0505: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, 5 Update 33 and earlier, and 1.4.2_35 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality, integrity, and availability via unknown vectors related to Seriali
nvd
CVE-2011-3563MEDIUMCVSS 6.4≤ 1.4.2_35v1.4.2+37 more2012-02-15
CVE-2011-3563 [MEDIUM] CVE-2011-3563: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, 5.0 Update 33 and earlier, and 1.4.2_35 and earlier allows remote attackers to affect confidentiality and availability via unknown vectors related to Sound.
nvd
CVE-2012-0502MEDIUMCVSS 6.4≤ 1.4.2_35v1.4.2+37 more2012-02-15
CVE-2012-0502 [MEDIUM] CVE-2012-0502: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, 5.0 Update 33 and earlier, and 1.4.2_35 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality and availability, related to AWT.
nvd
CVE-2012-0506MEDIUMCVSS 4.3≤ 1.4.2_35v1.4.2+37 more2012-02-15
CVE-2012-0506 [MEDIUM] CVE-2012-0506: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, 5.0 Update 33 and earlier, and 1.4.2_35 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect integrity via unknown vectors related to CORBA.
nvd
CVE-2012-0501MEDIUMCVSS 5.0≤ 1.5.0v1.5.0+1 more2012-02-15
CVE-2012-0501 [MEDIUM] CVE-2012-0501: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, and 5.0 Update 33 and earlier allows remote attackers to affect availability via unknown vectors.
nvd
CVE-2011-3551CRITICALCVSS 9.3v1.7.0≤ 1.6.0+1 more2011-10-19
CVE-2011-3551 [CRITICAL] CVE-2011-3551: Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7,
Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7, 6 Update 27 and earlier, and JRockit R28.1.4 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D.
nvd
CVE-2011-3554CRITICALCVSS 10.0≤ 1.6.0v1.6.0+3 more2011-10-19
CVE-2011-3554 [CRITICAL] CVE-2011-3554: Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7,
Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7, 6 Update 27 and earlier, 5.0 Update 31 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality, integrity, and availability via unknown vectors.
nvd
CVE-2011-3545CRITICALCVSS 10.0≤ 1.6.0v1.6.0+36 more2011-10-19
CVE-2011-3545 [CRITICAL] CVE-2011-3545: Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 6
Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 6 Update 27 and earlier, 5.0 Update 31 and earlier, and 1.4.2_33 and earlier, and JRockit R28.1.4 and earlier, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Sound.
nvd
CVE-2011-3549CRITICALCVSS 10.0≤ 1.6.0v1.6.0+36 more2011-10-19
CVE-2011-3549 [CRITICAL] CVE-2011-3549: Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 6
Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 6 Update 27 and earlier, 5.0 Update 31 and earlier, and 1.4.2_33 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality, integrity, and availability via unknown vectors related to Swing.
nvd
CVE-2011-3548CRITICALCVSS 10.0≤ 1.6.0v1.6.0+37 more2011-10-19
CVE-2011-3548 [CRITICAL] CVE-2011-3548: Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7,
Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7, 6 Update 27 and earlier, 5.0 Update 31 and earlier, and 1.4.2_33 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality, integrity, and availability, related to AWT.
nvd
CVE-2011-3521CRITICALCVSS 10.0v1.7.0≤ 1.6.0+3 more2011-10-19
CVE-2011-3521 [CRITICAL] CVE-2011-3521: Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE, 7
Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE, 7, 6 Update 27 and earlier, and 5.0 Update 31 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality, integrity, and availability via unknown vectors related to Deserialization.
nvd
CVE-2011-3516HIGHCVSS 7.6≤ 1.6.0v1.6.02011-10-19
CVE-2011-3516 [HIGH] CVE-2011-3516: Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 6
Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 6 Update 27 and earlier, when running on Windows, allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality, integrity, and availability via unknown vectors related to Deployment.
nvd
CVE-2011-3556HIGHCVSS 7.5PoCv1.7.0≤ 1.6.0+37 more2011-10-19
CVE-2011-3556 [HIGH] CVE-2011-3556: Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7,
Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7, 6 Update 27 and earlier, 5.0 Update 31 and earlier, 1.4.2_33 and earlier, and JRockit R28.1.4 and earlier allows remote attackers to affect confidentiality, integrity, and availability, related to RMI, a different vulnerability than CVE-2011-3557.
nvd
CVE-2011-3550HIGHCVSS 7.6v1.7.0≤ 1.6.0+1 more2011-10-19
CVE-2011-3550 [HIGH] CVE-2011-3550: Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7,
Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7, 6 Update 27 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality, integrity, and availability, related to AWT.
nvd
CVE-2011-3558MEDIUMCVSS 5.0v1.7.0≤ 1.6.0+1 more2011-10-19
CVE-2011-3558 [MEDIUM] CVE-2011-3558: Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7,
Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7, 6 Update 27 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality via unknown vectors related to HotSpot.
nvd