cbcvebase.

Sun Jre vulnerabilities

423 known vulnerabilities affecting sun/jre.

Total CVEs
423
CISA KEV
2
actively exploited
Public exploits
36
Exploited in wild
13
Severity breakdown
CRITICAL162HIGH77MEDIUM162LOW20

Vulnerabilities

Page 9 of 22
CVE-2013-0419P3HIGHCVSS 7.6v1.6.02013-02-02
CVE-2013-0419 [HIGH] CVE-2013-0419: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 throug Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11 and 6 through Update 38 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment, a different vulnerability than other CVEs listed in the February 2013 CPU.
nvd
CVE-2013-0423P3HIGHCVSS 7.6v1.6.02013-02-02
CVE-2013-0423 [HIGH] CVE-2013-0423: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 throug Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11 and 6 through Update 38 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment, a different vulnerability than other CVEs listed in the February 2013 CPU.
nvd
CVE-2013-0429P3HIGHCVSS 7.6v1.6.0v1.5.02013-02-02
CVE-2013-0429 [HIGH] CVE-2013-0429: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 throug Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, and 5.0 through Update 38, and OpenJDK 6 and 7, allows remote attackers to affect confidentiality, integrity, and availability via vectors related to CORBA. NOTE: the previous information is from the February 2013 CPU. Oracle has
nvd
CVE-2010-0843P3HIGHCVSS 7.5v1.3.1_27v1.4.2_25+2 more2010-04-01
CVE-2010-0843 [HIGH] CVE-2010-0843: Unspecified vulnerability in the Sound component in Oracle Java SE and Java for Business 6 Update 18 Unspecified vulnerability in the Sound component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, 1.4.2_25, and 1.3.1_27 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the March 2010 CPU. Oracle has not commented on claims from a reliable res
nvd
CVE-2008-5358P3CRITICALCVSS 9.3≤ 6v62008-12-05
CVE-2008-5358 [CRITICAL] CWE-119 CVE-2008-5358: Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier might allow remote attack Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier might allow remote attackers to execute arbitrary code via a crafted GIF file that triggers memory corruption during display of the splash screen, possibly related to splashscreen.dll.
nvd
CVE-2010-0847P3HIGHCVSS 7.5≤ 1.6.0v1.6.0+56 more2010-04-01
CVE-2010-0847 [HIGH] CVE-2010-0847: Unspecified vulnerability in the Java 2D component in Oracle Java SE and Java for Business 6 Update Unspecified vulnerability in the Java 2D component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, 1.4.2_25, and 1.3.1_27 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the March 2010 CPU. Oracle has not commented on claims from a reliable re
nvd
CVE-2008-1195P3CRITICALCVSS 9.3v1.4.2v1.4.2_1+17 more2008-03-06
CVE-2008-1195 [CRITICAL] CWE-254 CVE-2008-1195: Unspecified vulnerability in Sun JDK and Java Runtime Environment (JRE) 6 Update 4 and earlier and 5 Unspecified vulnerability in Sun JDK and Java Runtime Environment (JRE) 6 Update 4 and earlier and 5.0 Update 14 and earlier; and SDK and JRE 1.4.2_16 and earlier; allows remote attackers to access arbitrary network services on the local host via unspecified vectors related to JavaScript and Java APIs.
nvd
CVE-2008-5354P3CRITICALCVSS 9.3≤ 1.4.2_18≤ 5.0+20 more2008-12-05
CVE-2008-5354 [CRITICAL] CWE-119 CVE-2008-5354: Stack-based buffer overflow in Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and ea Stack-based buffer overflow in Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier allows locally-launched and possibly remote untrusted Java applications to execute arbitrary code via a JAR file with a long Main-Class manifest entry.
nvd
CVE-2011-0864P3CRITICALCVSS 10.0≤ 1.4.2_31v1.4.2+34 more2011-06-14
CVE-2011-0864 [CRITICAL] CVE-2011-0864: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 6 Update Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 6 Update 25 and earlier, 5.0 Update 29 and earlier, and 1.4.2_31 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality, integrity, and availability via unknown vectors related to HotSpot.
nvd
CVE-2008-5343P3CRITICALCVSS 9.0≤ 1.4.2_18≤ 5.0+20 more2008-12-05
CVE-2008-5343 [CRITICAL] CVE-2008-5343: Java Web Start (JWS) and Java Plug-in with Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Java Web Start (JWS) and Java Plug-in with Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier allows remote attackers to make unauthorized network connections and hijack HTTP sessions via a crafted file that validates as both a GIF and a Java JAR file, aka "GIFAR" and CR 6707535.
nvd
CVE-2008-5357P3CRITICALCVSS 9.3v1.3.1v1.3.1_2+42 more2008-12-05
CVE-2008-5357 [CRITICAL] CWE-189 CVE-2008-5357: Integer overflow in Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK Integer overflow in Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; SDK and JRE 1.4.2_18 and earlier; and SDK and JRE 1.3.1_23 and earlier might allow remote attackers to execute arbitrary code via a crafted TrueType font file, which triggers a heap-based buffer overflow.
nvd
CVE-2013-2430P3HIGHCVSS 7.6v1.6.0v1.5.02013-04-17
CVE-2013-2430 [HIGH] CVE-2013-2430: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, 6 Update 43 and earlier, and 5.0 Update 41 and earlier; JavaFX 2.2.7 and earlier; and OpenJDK 6 and 7 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to ImageIO. NOTE: the previous inform
nvd
CVE-2013-2448P3HIGHCVSS 7.6v1.6.0v1.5.02013-06-18
CVE-2013-2448 [HIGH] CVE-2013-2448: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier, and OpenJDK 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Sound. NOTE: the previous information is from the June 2013 CPU.
nvd
CVE-2007-3504P3CRITICALCVSS 9.3≤ 1.4.2≤ 1.5.02007-06-30
CVE-2007-3504 [CRITICAL] CWE-22 CVE-2007-3504: Directory traversal vulnerability in the PersistenceService in Sun Java Web Start in JDK and JRE 5.0 Directory traversal vulnerability in the PersistenceService in Sun Java Web Start in JDK and JRE 5.0 Update 11 and earlier, and Java Web Start in SDK and JRE 1.4.2_13 and earlier, for Windows allows remote attackers to perform unauthorized actions via an application that grants file overwrite privileges to itself. NOTE: this can be leveraged to execu
nvd
CVE-2008-3108P3CRITICALCVSS 10.0v1.3.1v1.3.1_2+41 more2008-07-09
CVE-2008-3108 [CRITICAL] CWE-119 CVE-2008-3108: Buffer overflow in Sun Java Runtime Environment (JRE) in JDK and JRE 5.0 before Update 10, SDK and J Buffer overflow in Sun Java Runtime Environment (JRE) in JDK and JRE 5.0 before Update 10, SDK and JRE 1.4.x before 1.4.2_18, and SDK and JRE 1.3.x before 1.3.1_23 allows context-dependent attackers to gain privileges via unspecified vectors related to font processing.
nvd
CVE-2008-5340P3CRITICALCVSS 10.0≤ 1.4.2_18≤ 5.0+20 more2008-12-05
CVE-2008-5340 [CRITICAL] CWE-264 CVE-2008-5340: Unspecified vulnerability in Java Web Start (JWS) and Java Plug-in with Sun JDK and JRE 6 Update 10 Unspecified vulnerability in Java Web Start (JWS) and Java Plug-in with Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier allows untrusted JWS applications to gain privileges to access local files or applications via unknown vectors, aka 6727081.
nvd
CVE-2008-3107P3CRITICALCVSS 10.0≤ 1.4.2_17≤ 5.0+21 more2008-07-09
CVE-2008-3107 [CRITICAL] CWE-264 CVE-2008-3107: Unspecified vulnerability in the Virtual Machine in Sun Java Runtime Environment (JRE) in JDK and JR Unspecified vulnerability in the Virtual Machine in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 7, JDK and JRE 5.0 before Update 16, and SDK and JRE 1.4.x before 1.4.2_18 allows context-dependent attackers to gain privileges via an untrusted (1) application or (2) applet, as demonstrated by an application or applet that grants
nvd
CVE-2010-4422P3HIGHCVSS 7.6≤ 1.6.0v1.6.02011-02-17
CVE-2010-4422 [HIGH] CVE-2010-4422: Unspecified vulnerability in the Java Runtime Environment (JRE) in Oracle Java SE and Java for Busin Unspecified vulnerability in the Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 23 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment.
nvd
CVE-2011-0863P3CRITICALCVSS 10.0≤ 1.6.0v1.6.02011-06-14
CVE-2011-0863 [CRITICAL] CVE-2011-0863: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 6 Update Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 6 Update 25 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality, integrity, and availability via unknown vectors related to Deployment.
nvd
CVE-2010-4469P3CRITICALCVSS 10.0≤ 1.6.0v1.6.0+32 more2011-02-17
CVE-2010-4469 [CRITICAL] CVE-2010-4469: Unspecified vulnerability in the Java Runtime Environment (JRE) in Oracle Java SE and Java for Busin Unspecified vulnerability in the Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 23 and earlier, 5.0 Update 27 and earlier, and 1.4.2_29 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality, integrity, and availability via unknown vectors related to HotSpot. NOTE
nvd