Sun Sdk vulnerabilities
126 known vulnerabilities affecting sun/sdk.
Total CVEs
126
CISA KEV
0
Public exploits
10
Exploited in wild
3
Severity breakdown
CRITICAL50HIGH20MEDIUM51LOW5
Vulnerabilities
Page 1 of 7
CVE-2008-5353P2CRITICALCVSS 10.0ExploitedPoC≤ 1.4.2_18v1.4.2_1+16 more2008-12-05
CVE-2008-5353 [CRITICAL] CVE-2008-5353: The Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Upda
The Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier does not properly enforce context of ZoneInfo objects during deserialization, which allows remote attackers to run untrusted applets and applications in a privileged context, as demonstrated by "deserial
nvd
CVE-2009-3867P2CRITICALCVSS 9.3ExploitedPoCv1.4.2_01v1.4.2_1+63 more2009-11-05
CVE-2009-3867 [CRITICAL] CWE-119 CVE-2009-3867: Stack-based buffer overflow in the HsbParser.getSoundBank function in Sun Java SE in JDK and JRE 5.0
Stack-based buffer overflow in the HsbParser.getSoundBank function in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to execute arbitrary code via a long file: URL in an argument, aka Bug Id 6854303.
nvd
CVE-2010-0842P1HIGHCVSS 7.5ExploitedPoC≤ 1.4.2_25v1.4.2+59 more2010-04-01
CVE-2010-0842 [HIGH] CVE-2010-0842: Unspecified vulnerability in the Sound component in Oracle Java SE and Java for Business 6 Update 18
Unspecified vulnerability in the Sound component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, 1.4.2_25, and 1.3.1_27 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the March 2010 CPU. Oracle has not commented on claims from a reliable res
nvd
CVE-2009-3869P2CRITICALCVSS 9.3PoCv1.4.2_01v1.4.2_1+63 more2009-11-05
CVE-2009-3869 [CRITICAL] CWE-119 CVE-2009-3869: Stack-based buffer overflow in the setDiffICM function in the Abstract Window Toolkit (AWT) in Java
Stack-based buffer overflow in the setDiffICM function in the Abstract Window Toolkit (AWT) in Java Runtime Environment (JRE) in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to execute arbitrary code via a crafted argum
nvd
CVE-2007-5019P3CRITICALCVSS 10.0PoCv1.3.02007-09-20
CVE-2007-5019 [CRITICAL] CWE-119 CVE-2007-5019: Buffer overflow in the Sun Java Web Start ActiveX control in Java Runtime Environment (JRE) 1.6.0_X
Buffer overflow in the Sun Java Web Start ActiveX control in Java Runtime Environment (JRE) 1.6.0_X allows remote attackers to have an unknown impact via a long argument to the dnsResolve (isInstalled.dnsResolve) method.
nvd
CVE-2007-2788P3MEDIUMCVSS 6.8PoCv1.3.1v1.3.1_01+35 more2007-05-22
CVE-2007-2788 [MEDIUM] CWE-189 CVE-2007-2788: Integer overflow in the embedded ICC profile image parser in Sun Java Development Kit (JDK) before 1
Integer overflow in the embedded ICC profile image parser in Sun Java Development Kit (JDK) before 1.5.0_11-b03 and 1.6.x before 1.6.0_01-b06, and Sun Java Runtime Environment in JDK and JRE 6, JDK and JRE 5.0 Update 10 and earlier, SDK and JRE 1.4.2_14 and earlier, and SDK and JRE 1.3.1_20 and earlier, allows remote attackers to execute arbitrary cod
nvd
CVE-2007-4381P3CRITICALCVSS 9.3PoC≤ 1.4.2_142007-08-17
CVE-2007-4381 [CRITICAL] CVE-2007-4381: Unspecified vulnerability in the font parsing implementation in Sun JDK and JRE 5.0 Update 9 and ear
Unspecified vulnerability in the font parsing implementation in Sun JDK and JRE 5.0 Update 9 and earlier, and SDK and JRE 1.4.2_14 and earlier, allows remote attackers to perform unauthorized actions via an applet that grants certain privileges to itself.
nvd
CVE-2010-4476P3MEDIUMCVSS 5.0PoC≤ 1.4.2_29v1.4.2+28 more2011-02-17
CVE-2010-4476 [MEDIUM] CVE-2010-4476: The Double.parseDouble method in Java Runtime Environment (JRE) in Oracle Java SE and Java for Busin
The Double.parseDouble method in Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 23 and earlier, 5.0 Update 27 and earlier, and 1.4.2_29 and earlier, as used in OpenJDK, Apache, JBossweb, and other products, allows remote attackers to cause a denial of service via a crafted string that triggers an infinite loop of estimations d
nvd
CVE-2007-0243P3MEDIUMCVSS 6.8PoCv1.3.1_01v1.3.1_01a+8 more2007-01-17
CVE-2007-0243 [MEDIUM] CWE-119 CVE-2007-0243: Buffer overflow in Sun JDK and Java Runtime Environment (JRE) 5.0 Update 9 and earlier, SDK and JRE
Buffer overflow in Sun JDK and Java Runtime Environment (JRE) 5.0 Update 9 and earlier, SDK and JRE 1.4.2_12 and earlier, and SDK and JRE 1.3.1_18 and earlier allows applets to gain privileges via a GIF image with a block with a 0 width field, which triggers memory corruption.
nvd
CVE-2008-3112P3CRITICALCVSS 10.0v1.4.2v1.4.2_01+16 more2008-07-09
CVE-2008-3112 [CRITICAL] CWE-264 CVE-2008-3112: Directory traversal vulnerability in Sun Java Web Start in JDK and JRE 6 before Update 7, JDK and JR
Directory traversal vulnerability in Sun Java Web Start in JDK and JRE 6 before Update 7, JDK and JRE 5.0 before Update 16, and SDK and JRE 1.4.x before 1.4.2_18 allows remote attackers to create arbitrary files via the writeManifest method in the CacheEntry class, aka CR 6703909.
nvd
CVE-2010-3559P3CRITICALCVSS 10.0≤ 1.4.2_27v1.4.2+62 more2010-10-19
CVE-2010-3559 [CRITICAL] CVE-2010-3559: Unspecified vulnerability in the Sound component in Oracle Java SE and Java for Business 6 Update 21
Unspecified vulnerability in the Sound component in Oracle Java SE and Java for Business 6 Update 21, 5.0 Update 25, 1.4.2_27, and 1.3.1_28 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the October 2010 CPU. Oracle has not commented on claims from a reliab
nvd
CVE-2010-3571P3CRITICALCVSS 10.0≤ 1.4.2_27v1.4.2+62 more2010-10-19
CVE-2010-3571 [CRITICAL] CVE-2010-3571: Unspecified vulnerability in the 2D component in Oracle Java SE and Java for Business 6 Update 21, 5
Unspecified vulnerability in the 2D component in Oracle Java SE and Java for Business 6 Update 21, 5.0 Update 25, 1.4.2_27, and 1.3.1_28 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the October 2010 CPU. Oracle has not commented on claims from a reliable
nvd
CVE-2006-2426P3MEDIUMCVSS 6.4PoCv1.5.0_62006-05-17
CVE-2006-2426 [MEDIUM] CVE-2006-2426: Sun Java Runtime Environment (JRE) 1.5.0_6 and earlier, JDK 1.5.0_6 and earlier, and SDK 1.5.0_6 and
Sun Java Runtime Environment (JRE) 1.5.0_6 and earlier, JDK 1.5.0_6 and earlier, and SDK 1.5.0_6 and earlier allows remote attackers to cause a denial of service (disk consumption) by using the Font.createFont function to create temporary files of arbitrary size in the %temp% directory.
nvd
CVE-2010-3569P3CRITICALCVSS 10.0≤ 1.4.2_27v1.4.2+26 more2010-10-19
CVE-2010-3569 [CRITICAL] CVE-2010-3569: Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for B
Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 21, 5.0 Update 25, and 1.4.2_27 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the October 2010 CPU. Oracle has not commented on claims from
nvd
CVE-2010-3562P3CRITICALCVSS 10.0≤ 1.4.2_27v1.4.2+62 more2010-10-19
CVE-2010-3562 [CRITICAL] CVE-2010-3562: Unspecified vulnerability in the 2D component in Oracle Java SE and Java for Business 6 Update 21, 5
Unspecified vulnerability in the 2D component in Oracle Java SE and Java for Business 6 Update 21, 5.0 Update 25, 1.4.2_27, and 1.3.1_28 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the October 2010 CPU. Oracle has not commented on claims from a reliable
nvd
CVE-2010-4454P3CRITICALCVSS 10.0≤ 1.4.2_29v1.4.2+28 more2011-02-17
CVE-2010-4454 [CRITICAL] CVE-2010-4454: Unspecified vulnerability in the Java Runtime Environment (JRE) in Oracle Java SE and Java for Busin
Unspecified vulnerability in the Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 23 and earlier, 5.0 Update 27 and earlier, and 1.4.2_29 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Sound and unspecified APIs, a different vulnerability than CVE-2010-
nvd
CVE-2010-4462P3CRITICALCVSS 10.0≤ 1.4.2_29v1.4.2+28 more2011-02-17
CVE-2010-4462 [CRITICAL] CVE-2010-4462: Unspecified vulnerability in the Java Runtime Environment (JRE) in Oracle Java SE and Java for Busin
Unspecified vulnerability in the Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 23 and earlier, 5.0 Update 27 and earlier, and 1.4.2_29 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Sound and unspecified APIs, a different vulnerability than CVE-2010-
nvd
CVE-2010-4473P3CRITICALCVSS 10.0≤ 1.4.2_29v1.4.2+28 more2011-02-17
CVE-2010-4473 [CRITICAL] CVE-2010-4473: Unspecified vulnerability in the Java Runtime Environment (JRE) in Oracle Java SE and Java for Busin
Unspecified vulnerability in the Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 23 and earlier, 5.0 Update 27 and earlier, and 1.4.2_29 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Sound and unspecified APIs, a different vulnerability than CVE-2010-
nvd
CVE-2008-5359P3CRITICALCVSS 9.3v1.3.1v1.3.1_01+47 more2008-12-05
CVE-2008-5359 [CRITICAL] CWE-119 CVE-2008-5359: Buffer overflow in Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK a
Buffer overflow in Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; SDK and JRE 1.4.2_18 and earlier; and SDK and JRE 1.3.1_23 and earlier might allow remote attackers to execute arbitrary code, related to a ConvolveOp operation in the Java AWT library.
nvd
CVE-2010-3574P3CRITICALCVSS 10.0≤ 1.4.2_27v1.4.2+62 more2010-10-19
CVE-2010-3574 [CRITICAL] CVE-2010-3574: Unspecified vulnerability in the Networking component in Oracle Java SE and Java for Business 6 Upda
Unspecified vulnerability in the Networking component in Oracle Java SE and Java for Business 6 Update 21, 5.0 Update 25, 1.4.2_27, and 1.3.1_28 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the October 2010 CPU. Oracle has not commented on claims from a r
nvd
1 / 7Next →