Sun Sdk vulnerabilities
126 known vulnerabilities affecting sun/sdk.
Total CVEs
126
CISA KEV
0
Public exploits
10
Exploited in wild
3
Severity breakdown
CRITICAL50HIGH20MEDIUM51LOW5
Vulnerabilities
Page 2 of 7
CVE-2008-1190P3CRITICALCVSS 9.3v1.4.2v1.4.2_1+15 more2008-03-06
CVE-2008-1190 [CRITICAL] CWE-264 CVE-2008-1190: Unspecified vulnerability in Java Web Start in Sun JDK and JRE 6 Update 4 and earlier, 5.0 Update 14
Unspecified vulnerability in Java Web Start in Sun JDK and JRE 6 Update 4 and earlier, 5.0 Update 14 and earlier, and SDK/JRE 1.4.2_16 and earlier allows remote attackers to gain privileges via an untrusted application, a different issue than CVE-2008-1191, aka the "fourth" issue.
nvd
CVE-2009-3871P3CRITICALCVSS 9.3v1.4.2_01v1.4.2_1+63 more2009-11-05
CVE-2009-3871 [CRITICAL] CWE-119 CVE-2009-3871: Heap-based buffer overflow in the setBytePixels function in the Abstract Window Toolkit (AWT) in Jav
Heap-based buffer overflow in the setBytePixels function in the Abstract Window Toolkit (AWT) in Java Runtime Environment (JRE) in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to execute arbitrary code via crafted argu
nvd
CVE-2009-1098P3CRITICALCVSS 9.3≤ 1.3.1_24v1.3.1+47 more2009-03-25
CVE-2009-1098 [CRITICAL] CWE-119 CVE-2009-1098: Buffer overflow in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 17 an
Buffer overflow in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 17 and earlier; 6 Update 12 and earlier; 1.4.2_19 and earlier; and 1.3.1_24 and earlier allows remote attackers to access files or execute arbitrary code via a crafted GIF image, aka CR 6804998.
nvd
CVE-2008-5355P3CRITICALCVSS 10.0≤ 1.4.2_18v1.4.2_1+16 more2008-12-05
CVE-2008-5355 [CRITICAL] CWE-287 CVE-2008-5355: The "Java Update" feature for Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and ear
The "Java Update" feature for Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier does not verify the signature of the JRE that is downloaded, which allows remote attackers to execute arbitrary code via DNS man-in-the-middle attacks.
nvd
CVE-2010-3556P3CRITICALCVSS 10.0≤ 1.4.2_27v1.4.2+62 more2010-10-19
CVE-2010-3556 [CRITICAL] CVE-2010-3556: Unspecified vulnerability in the 2D component in Oracle Java SE and Java for Business 6 Update 21, 5
Unspecified vulnerability in the 2D component in Oracle Java SE and Java for Business 6 Update 21, 5.0 Update 25, 1.4.2_27, and 1.3.1_28 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.
nvd
CVE-2010-3572P3CRITICALCVSS 10.0≤ 1.4.2_27v1.4.2+62 more2010-10-19
CVE-2010-3572 [CRITICAL] CVE-2010-3572: Unspecified vulnerability in the Sound component in Oracle Java SE and Java for Business 6 Update 21
Unspecified vulnerability in the Sound component in Oracle Java SE and Java for Business 6 Update 21, 5.0 Update 25, 1.4.2_27, and 1.3.1_28 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.
nvd
CVE-2010-3554P3CRITICALCVSS 10.0≤ 1.4.2_27v1.4.2+62 more2010-10-19
CVE-2010-3554 [CRITICAL] CVE-2010-3554: Unspecified vulnerability in the CORBA component in Oracle Java SE and Java for Business 6 Update 21
Unspecified vulnerability in the CORBA component in Oracle Java SE and Java for Business 6 Update 21, 5.0 Update 25, 1.4.2_27, and 1.3.1_28 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the October 2010 CPU. Oracle has not commented on claims from a reliab
nvd
CVE-2009-1094P3CRITICALCVSS 10.0≤ 1.3.1_24v1.3.1+47 more2009-03-25
CVE-2009-1094 [CRITICAL] CVE-2009-1094: Unspecified vulnerability in the LDAP implementation in Java SE Development Kit (JDK) and Java Runti
Unspecified vulnerability in the LDAP implementation in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 17 and earlier; 6 Update 12 and earlier; SDK and JRE 1.3.1_24 and earlier; and 1.4.2_19 and earlier allows remote LDAP servers to execute arbitrary code via unknown vectors related to serialized data.
nvd
CVE-2009-3874P3CRITICALCVSS 9.3v1.4.2_01v1.4.2_1+63 more2009-11-05
CVE-2009-3874 [CRITICAL] CWE-189 CVE-2009-3874: Integer overflow in the JPEGImageReader implementation in the ImageI/O component in Sun Java SE in J
Integer overflow in the JPEGImageReader implementation in the ImageI/O component in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to execute arbitrary code via large subsample dimensions in a JPEG file that triggers a heap-based buffer overflow, aka Bug
nvd
CVE-2010-3553P3CRITICALCVSS 10.0≤ 1.4.2_27v1.4.2+62 more2010-10-19
CVE-2010-3553 [CRITICAL] CVE-2010-3553: Unspecified vulnerability in the Swing component in Oracle Java SE and Java for Business 6 Update 21
Unspecified vulnerability in the Swing component in Oracle Java SE and Java for Business 6 Update 21, 5.0 Update 25, 1.4.2_27, and 1.3.1_28 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the October 2010 CPU. Oracle has not commented on claims from a reliab
nvd
CVE-2007-5689P3CRITICALCVSS 10.0≤ 1.4.2_15v1.3.1_01+14 more2007-10-29
CVE-2007-5689 [CRITICAL] CVE-2007-5689: The Java Virtual Machine (JVM) in Sun Java Runtime Environment (JRE) in SDK and JRE 1.3.x through 1.
The Java Virtual Machine (JVM) in Sun Java Runtime Environment (JRE) in SDK and JRE 1.3.x through 1.3.1_20 and 1.4.x through 1.4.2_15, and JDK and JRE 5.x through 5.0 Update 12 and 6.x through 6 Update 2, allows remote attackers to execute arbitrary programs, or read or modify arbitrary files, via applets that grant privileges to themselves.
nvd
CVE-2010-0841P3HIGHCVSS 7.5≤ 1.4.2_25v1.4.2+24 more2010-04-01
CVE-2010-0841 [HIGH] CVE-2010-0841: Unspecified vulnerability in the ImageIO component in Oracle Java SE and Java for Business 6 Update
Unspecified vulnerability in the ImageIO component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, and 1.4.2_25 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the March 2010 CPU. Oracle has not commented on claims from a reliable researcher t
nvd
CVE-2010-3568P3CRITICALCVSS 10.0≤ 1.4.2_27v1.4.2+26 more2010-10-19
CVE-2010-3568 [CRITICAL] CVE-2010-3568: Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for B
Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 21, 5.0 Update 25, and 1.4.2_27 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the October 2010 CPU. Oracle has not commented on claims from
nvd
CVE-2010-4465P3CRITICALCVSS 10.0≤ 1.4.2_29v1.4.2+28 more2011-02-17
CVE-2010-4465 [CRITICAL] CVE-2010-4465: Unspecified vulnerability in the Java Runtime Environment (JRE) in Oracle Java SE and Java for Busin
Unspecified vulnerability in the Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 23 and earlier, 5.0 Update 27 and earlier, and 1.4.2_29 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality, integrity, and availability via unknown vectors related to Swing. NOTE:
nvd
CVE-2010-0849P3HIGHCVSS 7.5≤ 1.4.2_25v1.4.2+59 more2010-04-01
CVE-2010-0849 [HIGH] CVE-2010-0849: Unspecified vulnerability in the Java 2D component in Oracle Java SE and Java for Business 6 Update
Unspecified vulnerability in the Java 2D component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, 1.4.2_25, and 1.3.1_27 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the March 2010 CPU. Oracle has not commented on claims from a reliable re
nvd
CVE-2010-0846P3HIGHCVSS 7.5≤ 1.4.2_25v1.4.2+59 more2010-04-01
CVE-2010-0846 [HIGH] CVE-2010-0846: Unspecified vulnerability in the ImageIO component in Oracle Java SE and Java for Business 6 Update
Unspecified vulnerability in the ImageIO component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, 1.4.2_25, and 1.3.1_27 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the March 2010 CPU. Oracle has not commented on claims from a reliable re
nvd
CVE-2008-3113P3CRITICALCVSS 10.0v1.4.2v1.4.2_01+16 more2008-07-09
CVE-2008-3113 [CRITICAL] CWE-264 CVE-2008-3113: Unspecified vulnerability in Sun Java Web Start in JDK and JRE 5.0 before Update 16 and SDK and JRE
Unspecified vulnerability in Sun Java Web Start in JDK and JRE 5.0 before Update 16 and SDK and JRE 1.4.x before 1.4.2_18 allows remote attackers to create or delete arbitrary files via an untrusted application, aka CR 6704077.
nvd
CVE-2010-3565P3CRITICALCVSS 10.0≤ 1.4.2_27v1.4.2+26 more2010-10-19
CVE-2010-3565 [CRITICAL] CVE-2010-3565: Unspecified vulnerability in the 2D component in Oracle Java SE and Java for Business 6 Update 21, 5
Unspecified vulnerability in the 2D component in Oracle Java SE and Java for Business 6 Update 21, 5.0 Update 25, and 1.4.2_27 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the October 2010 CPU. Oracle has not commented on claims from a reliable researcher
nvd
CVE-2008-2086P3CRITICALCVSS 9.3≤ 1.4.2_18v1.4.2_1+16 more2008-12-05
CVE-2008-2086 [CRITICAL] CWE-94 CVE-2008-2086: Sun Java Web Start and Java Plug-in for JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update
Sun Java Web Start and Java Plug-in for JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier allow remote attackers to execute arbitrary code via a crafted jnlp file that modifies the (1) java.home, (2) java.ext.dirs, or (3) user.home System Properties, aka "Java Web Start File Inclusion" and
nvd
CVE-2010-0843P3HIGHCVSS 7.5v1.3.1_27v1.4.2_252010-04-01
CVE-2010-0843 [HIGH] CVE-2010-0843: Unspecified vulnerability in the Sound component in Oracle Java SE and Java for Business 6 Update 18
Unspecified vulnerability in the Sound component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, 1.4.2_25, and 1.3.1_27 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the March 2010 CPU. Oracle has not commented on claims from a reliable res
nvd