Sun Sdk vulnerabilities
126 known vulnerabilities affecting sun/sdk.
Total CVEs
126
CISA KEV
0
Public exploits
10
Exploited in wild
3
Severity breakdown
CRITICAL50HIGH20MEDIUM51LOW5
Vulnerabilities
Page 3 of 7
CVE-2010-0847P3HIGHCVSS 7.5≤ 1.4.2_25v1.4.2+59 more2010-04-01
CVE-2010-0847 [HIGH] CVE-2010-0847: Unspecified vulnerability in the Java 2D component in Oracle Java SE and Java for Business 6 Update
Unspecified vulnerability in the Java 2D component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, 1.4.2_25, and 1.3.1_27 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the March 2010 CPU. Oracle has not commented on claims from a reliable re
nvd
CVE-2008-1195P3CRITICALCVSS 9.3v1.4.2v1.4.2_1+15 more2008-03-06
CVE-2008-1195 [CRITICAL] CWE-254 CVE-2008-1195: Unspecified vulnerability in Sun JDK and Java Runtime Environment (JRE) 6 Update 4 and earlier and 5
Unspecified vulnerability in Sun JDK and Java Runtime Environment (JRE) 6 Update 4 and earlier and 5.0 Update 14 and earlier; and SDK and JRE 1.4.2_16 and earlier; allows remote attackers to access arbitrary network services on the local host via unspecified vectors related to JavaScript and Java APIs.
nvd
CVE-2008-5354P3CRITICALCVSS 9.3≤ 1.4.2_18v1.4.2_1+16 more2008-12-05
CVE-2008-5354 [CRITICAL] CWE-119 CVE-2008-5354: Stack-based buffer overflow in Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and ea
Stack-based buffer overflow in Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier allows locally-launched and possibly remote untrusted Java applications to execute arbitrary code via a JAR file with a long Main-Class manifest entry.
nvd
CVE-2008-5343P3CRITICALCVSS 9.0≤ 1.4.2_18v1.4.2_1+16 more2008-12-05
CVE-2008-5343 [CRITICAL] CVE-2008-5343: Java Web Start (JWS) and Java Plug-in with Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0
Java Web Start (JWS) and Java Plug-in with Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier allows remote attackers to make unauthorized network connections and hijack HTTP sessions via a crafted file that validates as both a GIF and a Java JAR file, aka "GIFAR" and CR 6707535.
nvd
CVE-2008-5357P3CRITICALCVSS 9.3v1.3.1v1.3.1_01+47 more2008-12-05
CVE-2008-5357 [CRITICAL] CWE-189 CVE-2008-5357: Integer overflow in Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK
Integer overflow in Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; SDK and JRE 1.4.2_18 and earlier; and SDK and JRE 1.3.1_23 and earlier might allow remote attackers to execute arbitrary code via a crafted TrueType font file, which triggers a heap-based buffer overflow.
nvd
CVE-2007-3504P3CRITICALCVSS 9.3≤ 1.4.2_132007-06-30
CVE-2007-3504 [CRITICAL] CWE-22 CVE-2007-3504: Directory traversal vulnerability in the PersistenceService in Sun Java Web Start in JDK and JRE 5.0
Directory traversal vulnerability in the PersistenceService in Sun Java Web Start in JDK and JRE 5.0 Update 11 and earlier, and Java Web Start in SDK and JRE 1.4.2_13 and earlier, for Windows allows remote attackers to perform unauthorized actions via an application that grants file overwrite privileges to itself. NOTE: this can be leveraged to execu
nvd
CVE-2008-3108P3CRITICALCVSS 10.0v1.3.1v1.3.1_01+47 more2008-07-09
CVE-2008-3108 [CRITICAL] CWE-119 CVE-2008-3108: Buffer overflow in Sun Java Runtime Environment (JRE) in JDK and JRE 5.0 before Update 10, SDK and J
Buffer overflow in Sun Java Runtime Environment (JRE) in JDK and JRE 5.0 before Update 10, SDK and JRE 1.4.x before 1.4.2_18, and SDK and JRE 1.3.x before 1.3.1_23 allows context-dependent attackers to gain privileges via unspecified vectors related to font processing.
nvd
CVE-2008-5340P3CRITICALCVSS 10.0≤ 1.4.2_18v1.4.2_1+16 more2008-12-05
CVE-2008-5340 [CRITICAL] CWE-264 CVE-2008-5340: Unspecified vulnerability in Java Web Start (JWS) and Java Plug-in with Sun JDK and JRE 6 Update 10
Unspecified vulnerability in Java Web Start (JWS) and Java Plug-in with Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier allows untrusted JWS applications to gain privileges to access local files or applications via unknown vectors, aka 6727081.
nvd
CVE-2008-3107P3CRITICALCVSS 10.0≤ 1.4.2_17v1.4.2_02+14 more2008-07-09
CVE-2008-3107 [CRITICAL] CWE-264 CVE-2008-3107: Unspecified vulnerability in the Virtual Machine in Sun Java Runtime Environment (JRE) in JDK and JR
Unspecified vulnerability in the Virtual Machine in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 7, JDK and JRE 5.0 before Update 16, and SDK and JRE 1.4.x before 1.4.2_18 allows context-dependent attackers to gain privileges via an untrusted (1) application or (2) applet, as demonstrated by an application or applet that grants
nvd
CVE-2010-4469P3CRITICALCVSS 10.0≤ 1.4.2_29v1.4.2+28 more2011-02-17
CVE-2010-4469 [CRITICAL] CVE-2010-4469: Unspecified vulnerability in the Java Runtime Environment (JRE) in Oracle Java SE and Java for Busin
Unspecified vulnerability in the Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 23 and earlier, 5.0 Update 27 and earlier, and 1.4.2_29 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality, integrity, and availability via unknown vectors related to HotSpot. NOTE
nvd
CVE-2008-5356P3CRITICALCVSS 9.3≤ 1.4.2_18v1.4.2_1+16 more2008-12-05
CVE-2008-5356 [CRITICAL] CWE-119 CVE-2008-5356: Heap-based buffer overflow in Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and ear
Heap-based buffer overflow in Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier might allow remote attackers to execute arbitrary code via a crafted TrueType font file.
nvd
CVE-2007-2435P3CRITICALCVSS 10.0≤ 1.4.3_132007-05-02
CVE-2007-2435 [CRITICAL] CWE-264 CVE-2007-2435: Sun Java Web Start in JDK and JRE 5.0 Update 10 and earlier, and Java Web Start in SDK and JRE 1.4.2
Sun Java Web Start in JDK and JRE 5.0 Update 10 and earlier, and Java Web Start in SDK and JRE 1.4.2_13 and earlier, allows remote attackers to perform unauthorized actions via an application that grants privileges to itself, related to "Incorrect Use of System Classes" and probably related to support for JNLP files.
nvd
CVE-2010-0844P3HIGHCVSS 7.5≤ 1.4.2_25v1.4.2+59 more2010-04-01
CVE-2010-0844 [HIGH] CVE-2010-0844: Unspecified vulnerability in the Sound component in Oracle Java SE and Java for Business 6 Update 18
Unspecified vulnerability in the Sound component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, 1.4.2_25, and 1.3.1_27 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the March 2010 CPU. Oracle has not commented on claims from a reliable res
nvd
CVE-2009-3868P3CRITICALCVSS 9.3v1.4.2_01v1.4.2_1+63 more2009-11-05
CVE-2009-3868 [CRITICAL] CWE-119 CVE-2009-3868: Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x b
Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK and JRE 1.4.x before 1.4.2_24 does not properly parse color profiles, which allows remote attackers to gain privileges via a crafted image file, aka Bug Id 6862970.
nvd
CVE-2009-3872P3CRITICALCVSS 9.3v1.4.2_01v1.4.2_1+63 more2009-11-05
CVE-2009-3872 [CRITICAL] CVE-2009-3872: Unspecified vulnerability in the JPEG JFIF Decoder in Sun Java SE in JDK and JRE 5.0 before Update 2
Unspecified vulnerability in the JPEG JFIF Decoder in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to gain privileges via a crafted image file, aka Bug Id 6862969.
nvd
CVE-2008-3111P3CRITICALCVSS 10.0v1.4v1.4.2+17 more2008-07-09
CVE-2008-3111 [CRITICAL] CWE-20 CVE-2008-3111: Multiple buffer overflows in Sun Java Web Start in JDK and JRE 6 before Update 4, JDK and JRE 5.0 be
Multiple buffer overflows in Sun Java Web Start in JDK and JRE 6 before Update 4, JDK and JRE 5.0 before Update 16, and SDK and JRE 1.4.x before 1.4.2_18 allow context-dependent attackers to gain privileges via an untrusted application, as demonstrated by (a) an application that grants itself privileges to (1) read local files, (2) write to local fil
nvd
CVE-2009-3873P3CRITICALCVSS 9.3v1.4.2_01v1.4.2_1+63 more2009-11-05
CVE-2009-3873 [CRITICAL] CWE-119 CVE-2009-3873: The JPEG Image Writer in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Updat
The JPEG Image Writer in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to gain privileges via a crafted image file, related to a "quantization problem," aka Bug Id 6862968.
nvd
CVE-2008-1185P3CRITICALCVSS 9.3v1.4.2v1.4.2_1+15 more2008-03-06
CVE-2008-1185 [CRITICAL] CWE-264 CVE-2008-1185: Unspecified vulnerability in the Virtual Machine for Sun Java Runtime Environment (JRE) and JDK 6 Up
Unspecified vulnerability in the Virtual Machine for Sun Java Runtime Environment (JRE) and JDK 6 Update 4 and earlier, 5.0 Update 14 and earlier, and SDK/JRE 1.4.2_16 and earlier allows remote attackers to gain privileges via an untrusted application or applet, a different issue than CVE-2008-1186, aka "the first issue."
nvd
CVE-2008-1186P3CRITICALCVSS 9.3v1.4.2v1.4.2_1+15 more2008-03-06
CVE-2008-1186 [CRITICAL] CVE-2008-1186: Unspecified vulnerability in the Virtual Machine for Sun Java Runtime Environment (JRE) and JDK 5.0
Unspecified vulnerability in the Virtual Machine for Sun Java Runtime Environment (JRE) and JDK 5.0 Update 13 and earlier, and SDK/JRE 1.4.2_16 and earlier, allows remote attackers to gain privileges via an untrusted application or applet, a different issue than CVE-2008-1185, aka "the second issue."
nvd
CVE-2010-0850P3HIGHCVSS 7.5≤ 1.3.1_27v1.3.0+33 more2010-04-01
CVE-2010-0850 [HIGH] CVE-2010-0850: Unspecified vulnerability in the Java 2D component in Oracle Java SE and Java for Business 1.3.1_27
Unspecified vulnerability in the Java 2D component in Oracle Java SE and Java for Business 1.3.1_27 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.
nvd