Sun Sdk vulnerabilities
126 known vulnerabilities affecting sun/sdk.
Total CVEs
126
CISA KEV
0
Public exploits
10
Exploited in wild
3
Severity breakdown
CRITICAL50HIGH20MEDIUM51LOW5
Vulnerabilities
Page 4 of 7
CVE-2010-0848P3HIGHCVSS 7.5≤ 1.4.2_25v1.4.2+59 more2010-04-01
CVE-2010-0848 [HIGH] CVE-2010-0848: Unspecified vulnerability in the Java 2D component in Oracle Java SE and Java for Business 6 Update
Unspecified vulnerability in the Java 2D component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, 1.4.2_25, and 1.3.1_27 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.
nvd
CVE-2010-0839P3HIGHCVSS 7.5≤ 1.4.2_25v1.4.2+59 more2010-04-01
CVE-2010-0839 [HIGH] CVE-2010-0839: Unspecified vulnerability in the Sound component in Oracle Java SE and Java for Business 6 Update 18
Unspecified vulnerability in the Sound component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, 1.4.2_25, and 1.3.1_27 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.
nvd
CVE-2008-5344P3HIGHCVSS 7.5≤ 1.4.2_18v1.4.2_1+16 more2008-12-05
CVE-2008-5344 [HIGH] CVE-2008-5344: Unspecified vulnerability in Java Web Start (JWS) and Java Plug-in with Sun JDK and JRE 6 Update 10
Unspecified vulnerability in Java Web Start (JWS) and Java Plug-in with Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier allows untrusted applets to read arbitrary files and make unauthorized network connections via unknown vectors related to applet classloading, aka 6716217.
nvd
CVE-2010-0087P3HIGHCVSS 7.5≤ 1.4.2_25v1.4.2+59 more2010-04-01
CVE-2010-0087 [HIGH] CVE-2010-0087: Unspecified vulnerability in the Java Web Start, Java Plug-in component in Oracle Java SE and Java f
Unspecified vulnerability in the Java Web Start, Java Plug-in component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, 1.4.2_25, and 1.3.1_27 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.
nvd
CVE-2008-1189P3MEDIUMCVSS 6.8v1.4.2v1.4.2_1+15 more2008-03-06
CVE-2008-1189 [MEDIUM] CVE-2008-1189: Buffer overflow in Java Web Start in Sun JDK and JRE 6 Update 4 and earlier, 5.0 Update 14 and earli
Buffer overflow in Java Web Start in Sun JDK and JRE 6 Update 4 and earlier, 5.0 Update 14 and earlier, and SDK/JRE 1.4.2_16 and earlier allows remote attackers to execute arbitrary code via unknown vectors, a different issue than CVE-2008-1188, aka the "third" issue.
nvd
CVE-2008-5345P3HIGHCVSS 7.5v1.3.1v1.3.1_01+47 more2008-12-05
CVE-2008-5345 [HIGH] CVE-2008-5345: Unspecified vulnerability in Java Runtime Environment (JRE) with Sun JDK and JRE 6 Update 10 and ear
Unspecified vulnerability in Java Runtime Environment (JRE) with Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; SDK and JRE 1.4.2_18 and earlier; and SDK and JRE 1.3.1_23 and earlier allows code that is loaded from a local filesystem to read arbitrary files and make unauthorized connections to localhost via unknown vectors.
nvd
CVE-2008-5351P3HIGHCVSS 7.5≤ 1.4.2_18v1.4.2_1+16 more2008-12-05
CVE-2008-5351 [HIGH] CWE-264 CVE-2008-5351: Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 1
Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier accepts UTF-8 encodings that are not the "shortest" form, which makes it easier for attackers to bypass protection mechanisms for other applications that rely on shortest-form UTF-8 encodings.
nvd
CVE-2004-2764P3CRITICALCVSS 10.0v1.4.0v1.4.0_01+16 more2009-06-02
CVE-2004-2764 [CRITICAL] CWE-264 CVE-2004-2764: Sun SDK and Java Runtime Environment (JRE) 1.4.2 through 1.4.2_04, 1.4.1 through 1.4.1_07, and 1.4.0
Sun SDK and Java Runtime Environment (JRE) 1.4.2 through 1.4.2_04, 1.4.1 through 1.4.1_07, and 1.4.0 through 1.4.0_04 allows untrusted applets and unprivileged servlets to gain privileges and read data from other applets via unspecified vectors related to classes in the XSLT processor, aka "XML sniffing."
nvd
CVE-2010-0088P3MEDIUMCVSS 6.8≤ 1.4.2_25v1.4.2+59 more2010-04-01
CVE-2010-0088 [MEDIUM] CVE-2010-0088: Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for B
Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, 1.4.2_25, and 1.3.1_27 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors, a different vulnerability than CVE-2010-0085.
nvd
CVE-2010-0095P3MEDIUMCVSS 6.8≤ 1.4.2_25v1.4.2+24 more2010-04-01
CVE-2010-0095 [MEDIUM] CVE-2010-0095: Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for B
Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, and 1.4.2_25 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors, a different vulnerability than CVE-2010-0093.
nvd
CVE-2002-0076P4HIGHCVSS 7.5v1.2.2_10v1.2.2_010+3 more2002-03-19
CVE-2002-0076 [HIGH] CVE-2002-0076: Java Runtime Environment (JRE) Bytecode Verifier allows remote attackers to escape the Java sandbox
Java Runtime Environment (JRE) Bytecode Verifier allows remote attackers to escape the Java sandbox and execute commands via an applet containing an illegal cast operation, as seen in (1) Microsoft VM build 3802 and earlier as used in Internet Explorer 4.x and 5.x, (2) Netscape 6.2.1 and earlier, and possibly other implementations that use vulnerable versions of
nvd
CVE-2006-6731P3CRITICALCVSS 9.3v1.3.1v1.3.1_01+31 more2006-12-26
CVE-2006-6731 [CRITICAL] CVE-2006-6731: Multiple buffer overflows in Sun Java Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 U
Multiple buffer overflows in Sun Java Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 7 and earlier, Java System Development Kit (SDK) and JRE 1.4.2_12 and earlier 1.4.x versions, and SDK and JRE 1.3.1_18 and earlier allow attackers to develop Java applets that read, write, or execute local files, possibly related to (1) integer overflow
nvd
CVE-2010-3549P3MEDIUMCVSS 6.8≤ 1.4.2_27v1.4.2+62 more2010-10-19
CVE-2010-3549 [MEDIUM] CVE-2010-3549: Unspecified vulnerability in the Networking component in Oracle Java SE and Java for Business 6 Upda
Unspecified vulnerability in the Networking component in Oracle Java SE and Java for Business 6 Update 21, 5.0 Update 25, 1.4.2_27, and 1.3.1_28 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the October 2010 CPU. Oracle has not commented on claims from a rel
nvd
CVE-2008-1196P3MEDIUMCVSS 6.8v1.4.2v1.4.2_1+15 more2008-03-06
CVE-2008-1196 [MEDIUM] CWE-119 CVE-2008-1196: Stack-based buffer overflow in Java Web Start (javaws.exe) in Sun JDK and JRE 6 Update 4 and earlier
Stack-based buffer overflow in Java Web Start (javaws.exe) in Sun JDK and JRE 6 Update 4 and earlier and 5.0 Update 14 and earlier; and SDK and JRE 1.4.2_16 and earlier; allows remote attackers to execute arbitrary code via a crafted JNLP file.
nvd
CVE-2009-2676P3MEDIUMCVSS 6.8≤ 1.4.2_21v1.4.0+33 more2009-08-05
CVE-2009-2676 [MEDIUM] CVE-2009-2676: Unspecified vulnerability in JNLPAppletlauncher in Sun Java SE, and SE for Business, in JDK and JRE
Unspecified vulnerability in JNLPAppletlauncher in Sun Java SE, and SE for Business, in JDK and JRE 6 Update 14 and earlier and JDK and JRE 5.0 Update 19 and earlier; and Java SE for Business in SDK and JRE 1.4.2_21 and earlier; allows remote attackers to create or modify arbitrary files via vectors involving an untrusted Java applet that accesses an old versi
nvd
CVE-2010-3557P3MEDIUMCVSS 6.8≤ 1.4.2_27v1.4.2+62 more2010-10-19
CVE-2010-3557 [MEDIUM] CVE-2010-3557: Unspecified vulnerability in the Swing component in Oracle Java SE and Java for Business 6 Update 21
Unspecified vulnerability in the Swing component in Oracle Java SE and Java for Business 6 Update 21, 5.0 Update 25, 1.4.2_27, and 1.3.1_28 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the October 2010 CPU. Oracle has not commented on claims from a reliable
nvd
CVE-2008-1187P3MEDIUMCVSS 6.8≤ 1.4.2_16v1.4.2+16 more2008-03-06
CVE-2008-1187 [MEDIUM] CWE-264 CVE-2008-1187: Unspecified vulnerability in Sun Java Runtime Environment (JRE) and JDK 6 Update 4 and earlier, 5.0
Unspecified vulnerability in Sun Java Runtime Environment (JRE) and JDK 6 Update 4 and earlier, 5.0 Update 14 and earlier, and SDK/JRE 1.4.2_16 and earlier allows remote attackers to cause a denial of service (JRE crash) and possibly execute arbitrary code via unknown vectors related to XSLT transforms.
nvd
CVE-2008-1192P3MEDIUMCVSS 6.8v1.3.1v1.3.1_01+38 more2008-03-06
CVE-2008-1192 [MEDIUM] CWE-254 CVE-2008-1192: Unspecified vulnerability in the Java Plug-in for Sun JDK and JRE 6 Update 4 and earlier, and 5.0 Up
Unspecified vulnerability in the Java Plug-in for Sun JDK and JRE 6 Update 4 and earlier, and 5.0 Update 14 and earlier; and SDK and JRE 1.4.2_16 and earlier, and 1.3.1_21 and earlier; allows remote attackers to bypass the same origin policy and "execute local applications" via unknown vectors.
nvd
CVE-2008-5348P4HIGHCVSS 7.1≤ 1.4.2_18v1.4.2_1+16 more2008-12-05
CVE-2008-5348 [HIGH] CVE-2008-5348: Unspecified vulnerability in Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earl
Unspecified vulnerability in Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier, when using Kerberos authentication, allows remote attackers to cause a denial of service (OS resource consumption) via unknown vectors.
nvd
CVE-2007-3922P4MEDIUMCVSS 6.8≤ 1.4.2_142007-07-21
CVE-2007-3922 [MEDIUM] CVE-2007-3922: Unspecified vulnerability in the Java Runtime Environment (JRE) Applet Class Loader in Sun JDK and J
Unspecified vulnerability in the Java Runtime Environment (JRE) Applet Class Loader in Sun JDK and JRE 5.0 Update 11 and earlier, 6 through 6 Update 1, and SDK and JRE 1.4.2_14 and earlier, allows remote attackers to violate the security model for an applet's outbound connections by connecting to certain localhost services running on the machine that loaded t
nvd