cbcvebase.

Sun Sdk vulnerabilities

126 known vulnerabilities affecting sun/sdk.

Total CVEs
126
CISA KEV
0
Public exploits
10
Exploited in wild
3
Severity breakdown
CRITICAL50HIGH20MEDIUM51LOW5

Vulnerabilities

Page 5 of 7
CVE-2008-5360P4MEDIUMCVSS 6.4v1.3.1v1.3.1_01+47 more2008-12-05
CVE-2008-5360 [MEDIUM] CVE-2008-5360: Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 1 Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; SDK and JRE 1.4.2_18 and earlier; and SDK and JRE 1.3.1_23 and earlier creates temporary files with predictable file names, which allows attackers to write malicious JAR files via unknown vectors.
nvd
CVE-2010-3541P4MEDIUMCVSS 5.1≤ 1.4.2_27v1.4.2+62 more2010-10-19
CVE-2010-3541 [MEDIUM] CVE-2010-3541: Unspecified vulnerability in the Networking component in Oracle Java SE and Java for Business 6 Upda Unspecified vulnerability in the Networking component in Oracle Java SE and Java for Business 6 Update 21, 5.0 Update 25, 1.4.2_27, and 1.3.1_28 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the October 2010 CPU. Oracle has not commented on claims from a rel
nvd
CVE-2010-0093P4MEDIUMCVSS 5.1≤ 1.4.2_25v1.4.2+24 more2010-04-01
CVE-2010-0093 [MEDIUM] CVE-2010-0093: Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for B Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, and 1.4.2_25 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors, a different vulnerability than CVE-2010-0095.
nvd
CVE-2010-0085P4MEDIUMCVSS 5.1≤ 1.4.2_25v1.4.2+59 more2010-04-01
CVE-2010-0085 [MEDIUM] CVE-2010-0085: Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for B Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, 1.4.2_25, and 1.3.1_27 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors, a different vulnerability than CVE-2010-0088.
nvd
CVE-2009-3875P4MEDIUMCVSS 5.0v1.4.2_01v1.4.2_1+64 more2009-11-05
CVE-2009-3875 [MEDIUM] CWE-310 CVE-2009-3875: The MessageDigest.isEqual function in Java Runtime Environment (JRE) in Sun Java SE in JDK and JRE 5 The MessageDigest.isEqual function in Java Runtime Environment (JRE) in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to spoof HMAC-based digital signatures, and possibly bypass authentication, via unspecified vectors rel
nvd
CVE-2008-5346P4HIGHCVSS 7.1v1.3.1v1.3.1_01+47 more2008-12-05
CVE-2008-5346 [HIGH] CWE-200 CVE-2008-5346: Unspecified vulnerability in Java Runtime Environment (JRE) for Sun JDK and JRE 5.0 Update 16 and ea Unspecified vulnerability in Java Runtime Environment (JRE) for Sun JDK and JRE 5.0 Update 16 and earlier; SDK and JRE 1.4.2_18 and earlier; and SDK and JRE 1.3.1_23 or earlier allows untrusted applets and applications to read arbitrary memory via a crafted ZIP file.
nvd
CVE-2007-3698P4HIGHCVSS 7.8v1.4.2_11v1.4.2_12+2 more2007-07-11
CVE-2007-3698 [HIGH] CVE-2007-3698: The Java Secure Socket Extension (JSSE) in Sun JDK and JRE 6 Update 1 and earlier, JDK and JRE 5.0 U The Java Secure Socket Extension (JSSE) in Sun JDK and JRE 6 Update 1 and earlier, JDK and JRE 5.0 Updates 7 through 11, and SDK and JRE 1.4.2_11 through 1.4.2_14, when using JSSE for SSL/TLS support, allows remote attackers to cause a denial of service (CPU consumption) via certain SSL/TLS handshake requests.
nvd
CVE-2010-0082P4MEDIUMCVSS 5.1≤ 1.4.2_25v1.4.2+59 more2010-04-01
CVE-2010-0082 [MEDIUM] CVE-2010-0082: Unspecified vulnerability in the HotSpot Server component in Oracle Java SE and Java for Business 6 Unspecified vulnerability in the HotSpot Server component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, 1.4.2_25, and 1.3.1_27 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.
nvd
CVE-2006-0614P4MEDIUMCVSS 6.4≥ 1.3.0, ≤ 1.3.1_16≥ 1.4.0, ≤ 1.4.2_082006-02-09
CVE-2006-0614 [MEDIUM] CVE-2006-0614: Unspecified vulnerability in Sun Java JDK and JRE 5.0 Update 3 and earlier, SDK and JRE 1.3.x throug Unspecified vulnerability in Sun Java JDK and JRE 5.0 Update 3 and earlier, SDK and JRE 1.3.x through 1.3.1_16 and 1.4.x through 1.4.2_08 allows remote attackers to bypass Java sandbox security and obtain privileges via unspecified vectors involving the reflection APIs, aka the "first issue."
nvd
CVE-2008-3104P4MEDIUMCVSS 6.8v1.3.0v1.3.1_01+38 more2008-07-09
CVE-2008-3104 [MEDIUM] CWE-264 CVE-2008-3104: Multiple unspecified vulnerabilities in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before U Multiple unspecified vulnerabilities in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 7, JDK and JRE 5.0 before Update 16, SDK and JRE 1.4.x before 1.4.2_18, and SDK and JRE 1.3.x before 1.3.1_23 allow remote attackers to violate the security model for an applet's outbound connections by connecting to localhost services running on
nvd
CVE-2010-3548P4MEDIUMCVSS 5.0≤ 1.4.2_27v1.4.2+26 more2010-10-19
CVE-2010-3548 [MEDIUM] CVE-2010-3548: Unspecified vulnerability in the Java Naming and Directory Interface (JNDI) component in Oracle Java Unspecified vulnerability in the Java Naming and Directory Interface (JNDI) component in Oracle Java SE and Java for Business 6 Update 21, 5.0 Update 25, and 1.4.2_27 allows remote attackers to affect confidentiality via unknown vectors. NOTE: the previous information was obtained from the October 2010 CPU. Oracle has not commented on claims from a reliable d
nvd
CVE-2005-1080P4MEDIUMCVSS 5.0v1.4.2v1.52005-05-02
CVE-2005-1080 [MEDIUM] CVE-2005-1080: Directory traversal vulnerability in the Java Archive Tool (Jar) utility in J2SE SDK 1.4.2 and 1.5, Directory traversal vulnerability in the Java Archive Tool (Jar) utility in J2SE SDK 1.4.2 and 1.5, and OpenJDK, allows remote attackers to create or overwrite arbitrary files via a .. (dot dot) in filenames in a .jar file.
nvd
CVE-2010-0084P4MEDIUMCVSS 5.0≤ 1.4.2_25v1.4.2+24 more2010-04-01
CVE-2010-0084 [MEDIUM] CVE-2010-0084: Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for B Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, and 1.4.2_25 allows remote attackers to affect confidentiality via unknown vectors, a different vulnerability than CVE-2010-0091.
nvd
CVE-2008-5339P4MEDIUMCVSS 5.0≤ 1.4.2_18v1.4.2_1+16 more2008-12-05
CVE-2008-5339 [MEDIUM] CVE-2008-5339: Unspecified vulnerability in Java Web Start (JWS) and Java Plug-in with Sun JDK and JRE 6 Update 10 Unspecified vulnerability in Java Web Start (JWS) and Java Plug-in with Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier allows untrusted JWS applications to perform network connections to unauthorized hosts via unknown vectors, aka CR 6727079.
nvd
CVE-2010-4466P4MEDIUMCVSS 5.0≤ 1.4.2_29v1.4.2+28 more2011-02-17
CVE-2010-4466 [MEDIUM] CVE-2010-4466: Unspecified vulnerability in the Java Runtime Environment (JRE) in Oracle Java SE and Java for Busin Unspecified vulnerability in the Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 23 and earlier for Windows, Solaris, and, Linux; 5.0 Update 27 and earlier for Windows; and 1.4.2_29 and earlier for Windows allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality via unknown vector
nvd
CVE-2009-3877P4MEDIUMCVSS 5.0v1.4.2_01v1.4.2_1+64 more2009-11-05
CVE-2009-3877 [MEDIUM] CWE-399 CVE-2009-3877: Unspecified vulnerability in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before U Unspecified vulnerability in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to cause a denial of service (memory consumption) via crafted HTTP headers, which are not properly parsed by the ASN.1 DER input stream parser, ak
nvd
CVE-2005-3583P4HIGHCVSS 7.8v1.4.2_08v1.4.2_09+1 more2005-11-16
CVE-2005-3583 [HIGH] CVE-2005-3583: (1) Java Runtime Environment (JRE) and (2) Software Development Kit (SDK) 1.4.2_08, 1.4.2_09, and 1. (1) Java Runtime Environment (JRE) and (2) Software Development Kit (SDK) 1.4.2_08, 1.4.2_09, and 1.5.0_05 and possibly other versions allow remote attackers to cause a denial of service (JVM unresponsive) via a crafted serialized object, such as a font object as demonstrated on JBoss.
nvd
CVE-2007-5240P4MEDIUMCVSS 5.0v1.3.1_01v1.3.1_01a+14 more2007-10-06
CVE-2007-5240 [MEDIUM] CVE-2007-5240: Visual truncation vulnerability in the Java Runtime Environment in Sun JDK and JRE 6 Update 2 and ea Visual truncation vulnerability in the Java Runtime Environment in Sun JDK and JRE 6 Update 2 and earlier, JDK and JRE 5.0 Update 12 and earlier, SDK and JRE 1.4.2_15 and earlier, and SDK and JRE 1.3.1_20 and earlier allows remote attackers to circumvent display of the untrusted-code warning banner by creating a window larger than the workstation screen.
nvd
CVE-2009-1093P4MEDIUMCVSS 5.0≤ 1.3.1_24v1.3.1+47 more2009-03-25
CVE-2009-1093 [MEDIUM] CWE-16 CVE-2009-1093: LdapCtx in the LDAP service in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 LdapCtx in the LDAP service in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 17 and earlier; 6 Update 12 and earlier; SDK and JRE 1.3.1_24 and earlier; and 1.4.2_19 and earlier does not close the connection when initialization fails, which allows remote attackers to cause a denial of service (LDAP service hang).
nvd
CVE-2010-0089P4MEDIUMCVSS 5.0≤ 1.4.2_25v1.4.2+24 more2010-04-01
CVE-2010-0089 [MEDIUM] CVE-2010-0089: Unspecified vulnerability in the Java Web Start, Java Plug-in component in Oracle Java SE and Java f Unspecified vulnerability in the Java Web Start, Java Plug-in component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, and 1.4.2_25 allows remote attackers to affect availability via unknown vectors.
nvd