Sun Sdk vulnerabilities
126 known vulnerabilities affecting sun/sdk.
Total CVEs
126
CISA KEV
0
Public exploits
10
Exploited in wild
3
Severity breakdown
CRITICAL50HIGH20MEDIUM51LOW5
Vulnerabilities
Page 6 of 7
CVE-2010-3551P4MEDIUMCVSS 5.0≤ 1.4.2_27v1.4.2+26 more2010-10-19
CVE-2010-3551 [MEDIUM] CVE-2010-3551: Unspecified vulnerability in the Networking component in Oracle Java SE and Java for Business 6 Upda
Unspecified vulnerability in the Networking component in Oracle Java SE and Java for Business 6 Update 21, 5.0 Update 25, and 1.4.2_27 allows remote attackers to affect confidentiality via unknown vectors.
nvd
CVE-2001-1480P4HIGHCVSS 7.5v1.1.3v1.3.02001-12-31
CVE-2001-1480 [HIGH] CVE-2001-1480: Java Runtime Environment (JRE) and SDK 1.2 through 1.3.0_04 allows untrusted applets to access the s
Java Runtime Environment (JRE) and SDK 1.2 through 1.3.0_04 allows untrusted applets to access the system clipboard.
nvd
CVE-2009-3876P4MEDIUMCVSS 5.0v1.4.2_01v1.4.2_1+64 more2009-11-05
CVE-2009-3876 [MEDIUM] CWE-399 CVE-2009-3876: Unspecified vulnerability in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before U
Unspecified vulnerability in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to cause a denial of service (memory consumption) via crafted DER encoded data, which is not properly decoded by the ASN.1 DER input stream parser
nvd
CVE-2008-5350P4MEDIUMCVSS 5.0≤ 1.4.2_18v1.4.2_1+16 more2008-12-05
CVE-2008-5350 [MEDIUM] CWE-200 CVE-2008-5350: Unspecified vulnerability in Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earl
Unspecified vulnerability in Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier allows untrusted applications and applets to list the contents of the operating user's directory via unknown vectors.
nvd
CVE-2010-0091P4MEDIUMCVSS 4.3≤ 1.4.2_25v1.4.2+24 more2010-04-01
CVE-2010-0091 [MEDIUM] CVE-2010-0091: Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for B
Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, and 1.4.2_25 allows remote attackers to affect confidentiality via unknown vectors, a different vulnerability than CVE-2010-0084.
nvd
CVE-2007-5236P4MEDIUMCVSS 5.4v1.4.2_03v1.4.2_08+7 more2007-10-06
CVE-2007-5236 [MEDIUM] CWE-264 CVE-2007-5236: Java Web Start in Sun JDK and JRE 5.0 Update 12 and earlier, and SDK and JRE 1.4.2_15 and earlier, o
Java Web Start in Sun JDK and JRE 5.0 Update 12 and earlier, and SDK and JRE 1.4.2_15 and earlier, on Windows does not properly enforce access restrictions for untrusted applications, which allows user-assisted remote attackers to read local files via an untrusted application.
nvd
CVE-2008-5342P4MEDIUMCVSS 5.0≤ 1.4.2_18v1.4.2_1+16 more2008-12-05
CVE-2008-5342 [MEDIUM] CWE-200 CVE-2008-5342: Unspecified vulnerability in the BasicService for Java Web Start (JWS) and Java Plug-in with Sun JDK
Unspecified vulnerability in the BasicService for Java Web Start (JWS) and Java Plug-in with Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier allows untrusted downloaded applications to cause local files to be displayed in the browser of the user of the untrusted application via unkno
nvd
CVE-2006-0615P4MEDIUMCVSS 4.0v1.4.2v1.4.2_1+8 more2006-02-09
CVE-2006-0615 [MEDIUM] CVE-2006-0615: Multiple unspecified vulnerabilities in Sun Java JDK and JRE 5.0 Update 4 and earlier, SDK and JRE 1
Multiple unspecified vulnerabilities in Sun Java JDK and JRE 5.0 Update 4 and earlier, SDK and JRE 1.4.x through 1.4.2_09 allow remote attackers to bypass Java sandbox security and obtain privileges via unspecified vectors involving the reflection APIs, aka the "second and third issues."
nvd
CVE-2010-4475P4MEDIUMCVSS 4.3≤ 1.4.2_29v1.4.2+28 more2011-02-17
CVE-2010-4475 [MEDIUM] CVE-2010-4475: Unspecified vulnerability in the Java Runtime Environment (JRE) in Oracle Java SE and Java for Busin
Unspecified vulnerability in the Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 23 and earlier, 5.0 Update 27 and earlier, and 1.4.2_29 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality via unknown vectors related to Deployment, a different vulnerability than C
nvd
CVE-2008-5341P4MEDIUMCVSS 5.0≤ 1.4.2_18v1.4.2_1+16 more2008-12-05
CVE-2008-5341 [MEDIUM] CWE-200 CVE-2008-5341: Unspecified vulnerability in Java Web Start (JWS) and Java Plug-in with Sun JDK and JRE 6 Update 10
Unspecified vulnerability in Java Web Start (JWS) and Java Plug-in with Sun JDK and JRE 6 Update 10 and earlier, and JDK and JRE 5.0 Update 16 and earlier, allows untrusted JWS applications to obtain the pathname of the JWS cache and the application username via unknown vectors, aka CR 6727071.
nvd
CVE-2007-2789P4MEDIUMCVSS 4.3v1.3.1v1.3.1_01+34 more2007-05-22
CVE-2007-2789 [MEDIUM] CWE-399 CVE-2007-2789: The BMP image parser in Sun Java Development Kit (JDK) before 1.5.0_11-b03 and 1.6.x before 1.6.0_01
The BMP image parser in Sun Java Development Kit (JDK) before 1.5.0_11-b03 and 1.6.x before 1.6.0_01-b06, and Sun Java Runtime Environment in JDK and JRE 6, JDK and JRE 5.0 Update 10 and earlier, SDK and JRE 1.4.2_14 and earlier, and SDK and JRE 1.3.1_19 and earlier, when running on Unix/Linux systems, allows remote attackers to cause a denial of serv
nvd
CVE-2010-4447P4MEDIUMCVSS 4.3≤ 1.4.2_29v1.4.2+28 more2011-02-17
CVE-2010-4447 [MEDIUM] CVE-2010-4447: Unspecified vulnerability in the Java Runtime Environment (JRE) in Oracle Java SE and Java for Busin
Unspecified vulnerability in the Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 23 and earlier, 5.0 Update 27 and earlier, and 1.4.2_29 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality via unknown vectors related to Deployment, a different vulnerability than C
nvd
CVE-2008-3114P4MEDIUMCVSS 5.0≤ 1.4.2_17v1.4.2+16 more2008-07-09
CVE-2008-3114 [MEDIUM] CWE-200 CVE-2008-3114: Unspecified vulnerability in Sun Java Web Start in JDK and JRE 6 before Update 7, JDK and JRE 5.0 be
Unspecified vulnerability in Sun Java Web Start in JDK and JRE 6 before Update 7, JDK and JRE 5.0 before Update 16, and SDK and JRE 1.4.x before 1.4.2_18 allows context-dependent attackers to obtain sensitive information (the cache location) via an untrusted application, aka CR 6704074.
nvd
CVE-2002-0058P4MEDIUMCVSS 5.0v1.1.8_007v1.2.2_10+2 more2002-03-15
CVE-2002-0058 [MEDIUM] CVE-2002-0058: Vulnerability in Java Runtime Environment (JRE) allows remote malicious web sites to hijack or sniff
Vulnerability in Java Runtime Environment (JRE) allows remote malicious web sites to hijack or sniff a web client's sessions, when an HTTP proxy is being used, via a Java applet that redirects the session to another server, as seen in (1) Netscape 6.0 through 6.1 and 4.79 and earlier, (2) Microsoft VM build 3802 and earlier as used in Internet Explorer 4.x an
nvd
CVE-2007-5232P4MEDIUMCVSS 4.0v1.3.1_01v1.3.1_01a+14 more2007-10-05
CVE-2007-5232 [MEDIUM] CVE-2007-5232: Sun Java Runtime Environment (JRE) in JDK and JRE 6 Update 2 and earlier, JDK and JRE 5.0 Update 12
Sun Java Runtime Environment (JRE) in JDK and JRE 6 Update 2 and earlier, JDK and JRE 5.0 Update 12 and earlier, SDK and JRE 1.4.2_15 and earlier, and SDK and JRE 1.3.1_20 and earlier, when applet caching is enabled, allows remote attackers to violate the security model for an applet's outbound connections via a DNS rebinding attack.
nvd
CVE-2006-5201P4MEDIUMCVSS 4.0v1.3.1v1.3.1_01+32 more2006-10-10
CVE-2006-5201 [MEDIUM] CVE-2006-5201: Multiple packages on Sun Solaris, including (1) NSS; (2) Java JDK and JRE 5.0 Update 8 and earlier,
Multiple packages on Sun Solaris, including (1) NSS; (2) Java JDK and JRE 5.0 Update 8 and earlier, SDK and JRE 1.4.x up to 1.4.2_12, and SDK and JRE 1.3.x up to 1.3.1_19; (3) JSSE 1.0.3_03 and earlier; (4) IPSec/IKE; (5) Secure Global Desktop; and (6) StarOffice, when using an RSA key with exponent 3, removes PKCS-1 padding before generating a hash, which all
nvd
CVE-2007-5239P4MEDIUMCVSS 4.0v1.3.1_01v1.3.1_01a+14 more2007-10-06
CVE-2007-5239 [MEDIUM] CWE-264 CVE-2007-5239: Java Web Start in Sun JDK and JRE 6 Update 2 and earlier, JDK and JRE 5.0 Update 12 and earlier, SDK
Java Web Start in Sun JDK and JRE 6 Update 2 and earlier, JDK and JRE 5.0 Update 12 and earlier, SDK and JRE 1.4.2_15 and earlier, and SDK and JRE 1.3.1_20 and earlier does not properly enforce access restrictions for untrusted (1) applications and (2) applets, which allows user-assisted remote attackers to copy or rename arbitrary files when local us
nvd
CVE-2006-6737P4MEDIUMCVSS 4.3v1.3.1v1.3.1_01+29 more2006-12-26
CVE-2006-6737 [MEDIUM] CVE-2006-6737: Unspecified vulnerability in Sun Java Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 U
Unspecified vulnerability in Sun Java Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 5 and earlier, Java System Development Kit (SDK) and JRE 1.4.2_10 and earlier 1.4.x versions, and SDK and JRE 1.3.1_18 and earlier allows attackers to use untrusted applets to "access data in other applets," aka "The first issue."
nvd
CVE-2006-6736P4MEDIUMCVSS 4.3v1.3.1v1.3.1_01+31 more2006-12-26
CVE-2006-6736 [MEDIUM] CVE-2006-6736: Unspecified vulnerability in Sun Java Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 U
Unspecified vulnerability in Sun Java Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 6 and earlier, Java System Development Kit (SDK) and JRE 1.4.2_12 and earlier 1.4.x versions, and SDK and JRE 1.3.1_18 and earlier allows attackers to use untrusted applets to "access data in other applets," aka "The second issue."
nvd
CVE-2004-0651P4MEDIUMCVSS 5.0v1.4.2v1.4.2_032004-08-06
CVE-2004-0651 [MEDIUM] CVE-2004-0651: Unknown vulnerability in Sun Java Runtime Environment (JRE) 1.4.2 through 1.4.2_03 allows remote att
Unknown vulnerability in Sun Java Runtime Environment (JRE) 1.4.2 through 1.4.2_03 allows remote attackers to cause a denial of service (virtual machine hang).
nvd