Skip to main content

Vendor/product archive

sun / jdk CVEs

Beta · best-effort

395 CVEs tagged to sun / jdk154 Critical, 70 High, 149 Medium, 20 Low, 2 Unrated.

CVE-2009-3866

Published Nov 5, 2009

The Java Web Start Installer in Sun Java SE in JDK and JRE 6 before Update 17 does not properly use security model permissions when removing installer extensions, which allows rem…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-3865

Published Nov 5, 2009

The launch method in the Deployment Toolkit plugin in Java Runtime Environment (JRE) in Sun Java SE in JDK and JRE 6 before Update 17 allows remote attackers to execute arbitrary…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-3864

Published Nov 5, 2009

The Java Update functionality in Java Runtime Environment (JRE) in Sun Java SE in JDK and JRE 5.0 before Update 22 and JDK and JRE 6 before Update 17, when a non-English version o…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2009-2676

Published Aug 5, 2009

Unspecified vulnerability in JNLPAppletlauncher in Sun Java SE, and SE for Business, in JDK and JRE 6 Update 14 and earlier and JDK and JRE 5.0 Update 19 and earlier; and Java SE…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-2675

Published Aug 5, 2009

Integer overflow in the unpack200 utility in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15, and JDK and JRE 5.0 before Update 20, allows context-dependent a…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-2674

Published Aug 5, 2009

Integer overflow in javaws.exe in Sun Java Web Start in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15 allows context-dependent attackers to execute arbitrar…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2009-2673

Published Aug 5, 2009

The proxy mechanism implementation in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15, and JDK and JRE 5.0 before Update 20, allows remote attackers to bypass…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2009-2672

Published Aug 5, 2009

The proxy mechanism implementation in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15, and JDK and JRE 5.0 before Update 20, does not prevent access to browse…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2009-2671

Published Aug 5, 2009

The SOCKS proxy implementation in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15, and JDK and JRE 5.0 before Update 20, allows remote attackers to discover t…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-2670

Published Aug 5, 2009

The audio system in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15, and JDK and JRE 5.0 before Update 20, does not prevent access to java.lang.System propert…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-2030

Published Jun 11, 2009

Unspecified vulnerability in the XML Digital Signature verification functionality in JVA-RUN in JDK 6.0 in IBM OS/400 i5/OS V5R4M0 and V6R1M0 has unknown impact and attack vectors…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-1006

Published Apr 15, 2009

Unspecified vulnerability in the JRockit component in BEA Product Suite R27.6.2 and earlier, with SDK/JRE 1.4.2, JRE/JDK 5, and JRE/JDK 6, allows remote attackers to affect confid…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-1106

Published Mar 25, 2009

The Java Plug-in in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 6 Update 12, 11, and 10 does not properly parse crossdomain.xml files, which allows remote att…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-1101

Published Mar 25, 2009

Unspecified vulnerability in the lightweight HTTP server implementation in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 6 Update 12 and earlier allows remote a…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-1100

Published Mar 25, 2009

Multiple unspecified vulnerabilities in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 17 and earlier, and 6 Update 12 and earlier, allow remote attac…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-1098

Published Mar 25, 2009

Buffer overflow in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 17 and earlier; 6 Update 12 and earlier; 1.4.2_19 and earlier; and 1.3.1_24 and earl…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort
Showing 276-300 of 395 CVEsPage 12 of 16