Skip to main content

Vendor/product archive

sun / openjdk CVEs

Beta · best-effort

17 CVEs tagged to sun / openjdk5 Critical, 5 High, 7 Medium, 0 Low, 0 Unrated.

CVE-2010-4351

Published Jan 20, 2011

The JNLP SecurityManager in IcedTea (IcedTea.so) 1.7 before 1.7.7, 1.8 before 1.8.4, and 1.9 before 1.9.4 for Java OpenJDK returns from the checkPermission method instead of throw…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-3884

Published Nov 9, 2009

The TimeZone.getTimeZone method in Sun Java SE 5.0 before Update 22 and 6 before Update 17, and OpenJDK, allows remote attackers to determine the existence of local files via vect…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-3883

Published Nov 9, 2009

Multiple unspecified vulnerabilities in the Windows Pluggable Look and Feel (PL&F) feature in the Swing implementation in Sun Java SE 5.0 before Update 22 and 6 before Update 17,…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2009-3882

Published Nov 9, 2009

Multiple unspecified vulnerabilities in the Swing implementation in Sun Java SE 5.0 before Update 22 and 6 before Update 17, and OpenJDK, have unknown impact and remote attack vec…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2009-3881

Published Nov 9, 2009

Sun Java SE 5.0 before Update 22 and 6 before Update 17, and OpenJDK, does not prevent the existence of children of a resurrected ClassLoader, which allows remote attackers to gai…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2009-3880

Published Nov 9, 2009

The Abstract Window Toolkit (AWT) in Java Runtime Environment (JRE) in Sun Java SE 5.0 before Update 22 and 6 before Update 17, and OpenJDK, does not properly restrict the objects…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-3879

Published Nov 9, 2009

Multiple unspecified vulnerabilities in the (1) X11 and (2) Win32GraphicsDevice subsystems in Sun Java SE 5.0 before Update 22 and 6 before Update 17, and OpenJDK, have unknown im…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2009-3728

Published Nov 9, 2009

Directory traversal vulnerability in the ICC_Profile.getInstance method in Java Runtime Environment (JRE) in Sun Java SE 5.0 before Update 22 and 6 before Update 17, and OpenJDK,…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-2690

Published Aug 10, 2009

The encoder in Sun Java SE 6 before Update 15, and OpenJDK, grants read access to private variables with unspecified names, which allows context-dependent attackers to obtain sens…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-2689

Published Aug 10, 2009

JDK13Services.getProviders in Sun Java SE 5.0 before Update 20 and 6 before Update 15, and OpenJDK, grants full privileges to instances of unspecified object types, which allows c…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-2476

Published Aug 10, 2009

The Java Management Extensions (JMX) implementation in Sun Java SE 6 before Update 15, and OpenJDK, does not properly enforce OpenType checks, which allows context-dependent attac…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-2475

Published Aug 10, 2009

Sun Java SE 5.0 before Update 20 and 6 before Update 15, and OpenJDK, might allow context-dependent attackers to obtain sensitive information via vectors involving static variable…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2009-1896

Published Aug 10, 2009

The Java Web Start framework in IcedTea in OpenJDK before 1.6.0.0-20.b16.fc10 on Fedora 10, and before 1.6.0.0-27.b16.fc11 on Fedora 11, trusts an entire application when at least…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-0794

Published Apr 13, 2009

Integer overflow in the PulseAudioTargetDataL class in src/java/org/classpath/icedtea/pulseaudio/PulseAudioTargetDataLine.java in Pulse-Java, as used in OpenJDK 1.6.0.0 and other…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-0793

Published Apr 9, 2009

cmsxform.c in LittleCMS (aka lcms or liblcms) 1.18, as used in OpenJDK and other products, allows remote attackers to cause a denial of service (NULL pointer dereference and appli…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-17 of 17 CVEsPage 1 of 1