Vulnerabilities > SUN > Java Plug IN

DATE CVE VULNERABILITY TITLE RISK
2005-12-31 CVE-2005-4845 Configuration vulnerability in SUN Java Plug-In 1.4.203/1.4.204
The Java Plug-in 1.4.2_03 and 1.4.2_04 controls, and the 1.4.2_03 and 1.4.2_04 <applet> redirector controls, allow remote attackers to cause a denial of service (Internet Explorer crash) by creating a COM object of the class associated with the control's CLSID, which is not intended for use within Internet Explorer.
network
low complexity
sun CWE-16
5.0
2003-12-31 CVE-2003-1521 Unspecified vulnerability in SUN Java Plug-In
Sun Java Plug-In 1.4 through 1.4.2_02 allows remote attackers to repeatedly access the floppy drive via the createXmlDocument method in the org.apache.crimson.tree.XmlDocument class, which violates the Java security model.
network
low complexity
sun
6.4
2003-12-31 CVE-2003-1516 Cross-Site Applet Sandbox Security Model Violation vulnerability in SUN Java Plug-In 1.4.201
The org.apache.xalan.processor.XSLProcessorVersion class in Java Plug-in 1.4.2_01 allows signed and unsigned applets to share variables, which violates the Java security model and could allow remote attackers to read or write data belonging to a signed applet.
network
sun
6.8
2001-08-31 CVE-2001-1008 Unspecified vulnerability in SUN Java Plug-In and JRE
Java Plugin 1.4 for JRE 1.3 executes signed applets even if the certificate is expired, which could allow remote attackers to conduct unauthorized activities via an applet that has been signed by an expired certificate.
network
low complexity
sun
7.5