Vulnerabilities > SUN > JRE > 1.3.1.11

DATE CVE VULNERABILITY TITLE RISK
2008-07-09 CVE-2008-3112 Permissions, Privileges, and Access Controls vulnerability in SUN Jdk, JRE and SDK
Directory traversal vulnerability in Sun Java Web Start in JDK and JRE 6 before Update 7, JDK and JRE 5.0 before Update 16, and SDK and JRE 1.4.x before 1.4.2_18 allows remote attackers to create arbitrary files via the writeManifest method in the CacheEntry class, aka CR 6703909.
network
low complexity
sun CWE-264
critical
10.0
2008-07-09 CVE-2008-3108 Buffer Errors vulnerability in SUN Jdk, JRE and SDK
Buffer overflow in Sun Java Runtime Environment (JRE) in JDK and JRE 5.0 before Update 10, SDK and JRE 1.4.x before 1.4.2_18, and SDK and JRE 1.3.x before 1.3.1_23 allows context-dependent attackers to gain privileges via unspecified vectors related to font processing.
network
low complexity
sun CWE-119
critical
10.0
2008-07-09 CVE-2008-3107 Permissions, Privileges, and Access Controls vulnerability in SUN Jdk, JRE and SDK
Unspecified vulnerability in the Virtual Machine in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 7, JDK and JRE 5.0 before Update 16, and SDK and JRE 1.4.x before 1.4.2_18 allows context-dependent attackers to gain privileges via an untrusted (1) application or (2) applet, as demonstrated by an application or applet that grants itself privileges to (a) read local files, (b) write to local files, or (c) execute local programs.
network
low complexity
sun CWE-264
critical
10.0
2008-07-09 CVE-2008-3104 Permissions, Privileges, and Access Controls vulnerability in SUN Jdk, JRE and SDK
Multiple unspecified vulnerabilities in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 7, JDK and JRE 5.0 before Update 16, SDK and JRE 1.4.x before 1.4.2_18, and SDK and JRE 1.3.x before 1.3.1_23 allow remote attackers to violate the security model for an applet's outbound connections by connecting to localhost services running on the machine that loaded the applet.
network
sun CWE-264
6.8
2008-03-06 CVE-2008-1192 7PK - Security Features vulnerability in SUN Jdk, JRE and SDK
Unspecified vulnerability in the Java Plug-in for Sun JDK and JRE 6 Update 4 and earlier, and 5.0 Update 14 and earlier; and SDK and JRE 1.4.2_16 and earlier, and 1.3.1_21 and earlier; allows remote attackers to bypass the same origin policy and "execute local applications" via unknown vectors.
network
sun CWE-254
6.8
2008-03-06 CVE-2008-1191 Unspecified vulnerability in SUN JDK and JRE
Unspecified vulnerability in Java Web Start in Sun JDK and JRE 6 Update 4 and earlier allows remote attackers to create arbitrary files via an untrusted application, a different issue than CVE-2008-1190, aka "The fifth issue."
network
sun
6.8
2008-03-06 CVE-2008-1187 Permissions, Privileges, and Access Controls vulnerability in SUN Jdk, JRE and SDK
Unspecified vulnerability in Sun Java Runtime Environment (JRE) and JDK 6 Update 4 and earlier, 5.0 Update 14 and earlier, and SDK/JRE 1.4.2_16 and earlier allows remote attackers to cause a denial of service (JRE crash) and possibly execute arbitrary code via unknown vectors related to XSLT transforms.
network
sun CWE-264
6.8
2007-05-22 CVE-2007-2789 Resource Management Errors vulnerability in SUN Jdk, JRE and SDK
The BMP image parser in Sun Java Development Kit (JDK) before 1.5.0_11-b03 and 1.6.x before 1.6.0_01-b06, and Sun Java Runtime Environment in JDK and JRE 6, JDK and JRE 5.0 Update 10 and earlier, SDK and JRE 1.4.2_14 and earlier, and SDK and JRE 1.3.1_19 and earlier, when running on Unix/Linux systems, allows remote attackers to cause a denial of service (JVM hang) via untrusted applets or applications that open arbitrary local files via a crafted BMP file, such as /dev/tty.
network
sun CWE-399
4.3
2007-05-22 CVE-2007-2788 Numeric Errors vulnerability in SUN Jdk, JRE and SDK
Integer overflow in the embedded ICC profile image parser in Sun Java Development Kit (JDK) before 1.5.0_11-b03 and 1.6.x before 1.6.0_01-b06, and Sun Java Runtime Environment in JDK and JRE 6, JDK and JRE 5.0 Update 10 and earlier, SDK and JRE 1.4.2_14 and earlier, and SDK and JRE 1.3.1_20 and earlier, allows remote attackers to execute arbitrary code or cause a denial of service (JVM crash) via a crafted JPEG or BMP file that triggers a buffer overflow.
network
sun CWE-189
6.8
2006-12-26 CVE-2006-6737 Information Disclosure vulnerability in SUN Jdk, JRE and SDK
Unspecified vulnerability in Sun Java Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 5 and earlier, Java System Development Kit (SDK) and JRE 1.4.2_10 and earlier 1.4.x versions, and SDK and JRE 1.3.1_18 and earlier allows attackers to use untrusted applets to "access data in other applets," aka "The first issue."
network
sun
4.3