Vulnerabilities > SUN

DATE CVE VULNERABILITY TITLE RISK
2009-03-25 CVE-2009-1101 Multiple Security vulnerability in SUN JDK and JRE
Unspecified vulnerability in the lightweight HTTP server implementation in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 6 Update 12 and earlier allows remote attackers to cause a denial of service (probably resource consumption) for a JAX-WS service endpoint via a connection without any data, which triggers a file descriptor "leak."
network
low complexity
sun
5.0
2009-03-25 CVE-2009-1100 Multiple Security vulnerability in SUN JDK and JRE
Multiple unspecified vulnerabilities in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 17 and earlier, and 6 Update 12 and earlier, allow remote attackers to cause a denial of service (disk consumption) via vectors related to temporary font files and (1) "limits on Font creation," aka CR 6522586, and (2) another unspecified vector, aka CR 6632886.
network
low complexity
sun
5.0
2009-03-25 CVE-2009-1099 Numeric Errors vulnerability in SUN Java Runtime Environment and Java SE Development KIT
Integer signedness error in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 17 and earlier, and 6 Update 12 and earlier, allows remote attackers to access files or execute arbitrary code via crafted glyph descriptions in a Type1 font, which bypasses a signed comparison and triggers a buffer overflow.
network
low complexity
sun CWE-189
7.5
2009-03-25 CVE-2009-1098 Buffer Errors vulnerability in SUN Jdk, JRE and SDK
Buffer overflow in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 17 and earlier; 6 Update 12 and earlier; 1.4.2_19 and earlier; and 1.3.1_24 and earlier allows remote attackers to access files or execute arbitrary code via a crafted GIF image, aka CR 6804998.
network
sun CWE-119
critical
9.3
2009-03-25 CVE-2009-1097 Buffer Errors vulnerability in SUN JDK and JRE
Multiple buffer overflows in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 6 Update 12 and earlier allow remote attackers to access files or execute arbitrary code via (1) a crafted PNG image that triggers an integer overflow during memory allocation for display on the splash screen, aka CR 6804996; and (2) a crafted GIF image from which unspecified values are used in calculation of offsets, leading to object-pointer corruption, aka CR 6804997.
network
sun CWE-119
critical
9.3
2009-03-25 CVE-2009-1096 Buffer Errors vulnerability in SUN JDK and JRE
Buffer overflow in unpack200 in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 17 and earlier, and 6 Update 12 and earlier, allows remote attackers to access files or execute arbitrary code via a JAR file with crafted Pack200 headers.
network
low complexity
sun CWE-119
critical
10.0
2009-03-25 CVE-2009-1095 Numeric Errors vulnerability in SUN JDK and JRE
Integer overflow in unpack200 in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 17 and earlier, and 6 Update 12 and earlier, allows remote attackers to access files or execute arbitrary code via a JAR file with crafted Pack200 headers.
network
low complexity
sun CWE-189
critical
10.0
2009-03-25 CVE-2009-1094 Multiple Security vulnerability in SUN Jdk, JRE and SDK
Unspecified vulnerability in the LDAP implementation in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 17 and earlier; 6 Update 12 and earlier; SDK and JRE 1.3.1_24 and earlier; and 1.4.2_19 and earlier allows remote LDAP servers to execute arbitrary code via unknown vectors related to serialized data.
network
low complexity
sun
critical
10.0
2009-03-25 CVE-2009-1093 Configuration vulnerability in SUN Jdk, JRE and SDK
LdapCtx in the LDAP service in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 17 and earlier; 6 Update 12 and earlier; SDK and JRE 1.3.1_24 and earlier; and 1.4.2_19 and earlier does not close the connection when initialization fails, which allows remote attackers to cause a denial of service (LDAP service hang).
network
low complexity
sun CWE-16
5.0
2009-03-25 CVE-2009-1084 Permissions, Privileges, and Access Controls vulnerability in SUN Java System Identity Manager
Sun Java System Identity Manager (IdM) 7.0 through 8.0 does not properly restrict access to the System Configuration object, which allows remote authenticated administrators and possibly remote attackers to have an unspecified impact by modifying this object.
network
low complexity
sun CWE-264
6.4