Vulnerabilities > SUN > Critical

DATE CVE VULNERABILITY TITLE RISK
2008-12-05 CVE-2008-5355 Improper Authentication vulnerability in SUN Jdk, JRE and SDK
The "Java Update" feature for Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier does not verify the signature of the JRE that is downloaded, which allows remote attackers to execute arbitrary code via DNS man-in-the-middle attacks.
network
low complexity
sun CWE-287
critical
10.0
2008-12-05 CVE-2008-5354 Buffer Errors vulnerability in SUN Jdk, JRE and SDK
Stack-based buffer overflow in Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier allows locally-launched and possibly remote untrusted Java applications to execute arbitrary code via a JAR file with a long Main-Class manifest entry.
network
sun CWE-119
critical
9.3
2008-12-05 CVE-2008-5353 Multiple Security vulnerability in SUN Jdk, JRE and SDK
The Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier does not properly enforce context of ZoneInfo objects during deserialization, which allows remote attackers to run untrusted applets and applications in a privileged context, as demonstrated by "deserializing Calendar objects".
network
low complexity
sun
critical
10.0
2008-12-05 CVE-2008-5352 Numeric Errors vulnerability in SUN JDK and JRE
Integer overflow in the JAR unpacking utility (unpack200) in the unpack library (unpack.dll) in Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier, and JDK and JRE 5.0 Update 16 and earlier, allows untrusted applications and applets to gain privileges via a Pack200 compressed JAR file that triggers a heap-based buffer overflow.
network
sun CWE-189
critical
9.3
2008-12-05 CVE-2008-5343 Privilege Escalation vulnerability in SUN Jdk, JRE and SDK
Java Web Start (JWS) and Java Plug-in with Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier allows remote attackers to make unauthorized network connections and hijack HTTP sessions via a crafted file that validates as both a GIF and a Java JAR file, aka "GIFAR" and CR 6707535.
network
low complexity
sun
critical
9.0
2008-12-05 CVE-2008-5340 Permissions, Privileges, and Access Controls vulnerability in SUN Jdk, JRE and SDK
Unspecified vulnerability in Java Web Start (JWS) and Java Plug-in with Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier allows untrusted JWS applications to gain privileges to access local files or applications via unknown vectors, aka 6727081.
network
low complexity
sun CWE-264
critical
10.0
2008-12-05 CVE-2008-2086 Code Injection vulnerability in SUN Jdk, JRE and SDK
Sun Java Web Start and Java Plug-in for JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier allow remote attackers to execute arbitrary code via a crafted jnlp file that modifies the (1) java.home, (2) java.ext.dirs, or (3) user.home System Properties, aka "Java Web Start File Inclusion" and CR 6694892.
network
sun CWE-94
critical
9.3
2008-11-10 CVE-2008-5010 Remote Code Execution vulnerability in SUN Opensolaris and Solaris
in.dhcpd in the DHCP implementation in Sun Solaris 8 through 10, and OpenSolaris before snv_103, allows remote attackers to cause a denial of service (assertion failure and daemon exit) via unknown DHCP requests related to the "number of offers," aka Bug ID 6713805.
network
low complexity
sun
critical
10.0
2008-11-04 CVE-2008-4910 Improper Input Validation vulnerability in SUN Java web Start
The BasicService in Sun Java Web Start allows remote attackers to execute arbitrary programs on a client machine via a file:// URL argument to the showDocument method.
network
low complexity
sun CWE-20
critical
10.0
2008-10-23 CVE-2008-4722 Improper Authentication vulnerability in SUN products
Unspecified vulnerability in Sun Integrated Lights-Out Manager (ILOM) 2.0.1.5 through 2.0.4.26 allows remote authenticated users to (1) access the service processor (SP) and cause a denial of service (shutdown or reboot), or (2) access the host operating system and have an unspecified impact, via unknown vectors.
network
low complexity
sun CWE-287
critical
9.0