Vulnerabilities > SUN > SDK > 1.4.2.04

DATE CVE VULNERABILITY TITLE RISK
2008-07-09 CVE-2008-3113 Permissions, Privileges, and Access Controls vulnerability in SUN Jdk, JRE and SDK
Unspecified vulnerability in Sun Java Web Start in JDK and JRE 5.0 before Update 16 and SDK and JRE 1.4.x before 1.4.2_18 allows remote attackers to create or delete arbitrary files via an untrusted application, aka CR 6704077.
network
low complexity
sun CWE-264
critical
10.0
2008-07-09 CVE-2008-3112 Permissions, Privileges, and Access Controls vulnerability in SUN Jdk, JRE and SDK
Directory traversal vulnerability in Sun Java Web Start in JDK and JRE 6 before Update 7, JDK and JRE 5.0 before Update 16, and SDK and JRE 1.4.x before 1.4.2_18 allows remote attackers to create arbitrary files via the writeManifest method in the CacheEntry class, aka CR 6703909.
network
low complexity
sun CWE-264
critical
10.0
2008-07-09 CVE-2008-3111 Improper Input Validation vulnerability in SUN Jdk, JRE and SDK
Multiple buffer overflows in Sun Java Web Start in JDK and JRE 6 before Update 4, JDK and JRE 5.0 before Update 16, and SDK and JRE 1.4.x before 1.4.2_18 allow context-dependent attackers to gain privileges via an untrusted application, as demonstrated by (a) an application that grants itself privileges to (1) read local files, (2) write to local files, or (3) execute local programs; and as demonstrated by (b) a long value associated with a java-vm-args attribute in a j2se tag in a JNLP file, which triggers a stack-based buffer overflow in the GetVMArgsOption function; aka CR 6557220.
network
low complexity
sun CWE-20
critical
10.0
2008-07-09 CVE-2008-3108 Buffer Errors vulnerability in SUN Jdk, JRE and SDK
Buffer overflow in Sun Java Runtime Environment (JRE) in JDK and JRE 5.0 before Update 10, SDK and JRE 1.4.x before 1.4.2_18, and SDK and JRE 1.3.x before 1.3.1_23 allows context-dependent attackers to gain privileges via unspecified vectors related to font processing.
network
low complexity
sun CWE-119
critical
10.0
2008-07-09 CVE-2008-3107 Permissions, Privileges, and Access Controls vulnerability in SUN Jdk, JRE and SDK
Unspecified vulnerability in the Virtual Machine in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 7, JDK and JRE 5.0 before Update 16, and SDK and JRE 1.4.x before 1.4.2_18 allows context-dependent attackers to gain privileges via an untrusted (1) application or (2) applet, as demonstrated by an application or applet that grants itself privileges to (a) read local files, (b) write to local files, or (c) execute local programs.
network
low complexity
sun CWE-264
critical
10.0
2008-07-09 CVE-2008-3104 Permissions, Privileges, and Access Controls vulnerability in SUN Jdk, JRE and SDK
Multiple unspecified vulnerabilities in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 7, JDK and JRE 5.0 before Update 16, SDK and JRE 1.4.x before 1.4.2_18, and SDK and JRE 1.3.x before 1.3.1_23 allow remote attackers to violate the security model for an applet's outbound connections by connecting to localhost services running on the machine that loaded the applet.
network
sun CWE-264
6.8
2008-03-06 CVE-2008-1187 Permissions, Privileges, and Access Controls vulnerability in SUN Jdk, JRE and SDK
Unspecified vulnerability in Sun Java Runtime Environment (JRE) and JDK 6 Update 4 and earlier, 5.0 Update 14 and earlier, and SDK/JRE 1.4.2_16 and earlier allows remote attackers to cause a denial of service (JRE crash) and possibly execute arbitrary code via unknown vectors related to XSLT transforms.
network
sun CWE-264
6.8
2007-10-29 CVE-2007-5689 Remote Privilege Escalation vulnerability in SUN Jdk, JRE and SDK
The Java Virtual Machine (JVM) in Sun Java Runtime Environment (JRE) in SDK and JRE 1.3.x through 1.3.1_20 and 1.4.x through 1.4.2_15, and JDK and JRE 5.x through 5.0 Update 12 and 6.x through 6 Update 2, allows remote attackers to execute arbitrary programs, or read or modify arbitrary files, via applets that grant privileges to themselves.
network
low complexity
sun
critical
10.0
2007-08-17 CVE-2007-4381 Remote Privilege Escalation vulnerability in SUN Jdk, JRE and SDK
Unspecified vulnerability in the font parsing implementation in Sun JDK and JRE 5.0 Update 9 and earlier, and SDK and JRE 1.4.2_14 and earlier, allows remote attackers to perform unauthorized actions via an applet that grants certain privileges to itself.
network
sun
critical
9.3
2007-07-21 CVE-2007-3922 Unspecified vulnerability in SUN Jdk, JRE and SDK
Unspecified vulnerability in the Java Runtime Environment (JRE) Applet Class Loader in Sun JDK and JRE 5.0 Update 11 and earlier, 6 through 6 Update 1, and SDK and JRE 1.4.2_14 and earlier, allows remote attackers to violate the security model for an applet's outbound connections by connecting to certain localhost services running on the machine that loaded the applet.
network
sun
6.8