Vulnerabilities > SUN > SDK > 1.4.2.10

DATE CVE VULNERABILITY TITLE RISK
2008-12-05 CVE-2008-5359 Buffer Errors vulnerability in SUN Jdk, JRE and SDK
Buffer overflow in Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; SDK and JRE 1.4.2_18 and earlier; and SDK and JRE 1.3.1_23 and earlier might allow remote attackers to execute arbitrary code, related to a ConvolveOp operation in the Java AWT library.
network
sun CWE-119
critical
9.3
2008-12-05 CVE-2008-5357 Numeric Errors vulnerability in SUN Jdk, JRE and SDK
Integer overflow in Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; SDK and JRE 1.4.2_18 and earlier; and SDK and JRE 1.3.1_23 and earlier might allow remote attackers to execute arbitrary code via a crafted TrueType font file, which triggers a heap-based buffer overflow.
network
sun CWE-189
critical
9.3
2008-12-05 CVE-2008-5356 Buffer Errors vulnerability in SUN Jdk, JRE and SDK
Heap-based buffer overflow in Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier might allow remote attackers to execute arbitrary code via a crafted TrueType font file.
network
sun CWE-119
critical
9.3
2008-12-05 CVE-2008-5355 Improper Authentication vulnerability in SUN Jdk, JRE and SDK
The "Java Update" feature for Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier does not verify the signature of the JRE that is downloaded, which allows remote attackers to execute arbitrary code via DNS man-in-the-middle attacks.
network
low complexity
sun CWE-287
critical
10.0
2008-12-05 CVE-2008-5354 Buffer Errors vulnerability in SUN Jdk, JRE and SDK
Stack-based buffer overflow in Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier allows locally-launched and possibly remote untrusted Java applications to execute arbitrary code via a JAR file with a long Main-Class manifest entry.
network
sun CWE-119
critical
9.3
2008-12-05 CVE-2008-5353 Multiple Security vulnerability in SUN Jdk, JRE and SDK
The Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier does not properly enforce context of ZoneInfo objects during deserialization, which allows remote attackers to run untrusted applets and applications in a privileged context, as demonstrated by "deserializing Calendar objects".
network
low complexity
sun
critical
10.0
2008-12-05 CVE-2008-5351 Permissions, Privileges, and Access Controls vulnerability in SUN Jdk, JRE and SDK
Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier accepts UTF-8 encodings that are not the "shortest" form, which makes it easier for attackers to bypass protection mechanisms for other applications that rely on shortest-form UTF-8 encodings.
network
low complexity
sun CWE-264
7.5
2008-12-05 CVE-2008-5350 Information Exposure vulnerability in SUN Jdk, JRE and SDK
Unspecified vulnerability in Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier allows untrusted applications and applets to list the contents of the operating user's directory via unknown vectors.
network
low complexity
sun CWE-200
5.0
2008-12-05 CVE-2008-5348 Multiple Security vulnerability in SUN Jdk, JRE and SDK
Unspecified vulnerability in Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier, when using Kerberos authentication, allows remote attackers to cause a denial of service (OS resource consumption) via unknown vectors.
network
sun
7.1
2008-12-05 CVE-2008-5346 Information Exposure vulnerability in SUN Jdk, JRE and SDK
Unspecified vulnerability in Java Runtime Environment (JRE) for Sun JDK and JRE 5.0 Update 16 and earlier; SDK and JRE 1.4.2_18 and earlier; and SDK and JRE 1.3.1_23 or earlier allows untrusted applets and applications to read arbitrary memory via a crafted ZIP file.
network
sun CWE-200
7.1