Vulnerabilities > SUN > SDK

DATE CVE VULNERABILITY TITLE RISK
2007-10-06 CVE-2007-5240 Unspecified vulnerability in SUN Jdk, JRE and SDK
Visual truncation vulnerability in the Java Runtime Environment in Sun JDK and JRE 6 Update 2 and earlier, JDK and JRE 5.0 Update 12 and earlier, SDK and JRE 1.4.2_15 and earlier, and SDK and JRE 1.3.1_20 and earlier allows remote attackers to circumvent display of the untrusted-code warning banner by creating a window larger than the workstation screen.
network
low complexity
sun
5.0
2007-10-06 CVE-2007-5239 Permissions, Privileges, and Access Controls vulnerability in SUN Jdk, JRE and SDK
Java Web Start in Sun JDK and JRE 6 Update 2 and earlier, JDK and JRE 5.0 Update 12 and earlier, SDK and JRE 1.4.2_15 and earlier, and SDK and JRE 1.3.1_20 and earlier does not properly enforce access restrictions for untrusted (1) applications and (2) applets, which allows user-assisted remote attackers to copy or rename arbitrary files when local users perform drag-and-drop operations from the untrusted application or applet window onto certain types of desktop applications.
network
high complexity
sun CWE-264
4.0
2007-10-06 CVE-2007-5238 Permissions, Privileges, and Access Controls vulnerability in SUN Jdk, JRE and SDK
Java Web Start in Sun JDK and JRE 6 Update 2 and earlier, JDK and JRE 5.0 Update 12 and earlier, and SDK and JRE 1.4.2_15 and earlier does not properly enforce access restrictions for untrusted applications, which allows user-assisted remote attackers to obtain sensitive information (the Java Web Start cache location) via an untrusted application, aka "three vulnerabilities."
network
high complexity
sun CWE-264
2.6
2007-10-06 CVE-2007-5236 Permissions, Privileges, and Access Controls vulnerability in SUN Jdk, JRE and SDK
Java Web Start in Sun JDK and JRE 5.0 Update 12 and earlier, and SDK and JRE 1.4.2_15 and earlier, on Windows does not properly enforce access restrictions for untrusted applications, which allows user-assisted remote attackers to read local files via an untrusted application.
network
high complexity
sun CWE-264
5.4
2007-10-05 CVE-2007-5232 Unspecified vulnerability in SUN Jdk, JRE and SDK
Sun Java Runtime Environment (JRE) in JDK and JRE 6 Update 2 and earlier, JDK and JRE 5.0 Update 12 and earlier, SDK and JRE 1.4.2_15 and earlier, and SDK and JRE 1.3.1_20 and earlier, when applet caching is enabled, allows remote attackers to violate the security model for an applet's outbound connections via a DNS rebinding attack.
network
high complexity
sun
4.0
2007-09-20 CVE-2007-5019 Buffer Errors vulnerability in SUN Java web Start, JRE and SDK
Buffer overflow in the Sun Java Web Start ActiveX control in Java Runtime Environment (JRE) 1.6.0_X allows remote attackers to have an unknown impact via a long argument to the dnsResolve (isInstalled.dnsResolve) method.
network
low complexity
sun CWE-119
critical
10.0
2007-08-17 CVE-2007-4381 Remote Privilege Escalation vulnerability in SUN Jdk, JRE and SDK
Unspecified vulnerability in the font parsing implementation in Sun JDK and JRE 5.0 Update 9 and earlier, and SDK and JRE 1.4.2_14 and earlier, allows remote attackers to perform unauthorized actions via an applet that grants certain privileges to itself.
network
sun
critical
9.3
2007-07-21 CVE-2007-3922 Unspecified vulnerability in SUN Jdk, JRE and SDK
Unspecified vulnerability in the Java Runtime Environment (JRE) Applet Class Loader in Sun JDK and JRE 5.0 Update 11 and earlier, 6 through 6 Update 1, and SDK and JRE 1.4.2_14 and earlier, allows remote attackers to violate the security model for an applet's outbound connections by connecting to certain localhost services running on the machine that loaded the applet.
network
sun
6.8
2007-07-11 CVE-2007-3698 Denial Of Service vulnerability in SUN Jdk, JRE and SDK
The Java Secure Socket Extension (JSSE) in Sun JDK and JRE 6 Update 1 and earlier, JDK and JRE 5.0 Updates 7 through 11, and SDK and JRE 1.4.2_11 through 1.4.2_14, when using JSSE for SSL/TLS support, allows remote attackers to cause a denial of service (CPU consumption) via certain SSL/TLS handshake requests.
network
low complexity
sun
7.8
2007-06-30 CVE-2007-3504 Path Traversal vulnerability in SUN Jdk, JRE and SDK
Directory traversal vulnerability in the PersistenceService in Sun Java Web Start in JDK and JRE 5.0 Update 11 and earlier, and Java Web Start in SDK and JRE 1.4.2_13 and earlier, for Windows allows remote attackers to perform unauthorized actions via an application that grants file overwrite privileges to itself.
network
microsoft sun CWE-22
critical
9.3