Sun

Openjdk

16 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.49%
  • Published 09.11.2009 19:30:00
  • Last modified 09.04.2025 00:30:58

Directory traversal vulnerability in the ICC_Profile.getInstance method in Java Runtime Environment (JRE) in Sun Java SE 5.0 before Update 22 and 6 before Update 17, and OpenJDK, allows remote attackers to determine the existence of local Internation...

  • EPSS 0.26%
  • Published 09.11.2009 19:30:00
  • Last modified 09.04.2025 00:30:58

Multiple unspecified vulnerabilities in the (1) X11 and (2) Win32GraphicsDevice subsystems in Sun Java SE 5.0 before Update 22 and 6 before Update 17, and OpenJDK, have unknown impact and attack vectors, related to failure to clone arrays that are re...

  • EPSS 0.48%
  • Published 09.11.2009 19:30:00
  • Last modified 09.04.2025 00:30:58

The Abstract Window Toolkit (AWT) in Java Runtime Environment (JRE) in Sun Java SE 5.0 before Update 22 and 6 before Update 17, and OpenJDK, does not properly restrict the objects that may be sent to loggers, which allows attackers to obtain sensitiv...

  • EPSS 1.28%
  • Published 09.11.2009 19:30:00
  • Last modified 09.04.2025 00:30:58

Sun Java SE 5.0 before Update 22 and 6 before Update 17, and OpenJDK, does not prevent the existence of children of a resurrected ClassLoader, which allows remote attackers to gain privileges via unspecified vectors, related to an "information leak v...

  • EPSS 0.66%
  • Published 09.11.2009 19:30:00
  • Last modified 09.04.2025 00:30:58

Multiple unspecified vulnerabilities in the Swing implementation in Sun Java SE 5.0 before Update 22 and 6 before Update 17, and OpenJDK, have unknown impact and remote attack vectors, related to "information leaks in mutable variables," aka Bug Id 6...

  • EPSS 0.66%
  • Published 09.11.2009 19:30:00
  • Last modified 09.04.2025 00:30:58

Multiple unspecified vulnerabilities in the Windows Pluggable Look and Feel (PL&F) feature in the Swing implementation in Sun Java SE 5.0 before Update 22 and 6 before Update 17, and OpenJDK, have unknown impact and remote attack vectors, related to ...

  • EPSS 1.35%
  • Published 09.11.2009 19:30:00
  • Last modified 09.04.2025 00:30:58

The TimeZone.getTimeZone method in Sun Java SE 5.0 before Update 22 and 6 before Update 17, and OpenJDK, allows remote attackers to determine the existence of local files via vectors related to handling of zoneinfo (aka tz) files, aka Bug Id 6824265.

  • EPSS 1.08%
  • Published 10.08.2009 18:30:00
  • Last modified 09.04.2025 00:30:58

The Java Web Start framework in IcedTea in OpenJDK before 1.6.0.0-20.b16.fc10 on Fedora 10, and before 1.6.0.0-27.b16.fc11 on Fedora 11, trusts an entire application when at least one of the listed jar files is trusted, which allows context-dependent...

  • EPSS 0.7%
  • Published 10.08.2009 18:30:00
  • Last modified 09.04.2025 00:30:58

Sun Java SE 5.0 before Update 20 and 6 before Update 15, and OpenJDK, might allow context-dependent attackers to obtain sensitive information via vectors involving static variables that are declared without the final keyword, related to (1) LayoutQue...

  • EPSS 1.83%
  • Published 10.08.2009 18:30:00
  • Last modified 09.04.2025 00:30:58

The Java Management Extensions (JMX) implementation in Sun Java SE 6 before Update 15, and OpenJDK, does not properly enforce OpenType checks, which allows context-dependent attackers to bypass intended access restrictions by leveraging finalizer res...