Sun

Openjdk

16 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 7.93%
  • Published 10.08.2009 18:30:00
  • Last modified 09.04.2025 00:30:58

JDK13Services.getProviders in Sun Java SE 5.0 before Update 20 and 6 before Update 15, and OpenJDK, grants full privileges to instances of unspecified object types, which allows context-dependent attackers to bypass intended access restrictions via a...

  • EPSS 4.37%
  • Published 10.08.2009 18:30:00
  • Last modified 09.04.2025 00:30:58

The encoder in Sun Java SE 6 before Update 15, and OpenJDK, grants read access to private variables with unspecified names, which allows context-dependent attackers to obtain sensitive information via an untrusted (1) applet or (2) application.

  • EPSS 1.88%
  • Published 13.04.2009 16:30:00
  • Last modified 09.04.2025 00:30:58

Integer overflow in the PulseAudioTargetDataL class in src/java/org/classpath/icedtea/pulseaudio/PulseAudioTargetDataLine.java in Pulse-Java, as used in OpenJDK 1.6.0.0 and other products, allows remote attackers to cause a denial of service (applet ...

  • EPSS 10.61%
  • Published 09.04.2009 15:08:35
  • Last modified 09.04.2025 00:30:58

cmsxform.c in LittleCMS (aka lcms or liblcms) 1.18, as used in OpenJDK and other products, allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted image that triggers execution of incorrect ...

Exploit
  • EPSS 0.95%
  • Published 23.03.2009 14:19:12
  • Last modified 09.04.2025 00:30:58

Multiple integer overflows in LittleCMS (aka lcms or liblcms) before 1.18beta2, as used in Firefox 3.1beta, OpenJDK, and GIMP, allow context-dependent attackers to execute arbitrary code via a crafted image file that triggers a heap-based buffer over...

Exploit
  • EPSS 1.74%
  • Published 23.03.2009 14:19:12
  • Last modified 09.04.2025 00:30:58

Multiple stack-based buffer overflows in the ReadSetOfCurves function in LittleCMS (aka lcms or liblcms) before 1.18beta2, as used in Firefox 3.1beta, OpenJDK, and GIMP, allow context-dependent attackers to execute arbitrary code via a crafted image ...