CVE-2005-3905
- EPSS 11.51%
- Veröffentlicht 30.11.2005 11:03:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Unspecified vulnerability in reflection APIs in Java SDK and JRE 1.3.1_15 and earlier, 1.4.2_08 and earlier, and JDK and JRE 5.0 Update 3 and earlier allows remote attackers to escape the Java sandbox and access arbitrary files or execute arbitrary a...
CVE-2005-3906
- EPSS 11.51%
- Veröffentlicht 30.11.2005 11:03:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Multiple unspecified vulnerabilities in reflection APIs in Java SDK and JRE 1.4.2_08 and earlier and JDK and JRE 5.0 Update 3 and earlier allow remote attackers to escape the Java sandbox and access arbitrary files or execute arbitrary applications v...
CVE-2005-3907
- EPSS 8.02%
- Veröffentlicht 30.11.2005 11:03:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Unspecified vulnerability in Java Runtime Environment in Java JDK and JRE 5.0 Update 3 and earlier allows remote attackers to escape the Java sandbox and access arbitrary files or execute arbitrary applications via unknown attack vectors involving un...
- EPSS 1.4%
- Veröffentlicht 14.03.2005 05:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Sun Java JRE 1.1.x through 1.4.x writes temporary files with long filenames that become predictable on a file system that uses 8.3 style short names, which allows remote attackers to write arbitrary files to known locations and facilitates the exploi...
CVE-2004-1029
- EPSS 42.56%
- Veröffentlicht 01.03.2005 05:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
The Sun Java Plugin capability in Java 2 Runtime Environment (JRE) 1.4.2_01, 1.4.2_04, and possibly earlier versions, does not properly restrict access between Javascript and Java applets during data transfer, which allows remote attackers to load un...
- EPSS 0.93%
- Veröffentlicht 31.12.2004 05:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
readObject in (1) Java Runtime Environment (JRE) and (2) Software Development Kit (SDK) 1.4.0 through 1.4.2_05 allows remote attackers to cause a denial of service (JVM unresponsive) via crafted serialized data.
CVE-2003-1123
- EPSS 14.56%
- Veröffentlicht 31.12.2003 05:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Sun Java Runtime Environment (JRE) and SDK 1.4.0_01 and earlier allows untrusted applets to access certain information within trusted applets, which allows attackers to bypass the restrictions of the Java security model.
CVE-2003-1156
- EPSS 0.06%
- Veröffentlicht 31.12.2003 05:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Java Runtime Environment (JRE) and Software Development Kit (SDK) 1.4.2 through 1.4.2_02 allows local users to overwrite arbitrary files via a symlink attack on (1) unpack.log, as created by the unpack program, or (2) .mailcap1 and .mime.types1, as c...
CVE-2002-0076
- EPSS 1.08%
- Veröffentlicht 19.03.2002 05:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Java Runtime Environment (JRE) Bytecode Verifier allows remote attackers to escape the Java sandbox and execute commands via an applet containing an illegal cast operation, as seen in (1) Microsoft VM build 3802 and earlier as used in Internet Explor...
- EPSS 2.81%
- Veröffentlicht 15.03.2002 05:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Vulnerability in Java Runtime Environment (JRE) allows remote malicious web sites to hijack or sniff a web client's sessions, when an HTTP proxy is being used, via a Java applet that redirects the session to another server, as seen in (1) Netscape 6....