Sun's vulnerability footprint spans a substantial historical portfolio centered on operating systems, Java runtime environments, and development kits that have been deeply embedded across enterprise infrastructure, servers, and client deployments. The vendor's disclosures frequently acquire public exploit code, reflecting both the widespread reach of products such as Solaris, SunOS, and the Java Runtime Environment and the long operational lifespans of many affected systems. The recurring weakness classes center on memory-safety issues including buffer-boundary violations, input-validation and neutralization flaws in web-facing contexts, and a significant share of NVD placeholder classifications that reflect the age and documentation gaps in some of these disclosures. Defenders should prioritize inventory of legacy Sun systems still in operation and treat Java runtime updates as broadly applicable across the enterprise; live severity, exploitation activity, and current CVE counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Sun over time
Signals from CVEs in this vendor scope (1711 CVEs).
1,711 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2013-2465CRITICAL Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier, and Ope | Jun 18, 2013 | 9.8 | 98 | YES | YES |
CVE-2012-0507CRITICAL Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, and 5.0 Update 33 and earlier allows re | Jun 7, 2012 | 9.8 | 98 | YES | YES |
CVE-2007-0882HIGH Argument injection vulnerability in the telnet daemon (in.telnetd) in Solaris 10 and 11 (SunOS 5.10 and 5.11) misinterprets certain client "-f" sequences as valid requests for the | Feb 12, 2007 | 10.0 | 91 | NO | YES |
CVE-2011-2140HIGH Adobe Flash Player before 10.3.183.5 on Windows, Mac OS X, Linux, and Solaris and before 10.3.186.3 on Android, and Adobe AIR before 2.7.1 on Windows and Mac OS X and before 2.7.1. | Aug 10, 2011 | 10.0 | 90 | NO | YES |
CVE-2013-1493HIGH The color management (CMM) functionality in the 2D component in Oracle Java SE 7 Update 15 and earlier, 6 Update 41 and earlier, and 5.0 Update 40 and earlier allows remote attacke | Mar 5, 2013 | 10.0 | 89 | NO | YES |
CVE-2011-2110HIGH Adobe Flash Player before 10.3.181.26 on Windows, Mac OS X, Linux, and Solaris, and 10.3.185.23 and earlier on Android, allows remote attackers to execute arbitrary code or cause a | Jun 16, 2011 | 10.0 | 89 | NO | YES |
CVE-2010-3563HIGH Unspecified vulnerability in the Deployment component in Oracle Java SE and Java for Business 6 Update 21 allows remote attackers to affect confidentiality, integrity, and availabi | Oct 19, 2010 | 10.0 | 89 | NO | YES |
CVE-2010-4452HIGH Unspecified vulnerability in the Deployment component in Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 23 and earlier allows remote untrusted Java | Feb 17, 2011 | 10.0 | 88 | NO | YES |
CVE-2010-3552HIGH Unspecified vulnerability in the New Java Plug-in component in Oracle Java SE and Java for Business 6 Update 21 allows remote attackers to affect confidentiality, integrity, and av | Oct 19, 2010 | 10.0 | 88 | NO | YES |
CVE-2008-5353HIGH The Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier does not properly enforc | Dec 5, 2008 | 10.0 | 88 | NO | YES |
Signals from CVEs in this vendor scope (1711 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Sun.
Media articles that mention a CVE ID that affects a product developed by Sun — matched by CVE ID, not by vendor name.