Sdk
Vendor:
First CVE: Dec 31, 2001 · Active for 24 years
127
Total CVEs
More Total CVEs than 99% of tracked products
12.7
Avg CVEs / Year
Higher CVE frequency than 97% of tracked products
7.4
Avg CVSS
Higher Avg CVSS than 48% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Sdk over time
Volume of CVEsAvg CVSS Base Score
First CVE
Dec 31, 2001
24 years ago
Most Recent CVE
Feb 17, 2011
5,636 days ago
CVE Severity & Scoring
Sdk127 CVEs
40%
56%
All CVEs352,231 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown127 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown127 (100.0%)
User Interaction
None0 (0.0%)
Unknown127 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown127 (100.0%)
Top CVEs
Signals from CVEs in this product scope (127 CVEs).
127 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-5353HIGH The Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier does not properly enforc | Dec 5, 2008 | 10.0 | 88 | NO | YES |
CVE-2009-3867HIGH Stack-based buffer overflow in the HsbParser.getSoundBank function in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3. | Nov 5, 2009 | 9.3 | 86 | NO | YES |
CVE-2010-0842HIGH Unspecified vulnerability in the Sound component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, 1.4.2_25, and 1.3.1_27 allows remote attackers to affect confid | Apr 1, 2010 | 7.5 | 83 | NO | YES |
CVE-2009-3869HIGH Stack-based buffer overflow in the setDiffICM function in the Abstract Window Toolkit (AWT) in Java Runtime Environment (JRE) in Sun Java SE in JDK and JRE 5.0 before Update 22, JD | Nov 5, 2009 | 9.3 | 80 | NO | YES |
CVE-2010-4476MEDIUM The Double.parseDouble method in Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 23 and earlier, 5.0 Update 27 and earlier, and 1.4.2_29 and earlier | Feb 17, 2011 | 5.0 | 41 | NO | YES |
CVE-2007-4381HIGH Unspecified vulnerability in the font parsing implementation in Sun JDK and JRE 5.0 Update 9 and earlier, and SDK and JRE 1.4.2_14 and earlier, allows remote attackers to perform u | Aug 17, 2007 | 9.3 | 40 | NO | YES |
CVE-2007-5019HIGH Buffer overflow in the Sun Java Web Start ActiveX control in Java Runtime Environment (JRE) 1.6.0_X allows remote attackers to have an unknown impact via a long argument to the dns | Sep 20, 2007 | 10.0 | 39 | NO | YES |
CVE-2008-3112HIGH Directory traversal vulnerability in Sun Java Web Start in JDK and JRE 6 before Update 7, JDK and JRE 5.0 before Update 16, and SDK and JRE 1.4.x before 1.4.2_18 allows remote atta | Jul 9, 2008 | 10.0 | 37 | NO | NO |
CVE-2007-2788MEDIUM Integer overflow in the embedded ICC profile image parser in Sun Java Development Kit (JDK) before 1.5.0_11-b03 and 1.6.x before 1.6.0_01-b06, and Sun Java Runtime Environment in J | May 22, 2007 | 6.8 | 37 | NO | YES |
CVE-2010-3571HIGH Unspecified vulnerability in the 2D component in Oracle Java SE and Java for Business 6 Update 21, 5.0 Update 25, 1.4.2_27, and 1.3.1_28 allows remote attackers to affect confident | Oct 19, 2010 | 10.0 | 36 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (127 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
4 CVEs
3.1% of CVEs· 96th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
10 CVEs
7.9% of CVEs· 88th percentile
Social Chatter
Signals from CVEs in this product scope (127 CVEs).
Media Mentions
Signals from CVEs in this product scope (127 CVEs).
Top CNAs Publishing CVEs For Sdk
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 1.5.0_6 | 1 | 6.4 | 12.7% | 0 | 1 |
| 1.5.0_05 | 1 | 7.8 | 2.9% | 0 | 0 |
| 1.5 | 1 | 5.0 | 5.9% | 0 | 0 |
| 1.4.2_9 | 89 | 7.6 | 9.4% | 0 | 6 |
| 1.4.2_8 | 89 | 7.6 | 9.4% | 0 | 6 |
| 1.4.2_7 | 92 | 7.6 | 9.3% | 0 | 6 |
| 1.4.2_6 | 92 | 7.6 | 9.3% | 0 | 6 |
| 1.4.2_5 | 92 | 7.6 | 9.3% | 0 | 6 |
| 1.4.2_4 | 92 | 7.6 | 9.3% | 0 | 6 |
| 1.4.2_3 | 92 | 7.6 | 9.3% | 0 | 6 |
| 1.4.2_28 | 11 | 6.8 | 5.2% | 0 | 1 |
| 1.4.2_27 | 11 | 6.8 | 5.2% | 0 | 1 |
| 1.4.2_26 | 27 | 7.9 | 5.2% | 0 | 1 |
| 1.4.2_25 | 28 | 7.9 | 5.3% | 0 | 1 |
| 1.4.2_24 | 44 | 7.4 | 6.4% | 0 | 2 |
| 1.4.2_23 | 47 | 7.2 | 6.3% | 0 | 2 |
| 1.4.2_22 | 54 | 7.7 | 10.3% | 0 | 4 |
| 1.4.2_21 | 54 | 7.7 | 10.3% | 0 | 4 |
| 1.4.2_20 | 55 | 7.7 | 10.2% | 0 | 4 |
| 1.4.2_2 | 48 | 7.8 | 11.6% | 0 | 4 |