Sdk

Vendor:

First CVE: Dec 31, 2001 · Active for 24 years

127
Total CVEs
More Total CVEs than 99% of tracked products
12.7
Avg CVEs / Year
Higher CVE frequency than 97% of tracked products
7.4
Avg CVSS
Higher Avg CVSS than 48% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Sdk over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 31, 2001
24 years ago
Most Recent CVE
Feb 17, 2011
5,636 days ago

CVE Severity & Scoring

Sdk127 CVEs
All CVEs352,231 CVEs
LowMediumHigh
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown127 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown127 (100.0%)
User Interaction
None0 (0.0%)
Unknown127 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown127 (100.0%)

Top CVEs

Signals from CVEs in this product scope (127 CVEs).

127 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
The Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier does not properly enforc
Dec 5, 200810.088NOYES
Stack-based buffer overflow in the HsbParser.getSoundBank function in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.
Nov 5, 20099.386NOYES
Unspecified vulnerability in the Sound component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, 1.4.2_25, and 1.3.1_27 allows remote attackers to affect confid
Apr 1, 20107.583NOYES
Stack-based buffer overflow in the setDiffICM function in the Abstract Window Toolkit (AWT) in Java Runtime Environment (JRE) in Sun Java SE in JDK and JRE 5.0 before Update 22, JD
Nov 5, 20099.380NOYES
The Double.parseDouble method in Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 23 and earlier, 5.0 Update 27 and earlier, and 1.4.2_29 and earlier
Feb 17, 20115.041NOYES
Unspecified vulnerability in the font parsing implementation in Sun JDK and JRE 5.0 Update 9 and earlier, and SDK and JRE 1.4.2_14 and earlier, allows remote attackers to perform u
Aug 17, 20079.340NOYES
Buffer overflow in the Sun Java Web Start ActiveX control in Java Runtime Environment (JRE) 1.6.0_X allows remote attackers to have an unknown impact via a long argument to the dns
Sep 20, 200710.039NOYES
Directory traversal vulnerability in Sun Java Web Start in JDK and JRE 6 before Update 7, JDK and JRE 5.0 before Update 16, and SDK and JRE 1.4.x before 1.4.2_18 allows remote atta
Jul 9, 200810.037NONO
Integer overflow in the embedded ICC profile image parser in Sun Java Development Kit (JDK) before 1.5.0_11-b03 and 1.6.x before 1.6.0_01-b06, and Sun Java Runtime Environment in J
May 22, 20076.837NOYES
Unspecified vulnerability in the 2D component in Oracle Java SE and Java for Business 6 Update 21, 5.0 Update 25, 1.4.2_27, and 1.3.1_28 allows remote attackers to affect confident
Oct 19, 201010.036NONO

Exploit Exposure

Signals from CVEs in this product scope (127 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
4 CVEs
3.1% of CVEs· 96th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
10 CVEs
7.9% of CVEs· 88th percentile

Social Chatter

Signals from CVEs in this product scope (127 CVEs).

Media Mentions

Signals from CVEs in this product scope (127 CVEs).

Top CNAs Publishing CVEs For Sdk

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
1.5.0_616.412.7%01
1.5.0_0517.82.9%00
1.515.05.9%00
1.4.2_9897.69.4%06
1.4.2_8897.69.4%06
1.4.2_7927.69.3%06
1.4.2_6927.69.3%06
1.4.2_5927.69.3%06
1.4.2_4927.69.3%06
1.4.2_3927.69.3%06
1.4.2_28116.85.2%01
1.4.2_27116.85.2%01
1.4.2_26277.95.2%01
1.4.2_25287.95.3%01
1.4.2_24447.46.4%02
1.4.2_23477.26.3%02
1.4.2_22547.710.3%04
1.4.2_21547.710.3%04
1.4.2_20557.710.2%04
1.4.2_2487.811.6%04