sdk software vulnerabilities
vulnerabilities.aspcode.net
Searching sdk software vulnerabilities
Java Runtime Environment (JRE) and SDK 1.2 thro
Environment
|
Runtime
|
Java
|
Java Runtime Environment (JRE) and SDK 1.2 through 1.3.0_04 allows untrusted applets to access the system clipboard.
Heap-based buffer overflow in VBE.DLL and VBE6.
Applications
|
Heap-based
|
Microsoft
|
overflow
|
VBE6DLL
|
buffer
|
Visual
|
VBEDLL
|
Basic
|
Heap-based buffer overflow in VBE.DLL and VBE6.DLL of Microsoft Visual Basic for Applications (VBA) SDK 5.0 through 6.3 allows remote attackers to execute arbitrary code via a document with a long ID parameter.
The loadClass method of the sun.applet.AppletCl
sunappletAppletClassLoader
|
loadClass
|
Virtual
|
Machine
|
method
|
class
|
Java
|
The loadClass method of the sun.applet.AppletClassLoader class in the Java Virtual Machine (JVM) in Sun SDK and JRE 1.4.1_03 and earlier allows remote attackers to bypass sandbox restrictions and execute arbitrary code via a loaded class name that contains "/" (slash) instead of "." (dot) characters, which bypasses a call to the Security Manager's checkPackageAccess method.
Sun Java Runtime Environment (JRE) and SDK 1.4.
Environment
|
Runtime
|
Java
|
Sun
|
Sun Java Runtime Environment (JRE) and SDK 1.4.0_01 and earlier allows untrusted applets to access certain information within trusted applets, which allows attackers to bypass the restrictions of the Java security model.
Java Runtime Environment (JRE) and Software Dev
Environment
|
Runtime
|
Java
|
Java Runtime Environment (JRE) and Software Development Kit (SDK) 1.4.2 through 1.4.2_02 allows local users to overwrite arbitrary files via a symlink attack on (1) unpack.log, as created by the unpack program, or (2) .mailcap1 and .mime.types1, as created by the RPM program.
X509TrustManager in (1) Java Secure Socket Exte
X509TrustManager
|
X509TrustManager in (1) Java Secure Socket Extension (JSSE) in SDK and JRE 1.4.0 through 1.4.0_01, (2) JSSE before 1.0.3, (3) Java Plug-in SDK and JRE 1.3.0 through 1.4.1, and (4) Java Web Start 1.0 through 1.2 incorrectly calls the isClientTrusted method when determining server trust, which results in improper validation of digital certificate and allows remote attackers to (1) falsely authenticate peers for SSL or (2) incorrectly validate signed JAR files.
readObject in (1) Java Runtime Environment (JRE
readObject
|
readObject in (1) Java Runtime Environment (JRE) and (2) Software Development Kit (SDK) 1.4.0 through 1.4.2_05 allows remote attackers to cause a denial of service (JVM unresponsive) via crafted serialized data.
The Software Development Kit (SDK) and Run Time
Development
|
Software
|
Kit
|
The Software Development Kit (SDK) and Run Time Environment (RTE) 1.4.1 and 1.4.2 for Tru64 UNIX allows remote attackers to cause a denial of service (Java Virtual Machine hang) via object deserialization.
Directory traversal vulnerability in the Java A
vulnerability
|
Directory
|
traversal
|
Archive
|
Tool
|
Java
|
Directory traversal vulnerability in the Java Archive Tool (Jar) utility in J2SE SDK 1.4.2, 1.5 allows remote attackersto write arbitrary files via a .. (dot dot) in filenames in a .jar file.
GameSpy SDK CD-Key Validation Toolkit, as used
Validation
|
attackers
|
command
|
sending
|
spoofed
|
GameSpy
|
Toolkit
|
bypass
|
longer
|
server
|
\disc\
|
CD-Key
|
online
|
remote
|
allows
|
which
|
tells
|
games
|
many
|
used
|
use
|
key
|
SDK
|
GameSpy SDK CD-Key Validation Toolkit, as used by many online games, allows remote attackers to bypass the CD key validation by sending a spoofed \disc\ command, which tells the server the CD key is no longer in use.
Unspecified vulnerability in Sun Java Developme
vulnerability
|
Development
|
Unspecified
|
Java
|
Kit
|
Sun
|
Unspecified vulnerability in Sun Java Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 6 and earlier, Java System Development Kit (SDK) and JRE 1.4.2_12 and earlier 1.4.x versions, and SDK and JRE 1.3.1_18 and earlier allows attackers to attackers to use untrusted applets to "access data in other applets," aka "The second issue."
Unspecified vulnerability in Sun Java Developme
vulnerability
|
Development
|
Unspecified
|
Java
|
Kit
|
Sun
|
Unspecified vulnerability in Sun Java Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 5 and earlier, Java System Development Kit (SDK) and JRE 1.4.2_10 and earlier 1.4.x versions, and SDK and JRE 1.3.1_18 and earlier allows attackers to use untrusted applets to "access data in other applets," aka "The first issue."
Buffer overflow in Sun JDK and Java Runtime Env
Environment
|
overflow
|
Runtime
|
Buffer
|
Java
|
Sun
|
JDK
|
Buffer overflow in Sun JDK and Java Runtime Environment (JRE) 5.0 Update 9 and earlier, SDK and JRE 1.4.2_12 and earlier, and SDK and JRE 1.3.1_18 and earlier allows applets to gain privileges via a GIF image with a block with a 0 width field, which triggers memory corruption.
Buffer overflow in the image parsing implementa
implementation
|
applications
|
Environment
|
themselves
|
privileges
|
arbitrary
|
attackers
|
overflow
|
programs
|
execute
|
earlier
|
applets
|
parsing
|
Runtime
|
remote
|
modify
|
allows
|
Buffer
|
Update
|
131_20
|
142_14
|
grant
|
files
|
image
|
Java
|
read
|
Sun
|
JRE
|
SDK
|
via
|
JDK
|
Buffer overflow in the image parsing implementation in the Sun Java Runtime Environment in JDK and JRE 6, JDK and JRE 5.0 Update 10 and earlier, SDK and JRE 1.4.2_14 and earlier, and SDK and JRE 1.3.1_20 and earlier allows remote attackers to execute arbitrary programs, or read or modify arbitrary files, via applets or applications that grant privileges to themselves.
Unspecified vulnerability in the Sun Java Runti
vulnerability
|
Environment
|
Unspecified
|
attackers
|
earlier
|
service
|
Runtime
|
131_19
|
allows
|
denial
|
remote
|
142_14
|
Update
|
cause
|
Java
|
JDK
|
Sun
|
JRE
|
SDK
|
Unspecified vulnerability in the Sun Java Runtime Environment in JDK and JRE 6, JDK and JRE 5.0 Update 10 and earlier, SDK and JRE 1.4.2_14 and earlier, and SDK and JRE 1.3.1_19 and earlier allows remote attackers to cause a denial of service (JVM hang) via certain untrusted applets or applications.
Buffer overflow in the GetWebStoreURL function
eSellerateControl365dll
|
GetWebStoreURL
|
function
|
overflow
|
control
|
ActiveX
|
certain
|
Buffer
|
Buffer overflow in the GetWebStoreURL function in a certain ActiveX control in eSellerateControl365.dll 3.6.5.0 in eSellerate SDK allows user-assisted remote attackers to execute arbitrary code via a long first argument.
Unspecified vulnerability in the font parsing i
implementation
|
vulnerability
|
unauthorized
|
Unspecified
|
privileges
|
attackers
|
earlier
|
actions
|
perform
|
certain
|
parsing
|
itself
|
applet
|
grants
|
142_14
|
Update
|
remote
|
allows
|
font
|
JDK
|
Sun
|
SDK
|
via
|
JRE
|
Unspecified vulnerability in the font parsing implementation in Sun JDK and JRE 5.0 Update 9 and earlier, and SDK and JRE 1.4.2_14 and earlier, allows remote attackers to perform unauthorized actions via an applet that grants certain privileges to itself.
Sun Java Runtime Environment (JRE) in JDK and J
Environment
|
Runtime
|
Java
|
Sun
|
Sun Java Runtime Environment (JRE) in JDK and JRE 6 Update 2 and earlier, JDK and JRE 5.0 Update 12 and earlier, SDK and JRE 1.4.2_15 and earlier, and SDK and JRE 1.3.1_20 and earlier, when applet caching is enabled, allows remote attackers to violate the security model for an applet's outbound connections via a DNS rebinding attack.
Java Web Start in Sun JDK and JRE 6 Update 2 an
restrictions
|
untrusted
|
properly
|
enforce
|
earlier
|
131_20
|
142_15
|
access
|
Update
|
Start
|
does
|
Java
|
not
|
Sun
|
Web
|
JDK
|
SDK
|
JRE
|
Java Web Start in Sun JDK and JRE 6 Update 2 and earlier, JDK and JRE 5.0 Update 12 and earlier, SDK and JRE 1.4.2_15 and earlier, and SDK and JRE 1.3.1_20 and earlier does not properly enforce access restrictions for untrusted (1) applications and (2) applets, which allows user-assisted remote attackers to copy or rename arbitrary files when local users perform drag-and-drop operations from the untrusted application or applet window onto certain types of desktop applications.
Visual truncation vulnerability in the Java Run
untrusted-code
|
vulnerability
|
Environment
|
workstation
|
circumvent
|
truncation
|
attackers
|
creating
|
warning
|
earlier
|
Runtime
|
display
|
larger
|
screen
|
banner
|
window
|
142_15
|
Update
|
Visual
|
allows
|
remote
|
131_20
|
than
|
Java
|
Sun
|
SDK
|
JRE
|
JDK
|
Visual truncation vulnerability in the Java Runtime Environment in Sun JDK and JRE 6 Update 2 and earlier, JDK and JRE 5.0 Update 12 and earlier, SDK and JRE 1.4.2_15 and earlier, and SDK and JRE 1.3.1_20 and earlier allows remote attackers to circumvent display of the untrusted-code warning banner by creating a window larger than the workstation screen.
Software vulnerabilities results 1 to 20 of 50
Page:
1
2
3
►