← Back to Products

java_virtual_machine

Vendor: oracle

1
Total CVEs
0
Critical
1
High
0
Medium
0
Low

Recent CVEs

Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 19.3-19.29 and 21.3-21.20. Easily exploitable vulnerability allows high privileged attacker...

Affected versions: 19.25 19.26 19.3 21.16 21.17 +1 more

Published: Jan 20, 2026

4.5

CVSS

Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 19.3-19.27 and 21.3-21.18. Easily exploitable vulnerability allows low privileged attacker ...

Affected versions: 19.25 19.26 19.3 21.16 21.17 +1 more

Published: Jul 15, 2025

7.7

CVSS

Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 19.3-19.26, 21.3-21.17 and 23.4-23.7. Difficult to exploit vulnerability allows unauthentic...

Affected versions: 19.25 19.26 19.3 21.16 21.17 +4 more

Published: Apr 15, 2025

7.4

CVSS

Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 19.3-19.25, 21.3-21.16 and 23.4-23.6. Difficult to exploit vulnerability allows low privile...

Affected versions: 19.25 19.3 21.16 21.3 23.4 +1 more

Published: Jan 21, 2025

4.2

CVSS

Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 19.3-19.22 and 21.3-21.13. Difficult to exploit vulnerability allows low privileged attacke...

Affected versions: 19.3 21.3

Published: Apr 16, 2024

5.3

CVSS

Microsoft Java virtual machine (VM) 5.0.0.3810 allows remote attackers to bypass sandbox restrictions to read or write certain data between applets from different domains via the "GET/Key" and "PUT/Ke...

Affected versions: 5.0.0.3810

Published: Jul 27, 2004

6.4

CVSS

The Microsoft Java implementation, as used in Internet Explorer, allows remote attackers to read and modify the contents of the Clipboard via an applet that accesses the (1) ClipBoardGetText and (2) C...

Affected versions: 1.1

Published: Nov 29, 2002

6.4

CVSS

The Microsoft Java implementation, as used in Internet Explorer, allows remote attackers to cause a denial of service (crash) and possibly conduct other unauthorized activities via applet tags in HTML...

Affected versions: 1.1

Published: Nov 29, 2002

7.5

CVSS

The Microsoft Java implementation, as used in Internet Explorer, allows remote attackers to read restricted process memory, cause a denial of service (crash), and possibly execute arbitrary code via t...

Affected versions: 1.1

Published: Nov 29, 2002

7.5

CVSS

The Microsoft Java implementation, as used in Internet Explorer, can provide HTML object references to applets via Javascript, which allows remote attackers to cause a denial of service (crash due to ...

Affected versions: 1.1

Published: Nov 29, 2002

7.5

CVSS

The Microsoft Java implementation, as used in Internet Explorer, allows remote attackers to steal cookies and execute script in a different security context via a URL that contains a colon in the doma...

Affected versions: 1.1

Published: Nov 29, 2002

7.5

CVSS

Stack-based buffer overflow in the Microsoft Java implementation, as used in Internet Explorer, allows remote attackers to cause a denial of service via a long class name through (1) Class.forName or ...

Affected versions: 1.1

Published: Nov 29, 2002

5.0

CVSS

The Microsoft Java implementation, as used in Internet Explorer, provides a public load0() method for the CabCracker class (com.ms.vm.loader.CabCracker), which allows remote attackers to bypass the se...

Affected versions: 1.1

Published: Nov 29, 2002

7.5

CVSS

The Microsoft Java virtual machine (VM) build 5.0.3805 and earlier, as used in Internet Explorer, allows remote attackers to extend the Standard Security Manager (SSM) class (com.ms.security.StandardS...

Affected versions: 1.1

Published: Nov 29, 2002

7.5

CVSS

The Microsoft Java implementation, as used in Internet Explorer, allows remote attackers to determine the current directory of the Internet Explorer process via the getAbsolutePath() method in a File(...

Affected versions: 1.1

Published: Nov 29, 2002

5.0

CVSS

The Microsoft Java implementation, as used in Internet Explorer, allows remote attackers to read arbitrary local files and network shares via an applet tag with a codebase set to a "file://%00" (null ...

Affected versions: 1.1

Published: Nov 29, 2002

5.0

CVSS