
CVE-2011-0311 – IBM JDK Class file parsing denial-of-service
https://notcve.org/view.php?id=CVE-2011-0311
02 Sep 2011 — The class file parser in IBM Java before 1.4.2 SR13 FP9, as used in IBM Runtimes for Java Technology 5.0.0 before SR13 and 6.0.0 before SR10, allows remote authenticated users to cause a denial of service (JVM segmentation fault, and possibly memory consumption or an infinite loop) via a crafted attribute length field in a class file, which triggers a buffer over-read. El analizador de archivos de clases en IBM Java antes de v1.4.2 SR13 FP9, tal como se utiliza en IBM Runtimes para Java Technology v5.0.0 an... • http://lists.opensuse.org/opensuse-security-announce/2011-05/msg00004.html • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2008-3440
https://notcve.org/view.php?id=CVE-2008-3440
01 Aug 2008 — Sun Java 1.6.0_03 and earlier versions, and possibly later versions, does not properly verify the authenticity of updates, which allows man-in-the-middle attackers to execute arbitrary code via a Trojan horse update, as demonstrated by evilgrade and DNS cache poisoning. Sun Java versión 1.6.0_03 y anteriores, y posiblemente versiones posteriores, no comprueba apropiadamente la autenticidad de las actualizaciones, lo que permite a los atacantes de tipo man-in-the-middle ejecutar código arbitrario por medio d... • http://archives.neohapsis.com/archives/bugtraq/2008-07/0250.html • CWE-94: Improper Control of Generation of Code ('Code Injection') •

CVE-2005-2527
https://notcve.org/view.php?id=CVE-2005-2527
31 Dec 2005 — Race condition in Java 1.4.2 before 1.4.2 Release 2 on Apple Mac OS X allows local users to corrupt files or create arbitrary files via unspecified attack vectors related to a temporary directory, possibly due to a symlink attack. • http://docs.info.apple.com/article.html?artnum=302266 • CWE-59: Improper Link Resolution Before File Access ('Link Following') •

CVE-2005-2529
https://notcve.org/view.php?id=CVE-2005-2529
31 Dec 2005 — Unspecified vulnerability in Java 1.4.2 before 1.4.2 Release 2 on Apple Mac OS X allows local users to gain privileges via unspecified attack vectors relating to "the utility used to update Java shared archives." • http://docs.info.apple.com/article.html?artnum=302266 •

CVE-2005-2738
https://notcve.org/view.php?id=CVE-2005-2738
31 Dec 2005 — Java 1.4.2 before 1.4.2 Release 2 on Apple Mac OS X does not prevent multiple programs from opening the same port as a Java ServerSocket, which allows local users to operate a Java program that intercepts network data intended for the ServerSocket of a different Java program. • http://docs.info.apple.com/article.html?artnum=302265 •

CVE-2003-1134 – Sun Microsystems Java Virtual Machine 1.x - Security Manager Denial of Service
https://notcve.org/view.php?id=CVE-2003-1134
31 Dec 2003 — Sun Java 1.3.1, 1.4.1, and 1.4.2 allows local users to cause a denial of service (JVM crash), possibly by calling the ClassDepth function with a null parameter, which causes a crash instead of generating a null pointer exception. • https://www.exploit-db.com/exploits/23292 •