← Vulnerability feed

Vulnerability record · CVE-2006-4302 · published 23 August 2006

CVE-2006-4302: Sun j2se permissions and access controls vulnerability

Sun · J2se

The Java Plug-in J2SE 1.3.0_02 through 5.0 Update 5, and Java Web Start 1.0 through 1.2 and J2SE 1.4.2 through 5.0 Update 5, allows remote attackers to exploit vulnerabilities by specifying a JRE version that contain vulnerabilities.

5.0 CVSS 2.0 Medium EPSS 4.0% · top 9.8% CWE-264 · Permissions and access controls
5.0CVSS 2.0 base score
4.0%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
20References
16 Jun 2026Last modified by NVD

Description

The Java Plug-in J2SE 1.3.0_02 through 5.0 Update 5, and Java Web Start 1.0 through 1.2 and J2SE 1.4.2 through 5.0 Update 5, allows remote attackers to exploit vulnerabilities by specifying a JRE version that contain vulnerabilities.

AV:N/AC:L/Au:N/C:N/I:P/A:N

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2006-4302 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2008-4910Sun java web start improper input validation vulnerabilityThe BasicService in Sun Java Web Start allows remote attackers to execute arbitrary programs on a client machine via a file:// URL argument to the sh…EPSS 10%10.0CVE-2007-5019Sun java web start memory buffer overflow vulnerabilityBuffer overflow in the Sun Java Web Start ActiveX control in Java Runtime Environment (JRE) 1.6.0_X allows remote attackers to have an unknown impact…EPSS 10%10.0CVE-2005-0836Sun j2se vulnerabilityArgument injection vulnerability in Java Web Start for J2SE 1.4.2 up to 1.4.2_06 allows untrusted applications to gain privileges via the value param…EPSS 2.9%9.3CVE-2006-6745Sun j2se vulnerabilityMultiple unspecified vulnerabilities in Sun Java Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 7 and earlier, and Java System D…EPSS 3.2%7.5CVE-2005-0418Sun j2se vulnerabilityArgument injection vulnerability in Java Web Start for J2SE 1.4.2 up to 1.4.2_06, on Mac OS X, allows untrusted applications to gain privileges via t…EPSS 1.5%7.5CVE-2003-1229Oracle jre improper certificate validation vulnerabilityX509TrustManager in (1) Java Secure Socket Extension (JSSE) in SDK and JRE 1.4.0 through 1.4.0_01, (2) JSSE before 1.0.3, (3) Java Plug-in SDK and JR…EPSS 4.6%7.5CVE-2002-2005Sun java web start vulnerabilityUnknown vulnerability in Java web start 1.0.1_01, 1.0.1, 1.0 and 1.0.1.01 (HP-UX 11.x only) allows attackers to gain access to restricted resources v…EPSS 1.8%5.1CVE-2005-1973Sun j2se vulnerabilityJava Web Start in Java 2 Platform Standard Edition (J2SE) 5.0 and 5.0 Update 1 allows applications to assign permissions to themselves and gain privi…EPSS 1.6%

Source: NIST National Vulnerability Database (record CVE-2006-4302), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.