First published: Fri Dec 31 2004(Updated: )
readObject in (1) Java Runtime Environment (JRE) and (2) Software Development Kit (SDK) 1.4.0 through 1.4.2_05 allows remote attackers to cause a denial of service (JVM unresponsive) via crafted serialized data.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sun Java Runtime Environment (JRE) | =1.4.0_02 | |
Sun Java Runtime Environment (JRE) | =1.4.0_04 | |
Java Development Kit (JDK) | =1.4.0_4 | |
Java Development Kit (JDK) | =1.4.1_03 | |
Sun Java Runtime Environment (JRE) | =1.4.2-update2 | |
Java Development Kit (JDK) | =1.4.2_05 | |
Java Development Kit (JDK) | =1.4.0_02 | |
Sun Java Runtime Environment (JRE) | =1.4.0_01 | |
Java Development Kit (JDK) | =1.4.2 | |
Java Development Kit (JDK) | =1.4.2 | |
Sun Java Runtime Environment (JRE) | =1.4.2-update5 | |
Sun Java Runtime Environment (JRE) | =1.4.0_01 | |
Sun Java Runtime Environment (JRE) | =1.4.2-update3 | |
Sun Java Runtime Environment (JRE) | =1.4.1 | |
Java Development Kit (JDK) | =1.4.0_03 | |
Sun Java Runtime Environment (JRE) | =1.4.2-update4 | |
Java Development Kit (JDK) | =1.4.1_02 | |
Java Development Kit (JDK) | =1.4 | |
Sun Java Runtime Environment (JRE) | =1.4.0_03 | |
Sun Java Runtime Environment (JRE) | =1.4.1_02 | |
Sun Java Runtime Environment (JRE) | =1.4.1-update3 | |
Sun Java Runtime Environment (JRE) | =1.4.1_02 | |
Sun Java Runtime Environment (JRE) | =1.4 | |
Sun Java Runtime Environment (JRE) | =1.4.1_01 | |
Sun Java Runtime Environment (JRE) | =1.4.0_04 | |
Java Development Kit (JDK) | =1.4.2_01 | |
Sun Java Runtime Environment (JRE) | =1.4.2-update3 | |
Java Development Kit (JDK) | =1.4.2_04 | |
Java Development Kit (JDK) | =1.4.1_02 | |
Sun Java Runtime Environment (JRE) | =1.4.2-update5 | |
Java Development Kit (JDK) | =1.4.1 | |
Sun Java Runtime Environment (JRE) | =1.4.1_01 | |
Java Development Kit (JDK) | =1.4.2 | |
Sun Java Runtime Environment (JRE) | =1.4 | |
Sun Java Runtime Environment (JRE) | =1.4.2-update1 | |
Java Development Kit (JDK) | =1.4.2_03 | |
Java Development Kit (JDK) | =1.4.2_03 | |
Sun Java Runtime Environment (JRE) | =1.4.0_03 | |
Sun Java Runtime Environment (JRE) | =1.4.0_02 | |
Sun Java Runtime Environment (JRE) | =1.4.2-update3 | |
Sun Java Runtime Environment (JRE) | =1.4.2-update1 | |
Java Development Kit (JDK) | =1.4.0_01 | |
Sun Java Runtime Environment (JRE) | =1.4.1 | |
Java Development Kit (JDK) | =1.4.1_01 | |
Java Development Kit (JDK) | =1.4 | |
Java Development Kit (JDK) | =1.4.0_03 | |
Java Development Kit (JDK) | =1.4.0_02 | |
Java Development Kit (JDK) | =1.4.1_01 | |
Sun Java Runtime Environment (JRE) | =1.4.2-update1 | |
Sun Java Runtime Environment (JRE) | =1.4.1-update3 | |
Java Development Kit (JDK) | =1.4.1_03 | |
Java Development Kit (JDK) | =1.4.0_03 | |
Sun Java Runtime Environment (JRE) | =1.4.1_01 | |
Java Development Kit (JDK) | =1.4.2_04 | |
Java Development Kit (JDK) | =1.4.2_05 | |
Sun Java Runtime Environment (JRE) | =1.4.2 | |
Sun Java Runtime Environment (JRE) | =1.4.2-update4 | |
Sun Java Runtime Environment (JRE) | =1.4.2-update2 | |
Java Development Kit (JDK) | =1.4.2_04 | |
Java Development Kit (JDK) | =1.4.0_4 | |
Sun Java Runtime Environment (JRE) | =1.4.2 | |
Sun Java Runtime Environment (JRE) | =1.4.2-update4 | |
Java Development Kit (JDK) | =1.4.1_03 | |
Java Development Kit (JDK) | =1.4.1 | |
Java Development Kit (JDK) | =1.4.0_4 | |
Sun Java Runtime Environment (JRE) | =1.4.2 | |
Sun Java Runtime Environment (JRE) | =1.4.2-update5 | |
Java Development Kit (JDK) | =1.4.1 | |
Java Development Kit (JDK) | =1.4.2_02 | |
Sun Java Runtime Environment (JRE) | =1.4.0_04 | |
Sun Java Runtime Environment (JRE) | =1.4 | |
Sun Java Runtime Environment (JRE) | =1.4.0_03 | |
Java Development Kit (JDK) | =1.4.2_03 | |
Java Development Kit (JDK) | =1.4.1_02 | |
Sun Java Runtime Environment (JRE) | =1.4.1_02 | |
Sun Java Runtime Environment (JRE) | =1.4.1-update3 | |
Java Development Kit (JDK) | =1.4.1_01 | |
Sun Java Runtime Environment (JRE) | =1.4.1_07 | |
Java Development Kit (JDK) | =1.4 | |
Java Development Kit (JDK) | =1.4.0_02 | |
Sun Java Runtime Environment (JRE) | =1.4.2-update2 | |
Java Development Kit (JDK) | =1.4.2_05 | |
Sun Java Runtime Environment (JRE) | =1.4.0_02 | |
Sun Java Runtime Environment (JRE) | =1.4.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-2540 is classified as a denial of service vulnerability that can cause the Java Virtual Machine to become unresponsive.
To mitigate CVE-2004-2540, upgrading to a patched version of the Java Runtime Environment or Software Development Kit is recommended.
CVE-2004-2540 affects Java Runtime Environment and SDK versions 1.4.0 through 1.4.2_05.
Exploitation of CVE-2004-2540 can lead to the Java Virtual Machine becoming unresponsive when processing crafted serialized data.
CVE-2004-2540 is primarily a concern for legacy applications still using the affected Java versions, making it less relevant for modern software.