CVE-2009-3864The Java Update functionality in Java Runtime Environment (JRE) in Sun Java SE in JDK and JRE 5.0 before Update 22 and JDK and JRE 6 before Update 17, when a non-English version of Windows is used, does not retrieve available new JRE versions, which allows remote attackers to leverage vulnerabilities in older releases of this software, aka Bug Id 6869694. |
Severity | HIGH |
Base Score | 7.5 |
Impact Score | 6.4 |
Exploit Score | 10.0 |
Confidentiality Impact | PARTIAL |
Integrity Impact | PARTIAL |
Availability Impact | PARTIAL |
Access Vector | |
Authentication | NONE |
Ease of Access | |
|
|
CVE-2009-3865The launch method in the Deployment Toolkit plugin in Java Runtime Environment (JRE) in Sun Java SE in JDK and JRE 6 before Update 17 allows remote attackers to execute arbitrary commands via a crafted web page, aka Bug Id 6869752. |
Severity | HIGH |
Base Score | 9.3 |
Impact Score | 10.0 |
Exploit Score | 8.6 |
Confidentiality Impact | COMPLETE |
Integrity Impact | COMPLETE |
Availability Impact | COMPLETE |
Access Vector | |
Authentication | NONE |
Ease of Access | |
|
|
CVE-2009-3866The Java Web Start Installer in Sun Java SE in JDK and JRE 6 before Update 17 does not properly use security model permissions when removing installer extensions, which allows remote attackers to execute arbitrary code by modifying a certain JNLP file to have a URL field that points to an unintended trusted application, aka Bug Id 6872824. |
Severity | HIGH |
Base Score | 9.3 |
Impact Score | 10.0 |
Exploit Score | 8.6 |
Confidentiality Impact | COMPLETE |
Integrity Impact | COMPLETE |
Availability Impact | COMPLETE |
Access Vector | |
Authentication | NONE |
Ease of Access | |
|
|
CVE-2009-3867Stack-based buffer overflow in the HsbParser.getSoundBank function in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to execute arbitrary code via a long file: URL in an argument, aka Bug Id 6854303. |
Severity | HIGH |
Base Score | 9.3 |
Impact Score | 10.0 |
Exploit Score | 8.6 |
Confidentiality Impact | COMPLETE |
Integrity Impact | COMPLETE |
Availability Impact | COMPLETE |
Access Vector | |
Authentication | NONE |
Ease of Access | |
|
|
CVE-2009-3868Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK and JRE 1.4.x before 1.4.2_24 does not properly parse color profiles, which allows remote attackers to gain privileges via a crafted image file, aka Bug Id 6862970. |
Severity | HIGH |
Base Score | 9.3 |
Impact Score | 10.0 |
Exploit Score | 8.6 |
Confidentiality Impact | COMPLETE |
Integrity Impact | COMPLETE |
Availability Impact | COMPLETE |
Access Vector | |
Authentication | NONE |
Ease of Access | |
|
|
CVE-2009-3869Stack-based buffer overflow in the setDiffICM function in the Abstract Window Toolkit (AWT) in Java Runtime Environment (JRE) in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to execute arbitrary code via a crafted argument, aka Bug Id 6872357. |
Severity | HIGH |
Base Score | 9.3 |
Impact Score | 10.0 |
Exploit Score | 8.6 |
Confidentiality Impact | COMPLETE |
Integrity Impact | COMPLETE |
Availability Impact | COMPLETE |
Access Vector | |
Authentication | NONE |
Ease of Access | |
|
|
CVE-2009-3871Heap-based buffer overflow in the setBytePixels function in the Abstract Window Toolkit (AWT) in Java Runtime Environment (JRE) in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to execute arbitrary code via crafted arguments, aka Bug Id 6872358. |
Severity | HIGH |
Base Score | 9.3 |
Impact Score | 10.0 |
Exploit Score | 8.6 |
Confidentiality Impact | COMPLETE |
Integrity Impact | COMPLETE |
Availability Impact | COMPLETE |
Access Vector | |
Authentication | NONE |
Ease of Access | |
|
|
CVE-2009-3872Unspecified vulnerability in the JPEG JFIF Decoder in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to gain privileges via a crafted image file, aka Bug Id 6862969. |
Severity | HIGH |
Base Score | 9.3 |
Impact Score | 10.0 |
Exploit Score | 8.6 |
Confidentiality Impact | COMPLETE |
Integrity Impact | COMPLETE |
Availability Impact | COMPLETE |
Access Vector | |
Authentication | NONE |
Ease of Access | |
|
|
CVE-2009-3873The JPEG Image Writer in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to gain privileges via a crafted image file, related to a "quantization problem," aka Bug Id 6862968. |
Severity | HIGH |
Base Score | 9.3 |
Impact Score | 10.0 |
Exploit Score | 8.6 |
Confidentiality Impact | COMPLETE |
Integrity Impact | COMPLETE |
Availability Impact | COMPLETE |
Access Vector | |
Authentication | NONE |
Ease of Access | |
|
|
CVE-2009-3874Integer overflow in the JPEGImageReader implementation in the ImageI/O component in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to execute arbitrary code via large subsample dimensions in a JPEG file that triggers a heap-based buffer overflow, aka Bug Id 6874643. |
Severity | HIGH |
Base Score | 9.3 |
Impact Score | 10.0 |
Exploit Score | 8.6 |
Confidentiality Impact | COMPLETE |
Integrity Impact | COMPLETE |
Availability Impact | COMPLETE |
Access Vector | |
Authentication | NONE |
Ease of Access | |
|
|
CVE-2009-3875The MessageDigest.isEqual function in Java Runtime Environment (JRE) in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to spoof HMAC-based digital signatures, and possibly bypass authentication, via unspecified vectors related to "timing attack vulnerabilities," aka Bug Id 6863503. |
Severity | MEDIUM |
Base Score | 5.0 |
Impact Score | 2.9 |
Exploit Score | 10.0 |
Confidentiality Impact | NONE |
Integrity Impact | PARTIAL |
Availability Impact | NONE |
Access Vector | |
Authentication | NONE |
Ease of Access | |
|
|
CVE-2009-3876Unspecified vulnerability in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to cause a denial of service (memory consumption) via crafted DER encoded data, which is not properly decoded by the ASN.1 DER input stream parser, aka Bug Id 6864911. |
Severity | MEDIUM |
Base Score | 5.0 |
Impact Score | 2.9 |
Exploit Score | 10.0 |
Confidentiality Impact | NONE |
Integrity Impact | NONE |
Availability Impact | PARTIAL |
Access Vector | |
Authentication | NONE |
Ease of Access | |
|
|
CVE-2009-3877Unspecified vulnerability in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to cause a denial of service (memory consumption) via crafted HTTP headers, which are not properly parsed by the ASN.1 DER input stream parser, aka Bug Id 6864911. |
Severity | MEDIUM |
Base Score | 5.0 |
Impact Score | 2.9 |
Exploit Score | 10.0 |
Confidentiality Impact | NONE |
Integrity Impact | NONE |
Availability Impact | PARTIAL |
Access Vector | |
Authentication | NONE |
Ease of Access | |
|
|