9.3

CVE-2006-6731

Multiple buffer overflows in Sun Java Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 7 and earlier, Java System Development Kit (SDK) and JRE 1.4.2_12 and earlier 1.4.x versions, and SDK and JRE 1.3.1_18 and earlier allow attackers to develop Java applets that read, write, or execute local files, possibly related to (1) integer overflows in the Java_sun_awt_image_ImagingLib_convolveBI, awt_parseRaster, and awt_parseColorModel functions; (2) a stack overflow in the Java_sun_awt_image_ImagingLib_lookupByteRaster function; and (3) improper handling of certain negative values in the Java_sun_font_SunLayoutEngine_nativeLayout function.  NOTE: some of these details are obtained from third party information.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SunJdk Version1.5.0 Update-
SunJdk Version1.5.0 Updateupdate1
SunJdk Version1.5.0 Updateupdate2
SunJdk Version1.5.0 Updateupdate3
SunJdk Version1.5.0 Updateupdate4
SunJdk Version1.5.0 Updateupdate5
SunJdk Version1.5.0 Updateupdate6
SunJdk Version1.5.0 Updateupdate7
SunJre Version1.3.1 Update-
SunJre Version1.3.1_2
SunJre Version1.3.1_03
SunJre Version1.3.1_04
SunJre Version1.3.1_05
SunJre Version1.3.1_06
SunJre Version1.3.1_07
SunJre Version1.3.1_08
SunJre Version1.3.1_09
SunJre Version1.3.1_10
SunJre Version1.3.1_11
SunJre Version1.3.1_12
SunJre Version1.3.1_13
SunJre Version1.3.1_14
SunJre Version1.3.1_15
SunJre Version1.3.1_16
SunJre Version1.3.1_17
SunJre Version1.3.1_18
SunJre Version1.4.2 Update-
SunJre Version1.4.2_1
SunJre Version1.4.2_2
SunJre Version1.4.2_3
SunJre Version1.4.2_4
SunJre Version1.4.2_5
SunJre Version1.4.2_6
SunJre Version1.4.2_7
SunJre Version1.4.2_8
SunJre Version1.4.2_9
SunJre Version1.4.2_10
SunJre Version1.4.2_11
SunJre Version1.4.2_12
SunJre Version1.5.0 Update-
SunJre Version1.5.0 Updateupdate1
SunJre Version1.5.0 Updateupdate2
SunJre Version1.5.0 Updateupdate3
SunJre Version1.5.0 Updateupdate4
SunJre Version1.5.0 Updateupdate5
SunJre Version1.5.0 Updateupdate6
SunJre Version1.5.0 Updateupdate7
SunSdk Version1.3.1
SunSdk Version1.3.1_01
SunSdk Version1.3.1_01a
SunSdk Version1.3.1_02
SunSdk Version1.3.1_03
SunSdk Version1.3.1_04
SunSdk Version1.3.1_05
SunSdk Version1.3.1_06
SunSdk Version1.3.1_07
SunSdk Version1.3.1_08
SunSdk Version1.3.1_09
SunSdk Version1.3.1_10
SunSdk Version1.3.1_11
SunSdk Version1.3.1_12
SunSdk Version1.3.1_13
SunSdk Version1.3.1_14
SunSdk Version1.3.1_15
SunSdk Version1.3.1_16
SunSdk Version1.3.1_17
SunSdk Version1.3.1_18
SunSdk Version1.4.2
SunSdk Version1.4.2_1
SunSdk Version1.4.2_2
SunSdk Version1.4.2_3
SunSdk Version1.4.2_4
SunSdk Version1.4.2_5
SunSdk Version1.4.2_6
SunSdk Version1.4.2_7
SunSdk Version1.4.2_8
SunSdk Version1.4.2_9
SunSdk Version1.4.2_10
SunSdk Version1.4.2_11
SunSdk Version1.4.2_12
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 6.07% 0.904
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.3 8.6 10
AV:N/AC:M/Au:N/C:C/I:C/A:C
http://securitytracker.com/id?1017425
Third Party Advisory
VDB Entry
http://www.kb.cert.org/vuls/id/149457
Third Party Advisory
US Government Resource
http://www.kb.cert.org/vuls/id/939609
Third Party Advisory
US Government Resource
http://www.securityfocus.com/bid/21675
Patch
Third Party Advisory
VDB Entry
http://www.us-cert.gov/cas/techalerts/TA07-022A.html
Third Party Advisory
US Government Resource