7.5

CVE-2009-3881

Sun Java SE 5.0 before Update 22 and 6 before Update 17, and OpenJDK, does not prevent the existence of children of a resurrected ClassLoader, which allows remote attackers to gain privileges via unspecified vectors, related to an "information leak vulnerability," aka Bug Id 6636650.

Data is provided by the National Vulnerability Database (NVD)
SunJre Updateupdate_21 Version <= 1.5.0
SunJre Updateupdate_16 Version <= 1.6.0
SunJre Version1.5.0 Updateupdate_1
SunJre Version1.5.0 Updateupdate_11
SunJre Version1.5.0 Updateupdate_12
SunJre Version1.5.0 Updateupdate_13
SunJre Version1.5.0 Updateupdate_14
SunJre Version1.5.0 Updateupdate_15
SunJre Version1.5.0 Updateupdate_16
SunJre Version1.5.0 Updateupdate_17
SunJre Version1.5.0 Updateupdate_18
SunJre Version1.5.0 Updateupdate_19
SunJre Version1.5.0 Updateupdate_2
SunJre Version1.5.0 Updateupdate_20
SunJre Version1.5.0 Updateupdate_3
SunJre Version1.5.0 Updateupdate_4
SunJre Version1.5.0 Updateupdate_5
SunJre Version1.5.0 Updateupdate_6
SunJre Version1.5.0 Updateupdate_7
SunJre Version1.5.0 Updateupdate_8
SunJre Version1.5.0 Updateupdate_9
SunJre Version1.5.0 Updateupdate10
SunJre Version1.6.0 Updateupdate_1
SunJre Version1.6.0 Updateupdate_10
SunJre Version1.6.0 Updateupdate_11
SunJre Version1.6.0 Updateupdate_12
SunJre Version1.6.0 Updateupdate_13
SunJre Version1.6.0 Updateupdate_14
SunJre Version1.6.0 Updateupdate_15
SunJre Version1.6.0 Updateupdate_2
SunJre Version1.6.0 Updateupdate_3
SunJre Version1.6.0 Updateupdate_4
SunJre Version1.6.0 Updateupdate_5
SunJre Version1.6.0 Updateupdate_6
SunJre Version1.6.0 Updateupdate_7
SunJre Version1.6.0 Updateupdate_8
SunJre Version1.6.0 Updateupdate_9
SunOpenjdk
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 1.28% 0.787
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.