CVE-2009-3874
- EPSS 8.11%
- Published 05.11.2009 16:30:00
- Last modified 09.04.2025 00:30:58
Integer overflow in the JPEGImageReader implementation in the ImageI/O component in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to execute arbitrary co...
- EPSS 2.16%
- Published 05.11.2009 16:30:00
- Last modified 09.04.2025 00:30:58
The MessageDigest.isEqual function in Java Runtime Environment (JRE) in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers ...
- EPSS 11.7%
- Published 05.11.2009 16:30:00
- Last modified 09.04.2025 00:30:58
Unspecified vulnerability in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to cause a denial of service (memory consum...
- EPSS 10.74%
- Published 05.11.2009 16:30:00
- Last modified 09.04.2025 00:30:58
Unspecified vulnerability in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to cause a denial of service (memory consum...
- EPSS 3.65%
- Published 05.08.2009 19:30:01
- Last modified 09.04.2025 00:30:58
The audio system in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15, and JDK and JRE 5.0 before Update 20, does not prevent access to java.lang.System properties by (1) untrusted applets and (2) Java Web Start applications, which...
- EPSS 6.12%
- Published 05.08.2009 19:30:01
- Last modified 09.04.2025 00:30:58
The SOCKS proxy implementation in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15, and JDK and JRE 5.0 before Update 20, allows remote attackers to discover the username of the account that invoked an untrusted (1) applet or (2) ...
CVE-2009-2672
- EPSS 12.99%
- Published 05.08.2009 19:30:01
- Last modified 09.04.2025 00:30:58
The proxy mechanism implementation in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15, and JDK and JRE 5.0 before Update 20, does not prevent access to browser cookies by untrusted (1) applets and (2) Java Web Start applications,...
CVE-2009-2673
- EPSS 11.39%
- Published 05.08.2009 19:30:01
- Last modified 09.04.2025 00:30:58
The proxy mechanism implementation in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15, and JDK and JRE 5.0 before Update 20, allows remote attackers to bypass intended access restrictions and connect to arbitrary sites via unspec...
CVE-2009-2674
- EPSS 3.98%
- Published 05.08.2009 19:30:01
- Last modified 09.04.2025 00:30:58
Integer overflow in javaws.exe in Sun Java Web Start in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15 allows context-dependent attackers to execute arbitrary code via a crafted JPEG image that is not properly handled during dis...
- EPSS 6.84%
- Published 05.08.2009 19:30:01
- Last modified 09.04.2025 00:30:58
Integer overflow in the unpack200 utility in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15, and JDK and JRE 5.0 before Update 20, allows context-dependent attackers to gain privileges via unspecified length fields in the header...