- EPSS 1.58%
- Published 09.11.2009 19:30:00
- Last modified 09.04.2025 00:30:58
Unspecified vulnerability in the TrueType font parsing functionality in Sun Java SE 5.0 before Update 22 and 6 before Update 17 allows remote attackers to cause a denial of service (application crash) via a certain test suite, aka Bug Id 6815780.
CVE-2009-3879
- EPSS 0.26%
- Published 09.11.2009 19:30:00
- Last modified 09.04.2025 00:30:58
Multiple unspecified vulnerabilities in the (1) X11 and (2) Win32GraphicsDevice subsystems in Sun Java SE 5.0 before Update 22 and 6 before Update 17, and OpenJDK, have unknown impact and attack vectors, related to failure to clone arrays that are re...
- EPSS 0.48%
- Published 09.11.2009 19:30:00
- Last modified 09.04.2025 00:30:58
The Abstract Window Toolkit (AWT) in Java Runtime Environment (JRE) in Sun Java SE 5.0 before Update 22 and 6 before Update 17, and OpenJDK, does not properly restrict the objects that may be sent to loggers, which allows attackers to obtain sensitiv...
CVE-2009-3881
- EPSS 1.28%
- Published 09.11.2009 19:30:00
- Last modified 09.04.2025 00:30:58
Sun Java SE 5.0 before Update 22 and 6 before Update 17, and OpenJDK, does not prevent the existence of children of a resurrected ClassLoader, which allows remote attackers to gain privileges via unspecified vectors, related to an "information leak v...
CVE-2009-3882
- EPSS 0.66%
- Published 09.11.2009 19:30:00
- Last modified 09.04.2025 00:30:58
Multiple unspecified vulnerabilities in the Swing implementation in Sun Java SE 5.0 before Update 22 and 6 before Update 17, and OpenJDK, have unknown impact and remote attack vectors, related to "information leaks in mutable variables," aka Bug Id 6...
CVE-2009-3883
- EPSS 0.66%
- Published 09.11.2009 19:30:00
- Last modified 09.04.2025 00:30:58
Multiple unspecified vulnerabilities in the Windows Pluggable Look and Feel (PL&F) feature in the Swing implementation in Sun Java SE 5.0 before Update 22 and 6 before Update 17, and OpenJDK, have unknown impact and remote attack vectors, related to ...
- EPSS 1.35%
- Published 09.11.2009 19:30:00
- Last modified 09.04.2025 00:30:58
The TimeZone.getTimeZone method in Sun Java SE 5.0 before Update 22 and 6 before Update 17, and OpenJDK, allows remote attackers to determine the existence of local files via vectors related to handling of zoneinfo (aka tz) files, aka Bug Id 6824265.
- EPSS 0.89%
- Published 09.11.2009 19:30:00
- Last modified 09.04.2025 00:30:58
Sun Java SE 5.0 before Update 22 and 6 before Update 17 on Windows allows remote attackers to cause a denial of service via a BMP file containing a link to a UNC share pathname for an International Color Consortium (ICC) profile file, probably a rela...
CVE-2009-3886
- EPSS 0.45%
- Published 09.11.2009 19:30:00
- Last modified 09.04.2025 00:30:58
The Java Web Start implementation in Sun Java SE 6 before Update 17 does not properly handle the interaction between a signed JAR file and a JNLP (1) application or (2) applet, which has unspecified impact and attack vectors, related to a "regression...
CVE-2009-3864
- EPSS 8.56%
- Published 05.11.2009 16:30:00
- Last modified 09.04.2025 00:30:58
The Java Update functionality in Java Runtime Environment (JRE) in Sun Java SE in JDK and JRE 5.0 before Update 22 and JDK and JRE 6 before Update 17, when a non-English version of Windows is used, does not retrieve available new JRE versions, which ...