9.3
CVSSv2

CVE-2009-1671

Published: 18/05/2009 Updated: 14/02/2024
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 935
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Multiple buffer overflows in the Deployment Toolkit ActiveX control in deploytk.dll 6.0.130.3 in Sun Java SE Runtime Environment (aka JRE) 6 Update 13 allow remote malicious users to execute arbitrary code via a long string argument to the (1) setInstallerType, (2) setAdditionalPackages, (3) compareVersion, (4) getStaticCLSID, or (5) launch method.

Vulnerable Product Search on Vulmon Subscribe to Product

sun jre 6

Exploits

------------------------------------------------------------------------- Java SE Runtime Environment - JRE 6 Update 13 Multiple Vulnerabilities url: javasuncom/ Author: shinnai mail: shinnai[at]autistici[dot]org site: wwwshinnainet/ File: deploytkdll Ver: 601303 Des: Deployment Toolkit Url : javadlsuncom ...