9.3
CVSSv2

CVE-2009-1672

Published: 18/05/2009 Updated: 14/02/2024
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 935
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

The Deployment Toolkit ActiveX control in deploytk.dll 6.0.130.3 in Sun Java SE Runtime Environment (aka JRE) 6 Update 13 allows remote malicious users to (1) execute arbitrary code via a .jnlp URL in the argument to the launch method, and might allow remote malicious users to launch JRE installation processes via the (2) installLatestJRE or (3) installJRE method.

Vulnerable Product Search on Vulmon Subscribe to Product

sun jre 6

Exploits

------------------------------------------------------------------------- Java SE Runtime Environment - JRE 6 Update 13 Multiple Vulnerabilities url: javasuncom/ Author: shinnai mail: shinnai[at]autistici[dot]org site: wwwshinnainet/ File: deploytkdll Ver: 601303 Des: Deployment Toolkit Url : javadlsuncom ...