6.8
CVSSv2

CVE-2009-2676

Published: 05/08/2009 Updated: 30/10/2018
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Unspecified vulnerability in JNLPAppletlauncher in Sun Java SE, and SE for Business, in JDK and JRE 6 Update 14 and previous versions and JDK and JRE 5.0 Update 19 and previous versions; and Java SE for Business in SDK and JRE 1.4.2_21 and previous versions; allows remote malicious users to create or modify arbitrary files via vectors involving an untrusted Java applet that accesses an old version of JNLPAppletLauncher.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

sun java_se

sun jdk

sun jdk 1.6.0

sun jre 1.6.0

sun jdk 1.5.0

sun jre 1.5.0

sun jre

sun sdk 1.4.2_1

sun sdk 1.4.2_2

sun sdk 1.4.2_10

sun sdk 1.4.2_11

sun sdk 1.4.2_18

sun sdk 1.4.2_19

sun sdk 1.4.1_02

sun sdk 1.4.1_03

sun jre 1.4.2

sun jre 1.4.2_1

sun jre 1.4.2_8

sun jre 1.4.2_9

sun jre 1.4.1

sun jre 1.4.0_03

sun jre 1.4.0_04

sun sdk 1.4.2_3

sun sdk 1.4.2_4

sun sdk 1.4.2_12

sun sdk 1.4.2_13

sun sdk 1.4.2_20

sun sdk

sun sdk 1.4.1_01

sun sdk 1.4.1

sun jre 1.4.2_2

sun jre 1.4.2_3

sun jre 1.4.2_10

sun jre 1.4.2_11

sun sdk 1.4.2

sun sdk 1.4.2_8

sun sdk 1.4.2_9

sun sdk 1.4.2_16

sun sdk 1.4.2_17

sun sdk 1.4.1_04

sun sdk 1.4.1_05

sun sdk 1.4.0_04

sun sdk 1.4.0_03

sun jre 1.4.2_6

sun jre 1.4.2_7

sun jre 1.4.2_14

sun jre 1.4.2_15

sun jre 1.4.0_01

sun jre 1.4.0_02

sun sdk 1.4.2_5

sun sdk 1.4.2_6

sun sdk 1.4.2_7

sun sdk 1.4.2_14

sun sdk 1.4.2_15

sun sdk 1.4.1_06

sun sdk 1.4.1_07

sun sdk 1.4.0_01

sun sdk 1.4.0_02

sun sdk 1.4.0

sun jre 1.4.2_4

sun jre 1.4.2_5

sun jre 1.4.2_12

sun jre 1.4.2_13

sun jre 1.4.0

Vendor Advisories

It was discovered that the XML HMAC signature system did not correctly check certain lengths If an attacker sent a truncated HMAC, it could bypass authentication, leading to potential privilege escalation (CVE-2009-0217) ...
Synopsis Critical: java-150-sun security update Type/Severity Security Advisory: Critical Topic Updated java-150-sun packages that correct several security issues arenow available for Red Hat Enterprise Linux 4 Extras and 5 SupplementaryThis update has been rated as having critical security impact by t ...
Synopsis Critical: java-160-sun security update Type/Severity Security Advisory: Critical Topic Updated java-160-sun packages that correct several security issues arenow available for Red Hat Enterprise Linux 4 Extras and 5 SupplementaryThis update has been rated as having critical security impact by t ...
Synopsis Low: Red Hat Network Satellite Server IBM Java Runtime security update Type/Severity Security Advisory: Low Topic Updated java-160-ibm packages that fix several security issues are nowavailable for Red Hat Network Satellite Server 53This update has been rated as having low security impact by th ...