[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250053

 
 

909

 
 

195940

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2006-6731Date: (C)2006-12-26   (M)2023-12-22


Multiple buffer overflows in Sun Java Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 7 and earlier, Java System Development Kit (SDK) and JRE 1.4.2_12 and earlier 1.4.x versions, and SDK and JRE 1.3.1_18 and earlier allow attackers to develop Java applets that read, write, or execute local files, possibly related to (1) integer overflows in the Java_sun_awt_image_ImagingLib_convolveBI, awt_parseRaster, and awt_parseColorModel functions; (2) a stack overflow in the Java_sun_awt_image_ImagingLib_lookupByteRaster function; and (3) improper handling of certain negative values in the Java_sun_font_SunLayoutEngine_nativeLayout function. NOTE: some of these details are obtained from third party information.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 9.3
Exploit Score: 8.6
Impact Score: 10.0
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: MEDIUM
Authentication: NONE
Confidentiality: COMPLETE
Integrity: COMPLETE
Availability: COMPLETE
  
Reference:
SECTRACK-1017425
SUNALERT-102729
BID-21675
SECUNIA-23445
SECUNIA-23650
SECUNIA-23835
SECUNIA-24099
SECUNIA-24189
SECUNIA-24468
SECUNIA-25283
SECUNIA-25404
SECUNIA-28115
ADV-2006-5073
ADV-2007-0936
ADV-2007-1814
ADV-2007-4224
APPLE-SA-2007-12-14
BEA07-174.00
GLSA-200701-15
GLSA-200702-08
GLSA-200705-20
HPSBUX02196
RHSA-2007:0062
RHSA-2007:0072
RHSA-2007:0073
SSRT071318
SUSE-SA:2007:003
SUSE-SA:2007:010
TA07-022A
VU#149457
VU#939609
http://docs.info.apple.com/article.html?artnum=307177
http://scary.beasts.org/security/CESA-2005-008.txt

CPE    76
cpe:/a:sun:sdk:1.3.1_17
cpe:/a:sun:sdk:1.3.1_18
cpe:/a:sun:sdk:1.3.1_15
cpe:/a:sun:sdk:1.3.1_16
...

© SecPod Technologies