[Forgot Password]
Login  Register Subscribe

24128

 
 

131615

 
 

112965

 
 

909

 
 

87888

 
 

136

Paid content will be excluded from the download.


Download | Alert*
CVE
view XML view JSON

CVE-2009-1106Date: (C)2009-03-25   (M)2018-06-09


The Java Plug-in in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 6 Update 12, 11, and 10 does not properly parse crossdomain.xml files, which allows remote attackers to bypass intended access restrictions and connect to arbitrary sites via unknown vectors, aka CR 6798948.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 6.4
Exploit Score: 10.0
Impact Score: 4.9
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: LOW
Authentication: NONE
Confidentiality: NONE
Integrity: PARTIAL
Availability: PARTIAL
  
Reference:
SECTRACK-1021920
http://www.securityfocus.com/archive/1/archive/1/507985/100/0/threaded
SUNALERT-254611
BID-34240
SECUNIA-34496
SECUNIA-35156
SECUNIA-35255
SECUNIA-36185
SECUNIA-37386
SECUNIA-37460
ADV-2009-1426
ADV-2009-3316
GLSA-200911-02
HPSBMA02429
HPSBUX02429
IAVM:2009-A-0105
RHSA-2009:0392
RHSA-2009:1038
RHSA-2009:1198
SSRT090058
SUSE-SA:2009:016
SUSE-SA:2009:036
http://sunsolve.sun.com/search/document.do?assetkey=1-21-125137-14-1
http://support.avaya.com/elmodocs2/security/ASA-2009-108.htm
http://www.vmware.com/security/advisories/VMSA-2009-0016.html
jre-plugin-crossdomain-info-disclosure(49459)

CPE    6
cpe:/a:sun:jre:1.6.0:update_12
cpe:/a:sun:jre:1.6.0:update_11
cpe:/a:sun:jre:1.6.0:update_10
cpe:/a:sun:jdk:1.6.0:update_10
...
CWE    1
CWE-20
OVAL    2
oval:org.secpod.oval:def:19741
oval:org.secpod.oval:def:400095

© SecPod Technologies