[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248268

 
 

909

 
 

195051

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2009-1106Date: (C)2009-03-25   (M)2023-12-22


The Java Plug-in in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 6 Update 12, 11, and 10 does not properly parse crossdomain.xml files, which allows remote attackers to bypass intended access restrictions and connect to arbitrary sites via unknown vectors, aka CR 6798948.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 6.4
Exploit Score: 10.0
Impact Score: 4.9
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: LOW
Authentication: NONE
Confidentiality: NONE
Integrity: PARTIAL
Availability: PARTIAL
  
Reference:
SECTRACK-1021920
http://www.securityfocus.com/archive/1/507985/100/0/threaded
SUNALERT-254611
BID-34240
SECUNIA-34496
SECUNIA-35156
SECUNIA-35255
SECUNIA-36185
SECUNIA-37386
SECUNIA-37460
ADV-2009-1426
ADV-2009-3316
GLSA-200911-02
HPSBUX02429
RHSA-2009:0392
RHSA-2009:1038
RHSA-2009:1198
SSRT090058
SUSE-SA:2009:016
SUSE-SA:2009:036
http://sunsolve.sun.com/search/document.do?assetkey=1-21-125137-14-1
http://support.avaya.com/elmodocs2/security/ASA-2009-108.htm
http://www.vmware.com/security/advisories/VMSA-2009-0016.html
jre-plugin-crossdomain-info-disclosure(49459)
oval:org.mitre.oval:def:6619

CPE    6
cpe:/a:sun:jdk:1.6.0:update_10
cpe:/a:sun:jdk:1.6.0:update_11
cpe:/a:sun:jdk:1.6.0:update_12
cpe:/a:sun:jre:1.6.0:update_12
...
CWE    1
CWE-20
OVAL    2
oval:org.secpod.oval:def:400095
oval:org.secpod.oval:def:19741

© SecPod Technologies