[Forgot Password]
Login  Register Subscribe

23631

 
 

117918

 
 

98218

 
 

909

 
 

79224

 
 

109

Paid content will be excluded from the download.


Download | Alert*
CVE
view XML

CVE-2009-1106

Date: (C)2009-03-25   (M)2017-10-04 


The Java Plug-in in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 6 Update 12, 11, and 10 does not properly parse crossdomain.xml files, which allows remote attackers to bypass intended access restrictions and connect to arbitrary sites via unknown vectors, aka CR 6798948.

CVSS Score: 6.4Access Vector: NETWORK
Exploit Score: 10.0Access Complexity: LOW
Impact Score: 4.9Authentication: NONE
 Confidentiality: NONE
 Integrity: PARTIAL
 Availability: PARTIAL





Reference:
SECTRACK-1021920
http://www.securityfocus.com/archive/1/archive/1/507985/100/0/threaded
SUNALERT-254611
BID-34240
SECUNIA-34496
SECUNIA-35156
SECUNIA-35255
SECUNIA-36185
SECUNIA-37386
SECUNIA-37460
ADV-2009-1426
ADV-2009-3316
GLSA-200911-02
HPSBMA02429
HPSBUX02429
IAVM:2009-A-0105
RHSA-2009:0392
RHSA-2009:1038
RHSA-2009:1198
SSRT090058
SUSE-SA:2009:016
SUSE-SA:2009:036
http://sunsolve.sun.com/search/document.do?assetkey=1-21-125137-14-1
http://support.avaya.com/elmodocs2/security/ASA-2009-108.htm
http://www.vmware.com/security/advisories/VMSA-2009-0016.html
jre-plugin-crossdomain-info-disclosure(49459)

CPE    6
cpe:/a:sun:jdk:1.6.0:update_10
cpe:/a:sun:jdk:1.6.0:update_11
cpe:/a:sun:jdk:1.6.0:update_12
cpe:/a:sun:jre:1.6.0:update_12
...
CWE    1
CWE-20
OVAL    2
oval:org.secpod.oval:def:400095
oval:org.secpod.oval:def:19741

© 2013 SecPod Technologies