[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247621

 
 

909

 
 

194512

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2009-3865Date: (C)2009-11-05   (M)2023-12-22


The launch method in the Deployment Toolkit plugin in Java Runtime Environment (JRE) in Sun Java SE in JDK and JRE 6 before Update 17 allows remote attackers to execute arbitrary commands via a crafted web page, aka Bug Id 6869752.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 9.3
Exploit Score: 8.6
Impact Score: 10.0
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: MEDIUM
Authentication: NONE
Confidentiality: COMPLETE
Integrity: COMPLETE
Availability: COMPLETE
  
Reference:
SECTRACK-1023244
SUNALERT-269869
BID-36881
SECUNIA-37231
SECUNIA-37239
SECUNIA-37386
SECUNIA-37581
SECUNIA-37841
ADV-2009-3131
APPLE-SA-2009-12-03-1
APPLE-SA-2009-12-03-2
GLSA-200911-02
HPSBMU02799
RHSA-2009:1694
SUSE-SA:2009:058
http://java.sun.com/javase/6/webnotes/6u17.html
http://support.apple.com/kb/HT3969
http://support.apple.com/kb/HT3970
oval:org.mitre.oval:def:7562

CPE    6
cpe:/a:sun:jre:1.6.0:update_2
cpe:/a:sun:jre:1.6.0:update_3
cpe:/a:sun:jre:1.6.0:update_1
cpe:/a:sun:jdk:1.6.0:update1_b06
...
CWE    1
CWE-94
OVAL    2
oval:org.secpod.oval:def:19721
oval:org.secpod.oval:def:400070

© SecPod Technologies