[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248392

 
 

909

 
 

195452

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2009-3884Date: (C)2009-11-09   (M)2024-02-22


The TimeZone.getTimeZone method in Sun Java SE 5.0 before Update 22 and 6 before Update 17, and OpenJDK, allows remote attackers to determine the existence of local files via vectors related to handling of zoneinfo (aka tz) files, aka Bug Id 6824265.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 5.0
Exploit Score: 10.0
Impact Score: 2.9
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: LOW
Authentication: NONE
Confidentiality: PARTIAL
Integrity: NONE
Availability: NONE
  
Reference:
SECUNIA-37386
SECUNIA-37581
APPLE-SA-2009-12-03-1
APPLE-SA-2009-12-03-2
GLSA-200911-02
MDVSA-2010:084
http://java.sun.com/j2se/1.5.0/ReleaseNotes.html
http://java.sun.com/javase/6/webnotes/6u17.html
http://support.apple.com/kb/HT3969
http://support.apple.com/kb/HT3970
https://bugzilla.redhat.com/show_bug.cgi?id=530300
oval:org.mitre.oval:def:11686
oval:org.mitre.oval:def:6960

CPE    15
cpe:/a:sun:jre:1.6.0:update_6
cpe:/a:sun:jre:1.6.0:update_7
cpe:/a:sun:jre:1.6.0:update_9
cpe:/a:sun:jre:1.6.0:update_2
...
OVAL    9
oval:org.secpod.oval:def:19737
oval:org.secpod.oval:def:301167
oval:org.secpod.oval:def:500496
oval:org.secpod.oval:def:101974
...

© SecPod Technologies