Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2009-1106

Опубликовано: 25 мар. 2009
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 6.4

Описание

The Java Plug-in in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 6 Update 12, 11, and 10 does not properly parse crossdomain.xml files, which allows remote attackers to bypass intended access restrictions and connect to arbitrary sites via unknown vectors, aka CR 6798948.

РелизСтатусПримечание
dapper

DNE

devel

not-affected

Sun Java only
gutsy

DNE

hardy

not-affected

Sun Java only
intrepid

not-affected

Sun Java only
jaunty

not-affected

Sun Java only
karmic

not-affected

Sun Java only
lucid

not-affected

Sun Java only
upstream

not-affected

Sun Java only

Показывать по

РелизСтатусПримечание
dapper

ignored

end of life
devel

DNE

gutsy

ignored

end of life, was needs-triage
hardy

not-affected

intrepid

ignored

end of life, was needs-triage
jaunty

not-affected

karmic

DNE

lucid

DNE

upstream

not-affected

Показывать по

РелизСтатусПримечание
dapper

DNE

devel

DNE

gutsy

ignored

end of life, was needs-triage
hardy

released

6.20dlj-0ubuntu1.8.04
intrepid

ignored

end of life, was needs-triage
jaunty

released

6.20dlj-0ubuntu1.9.04
karmic

released

6.20dlj-0ubuntu1.9.10
lucid

released

6.20dlj-1ubuntu3
upstream

released

6.13

Показывать по

Ссылки на источники

EPSS

Процентиль: 80%
0.01394
Низкий

6.4 Medium

CVSS2

Связанные уязвимости

redhat
больше 16 лет назад

The Java Plug-in in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 6 Update 12, 11, and 10 does not properly parse crossdomain.xml files, which allows remote attackers to bypass intended access restrictions and connect to arbitrary sites via unknown vectors, aka CR 6798948.

nvd
больше 16 лет назад

The Java Plug-in in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 6 Update 12, 11, and 10 does not properly parse crossdomain.xml files, which allows remote attackers to bypass intended access restrictions and connect to arbitrary sites via unknown vectors, aka CR 6798948.

debian
больше 16 лет назад

The Java Plug-in in Java SE Development Kit (JDK) and Java Runtime Env ...

github
больше 3 лет назад

The Java Plug-in in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 6 Update 12, 11, and 10 does not properly parse crossdomain.xml files, which allows remote attackers to bypass intended access restrictions and connect to arbitrary sites via unknown vectors, aka CR 6798948.

EPSS

Процентиль: 80%
0.01394
Низкий

6.4 Medium

CVSS2