Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2009-1896

Опубликовано: 10 авг. 2009
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 10

Описание

The Java Web Start framework in IcedTea in OpenJDK before 1.6.0.0-20.b16.fc10 on Fedora 10, and before 1.6.0.0-27.b16.fc11 on Fedora 11, trusts an entire application when at least one of the listed jar files is trusted, which allows context-dependent attackers to execute arbitrary code without the untrusted-code restrictions via a crafted application, related to NetX.

РелизСтатусПримечание
dapper

DNE

devel

not-affected

6b16-1.6.1-0ubuntu1
hardy

released

6b18-1.8.2-4ubuntu1~8.04.1
intrepid

released

6b12-0ubuntu6.5
jaunty

released

6b14-1.4.1-0ubuntu11
karmic

not-affected

6b16-1.6.1-0ubuntu1
lucid

not-affected

6b16-1.6.1-0ubuntu1
maverick

not-affected

6b16-1.6.1-0ubuntu1
upstream

released

6b16

Показывать по

РелизСтатусПримечание
dapper

ignored

end of life
devel

DNE

hardy

not-affected

intrepid

ignored

end of life, was needs-triage
jaunty

not-affected

karmic

DNE

lucid

DNE

maverick

DNE

upstream

not-affected

Показывать по

РелизСтатусПримечание
dapper

DNE

devel

DNE

hardy

not-affected

intrepid

ignored

end of life, was needs-triage
jaunty

not-affected

karmic

not-affected

lucid

not-affected

maverick

not-affected

upstream

not-affected

Показывать по

EPSS

Процентиль: 77%
0.01036
Низкий

10 Critical

CVSS2

Связанные уязвимости

redhat
больше 16 лет назад

The Java Web Start framework in IcedTea in OpenJDK before 1.6.0.0-20.b16.fc10 on Fedora 10, and before 1.6.0.0-27.b16.fc11 on Fedora 11, trusts an entire application when at least one of the listed jar files is trusted, which allows context-dependent attackers to execute arbitrary code without the untrusted-code restrictions via a crafted application, related to NetX.

nvd
больше 16 лет назад

The Java Web Start framework in IcedTea in OpenJDK before 1.6.0.0-20.b16.fc10 on Fedora 10, and before 1.6.0.0-27.b16.fc11 on Fedora 11, trusts an entire application when at least one of the listed jar files is trusted, which allows context-dependent attackers to execute arbitrary code without the untrusted-code restrictions via a crafted application, related to NetX.

debian
больше 16 лет назад

The Java Web Start framework in IcedTea in OpenJDK before 1.6.0.0-20.b ...

github
почти 4 года назад

The Java Web Start framework in IcedTea in OpenJDK before 1.6.0.0-20.b16.fc10 on Fedora 10, and before 1.6.0.0-27.b16.fc11 on Fedora 11, trusts an entire application when at least one of the listed jar files is trusted, which allows context-dependent attackers to execute arbitrary code without the untrusted-code restrictions via a crafted application, related to NetX.

EPSS

Процентиль: 77%
0.01036
Низкий

10 Critical

CVSS2