Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2009-2675

Integer overflow in the unpack200 utility in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15, and JDK and JRE 5.0 before Update 20, allows context-dependent attackers to gain privileges via unspecified length fields in the header of a Pack200-compressed JAR file, which leads to a heap-based buffer overflow during decompression.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.068
EPSS Ranking 90.9%
CVSS Severity
CVSS v2 Score 10.0
References
Products affected by CVE-2009-2675
  • Sun » Jdk » Version: 1.6.0
    cpe:2.3:a:sun:jdk:1.6.0
  • Sun » Jdk » Version: 5.0
    cpe:2.3:a:sun:jdk:5.0
  • Sun » Jdk » Version: 6
    cpe:2.3:a:sun:jdk:6
  • Sun » Jre » Version: 1.6.0
    cpe:2.3:a:sun:jre:1.6.0
  • Sun » Jre » Version: 5.0
    cpe:2.3:a:sun:jre:5.0
  • Sun » Jre » Version: 6
    cpe:2.3:a:sun:jre:6


Contact Us

Shodan ® - All rights reserved