← Back

CVE-2006-6731

nvd nist
Published: Dec 26, 2006Modified: Apr 23, 2026

JSON object

Loading...
9.3
Vector
AV:N/AC:M/Au:N/C:C/I:C/A:C
Exploitability: 8.6 / Impact: 10.0
Source: NVD

Description

Multiple buffer overflows in Sun Java Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 7 and earlier, Java System Development Kit (SDK) and JRE 1.4.2_12 and earlier 1.4.x versions, and SDK and JRE 1.3.1_18 and earlier allow attackers to develop Java applets that read, write, or execute local files, possibly related to (1) integer overflows in the Java_sun_awt_image_ImagingLib_convolveBI, awt_parseRaster, and awt_parseColorModel functions; (2) a stack overflow in the Java_sun_awt_image_ImagingLib_lookupByteRaster function; and (3) improper handling of certain negative values in the Java_sun_font_SunLayoutEngine_nativeLayout function. NOTE: some of these details are obtained from third party information.

Affected (80)

Products: Sun: Jdk, Jre, Sdk
3 products
Jdk
Jre
Sdk
Configuration A
8 vulnerable
Vulnerable SoftwareAffected Versions
Sun
Version 1.5.0
Version 1.5.0 update1
Version 1.5.0 update2
Version 1.5.0 update3
Version 1.5.0 update4
Version 1.5.0 update5
Version 1.5.0 update6
Version 1.5.0 update7
Configuration B
39 vulnerable
Vulnerable SoftwareAffected Versions
Sun
Version 1.3.1
Version 1.3.1_03
Version 1.3.1_04
Version 1.3.1_05
Version 1.3.1_06
Version 1.3.1_07
Version 1.3.1_08
Version 1.3.1_09
Version 1.3.1_10
Version 1.3.1_11
Version 1.3.1_12
Version 1.3.1_13
Version 1.3.1_14
Version 1.3.1_15
Version 1.3.1_16
Version 1.3.1_17
Version 1.3.1_18
Version 1.3.1_2
Version 1.4.2
Version 1.4.2_10
Version 1.4.2_11
Version 1.4.2_12
Version 1.4.2_1
Version 1.4.2_2
Version 1.4.2_3
Version 1.4.2_4
Version 1.4.2_5
Version 1.4.2_6
Version 1.4.2_7
Version 1.4.2_8
Version 1.4.2_9
Version 1.5.0
Version 1.5.0 update1
Version 1.5.0 update2
Version 1.5.0 update3
Version 1.5.0 update4
Version 1.5.0 update5
Version 1.5.0 update6
Version 1.5.0 update7
Configuration C
33 vulnerable
Vulnerable SoftwareAffected Versions
Sun
Version 1.3.1
Version 1.3.1_01
Version 1.3.1_01a
Version 1.3.1_02
Version 1.3.1_03
Version 1.3.1_04
Version 1.3.1_05
Version 1.3.1_06
Version 1.3.1_07
Version 1.3.1_08
Version 1.3.1_09
Version 1.3.1_10
Version 1.3.1_11
Version 1.3.1_12
Version 1.3.1_13
Version 1.3.1_14
Version 1.3.1_15
Version 1.3.1_16
Version 1.3.1_17
Version 1.3.1_18
Version 1.4.2
Version 1.4.2_10
Version 1.4.2_11
Version 1.4.2_12
Version 1.4.2_1
Version 1.4.2_2
Version 1.4.2_3
Version 1.4.2_4
Version 1.4.2_5
Version 1.4.2_6
Version 1.4.2_7
Version 1.4.2_8
Version 1.4.2_9

References (66)

Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Mailing ListThird Party Advisory
Source: cve@mitre.org
Mailing ListThird Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Third Party AdvisoryVDB Entry
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Third Party AdvisoryUS Government Resource
Source: cve@mitre.org
Third Party AdvisoryUS Government Resource
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Third Party AdvisoryVDB Entry
Source: cve@mitre.org
PatchThird Party AdvisoryVDB Entry
Source: cve@mitre.org
Third Party AdvisoryUS Government Resource
Source: cve@mitre.org
Permissions Required
Source: cve@mitre.org
Permissions Required
Source: cve@mitre.org
Permissions Required
Source: cve@mitre.org
Permissions Required
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Permissions Required
Source: af854a3a-2127-422b-91ae-364da2661108
Permissions Required
Source: af854a3a-2127-422b-91ae-364da2661108
Permissions Required
Source: af854a3a-2127-422b-91ae-364da2661108
Permissions Required
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.