← Back

CVE-2009-2675

nvd nist
Published: Aug 5, 2009Modified: Apr 23, 2026

JSON object

Loading...
10.0
Vector
AV:N/AC:L/Au:N/C:C/I:C/A:C
Exploitability: 10.0 / Impact: 10.0
Source: NVD

Description

Integer overflow in the unpack200 utility in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15, and JDK and JRE 5.0 before Update 20, allows context-dependent attackers to gain privileges via unspecified length fields in the header of a Pack200-compressed JAR file, which leads to a heap-based buffer overflow during decompression.

Affected (61)

Products: Sun: Jdk, Jre
2 products
Jdk
Jre
Configuration A
61 vulnerable
Vulnerable SoftwareAffected Versions
Sun
Up to 6
Version 5.0 update_10
Version 5.0 update_11
Version 5.0 update_12
Version 5.0 update_13
Version 5.0 update_14
Version 5.0 update_15
Version 5.0 update_16
Version 5.0 update_17
Version 5.0 update_1
Version 5.0 update_2
Version 5.0 update_3
Version 5.0 update_4
Version 5.0 update_5
Version 5.0 update_6
Version 5.0 update_7
Version 5.0 update_8
Version 5.0 update_9
Version 6 update_10
Version 6 update_11
Version 6 update_12
Version 6 update_1
Version 6 update_2
Version 6 update_3
Version 6 update_4
Version 6 update_5
Version 6 update_6
Version 6 update_7
Version 6 update_8
Version 6 update_9
Sun
Up to 6
Version 5.0 update_10
Version 5.0 update_11
Version 5.0 update_12
Version 5.0 update_13
Version 5.0 update_14
Version 5.0 update_15
Version 5.0 update_16
Version 5.0 update_17
Version 5.0 update_19
Version 5.0 update_1
Version 5.0 update_2
Version 5.0 update_3
Version 5.0 update_4
Version 5.0 update_5
Version 5.0 update_6
Version 5.0 update_7
Version 5.0 update_8
Version 5.0 update_9
Version 6 update_10
Version 6 update_11
Version 6 update_12
Version 6 update_1
Version 6 update_2
Version 6 update_3
Version 6 update_4
Version 6 update_5
Version 6 update_6
Version 6 update_7
Version 6 update_8
Version 6 update_9

Related CWEs

References (66)

Source: cve@mitre.org
Vendor Advisory
Source: cve@mitre.org
Vendor Advisory
Source: cve@mitre.org
Vendor Advisory
Source: cve@mitre.org
Vendor Advisory
Source: cve@mitre.org
Vendor Advisory
Source: cve@mitre.org
Vendor Advisory
Source: cve@mitre.org
Vendor Advisory
Source: cve@mitre.org
Vendor Advisory
Source: cve@mitre.org
US Government Resource
Source: cve@mitre.org
Vendor Advisory
Source: cve@mitre.org
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
US Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.