← Back

CVE-2009-3866

nvd nist
Published: Nov 5, 2009Modified: Apr 23, 2026

JSON object

Loading...
9.3
Vector
AV:N/AC:M/Au:N/C:C/I:C/A:C
Exploitability: 8.6 / Impact: 10.0
Source: NVD

Description

The Java Web Start Installer in Sun Java SE in JDK and JRE 6 before Update 17 does not properly use security model permissions when removing installer extensions, which allows remote attackers to execute arbitrary code by modifying a certain JNLP file to have a URL field that points to an unintended trusted application, aka Bug Id 6872824.

Affected (31)

Products: Sun: Jdk, Jre
2 products
Jdk
Jre
Configuration A
31 vulnerable
Vulnerable SoftwareAffected Versions
Sun
Version 1.6.0 update_10
Version 1.6.0 update_11
Version 1.6.0 update_12
Version 1.6.0 update_13
Version 1.6.0 update_14
Version 1.6.0 update_15
Version 1.6.0 update_16
Version 1.6.0 update_1
Version 1.6.0 update_3
Version 1.6.0 update_4
Version 1.6.0 update_5
Version 1.6.0 update_6
Version 1.6.0 update_7
Version 1.6.0 update_8
Version 1.6.0 update_9
Sun
Version 1.6.0 update_10
Version 1.6.0 update_11
Version 1.6.0 update_12
Version 1.6.0 update_13
Version 1.6.0 update_14
Version 1.6.0 update_15
Version 1.6.0 update_16
Version 1.6.0 update_1
Version 1.6.0 update_2
Version 1.6.0 update_3
Version 1.6.0 update_4
Version 1.6.0 update_5
Version 1.6.0 update_6
Version 1.6.0 update_7
Version 1.6.0 update_8
Version 1.6.0 update_9

Related CWEs

References (38)

Source: cve@mitre.org
Vendor Advisory
Source: cve@mitre.org
Vendor Advisory
Source: cve@mitre.org
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Patch

Timeline

No history available yet.