← Back

CVE-2009-3880

nvd nist
Published: Nov 9, 2009Modified: Apr 23, 2026

JSON object

Loading...
5.0
Vector
AV:N/AC:L/Au:N/C:P/I:N/A:N
Exploitability: 10.0 / Impact: 2.9
Source: NVD

Description

The Abstract Window Toolkit (AWT) in Java Runtime Environment (JRE) in Sun Java SE 5.0 before Update 22 and 6 before Update 17, and OpenJDK, does not properly restrict the objects that may be sent to loggers, which allows attackers to obtain sensitive information via vectors related to the implementation of Component, KeyboardFocusManager, and DefaultKeyboardFocusManager, aka Bug Id 6664512.

Affected (38)

Products: Sun: Jre, Openjdk
2 products
Jre
Openjdk
Configuration A
38 vulnerable
Vulnerable SoftwareAffected Versions
Sun
Up to 1.6.0
Up to 1.5.0
Version 1.5.0 update10
Version 1.5.0 update_11
Version 1.5.0 update_12
Version 1.5.0 update_13
Version 1.5.0 update_14
Version 1.5.0 update_15
Version 1.5.0 update_16
Version 1.5.0 update_17
Version 1.5.0 update_18
Version 1.5.0 update_19
Version 1.5.0 update_1
Version 1.5.0 update_20
Version 1.5.0 update_2
Version 1.5.0 update_3
Version 1.5.0 update_4
Version 1.5.0 update_5
Version 1.5.0 update_6
Version 1.5.0 update_7
Version 1.5.0 update_8
Version 1.5.0 update_9
Version 1.6.0 update_10
Version 1.6.0 update_11
Version 1.6.0 update_12
Version 1.6.0 update_13
Version 1.6.0 update_14
Version 1.6.0 update_15
Version 1.6.0 update_1
Version 1.6.0 update_2
Version 1.6.0 update_3
Version 1.6.0 update_4
Version 1.6.0 update_5
Version 1.6.0 update_6
Version 1.6.0 update_7
Version 1.6.0 update_8
Version 1.6.0 update_9
All versions

Related CWEs

References (16)

Source: secalert@redhat.com
Vendor Advisory
Source: secalert@redhat.com
Vendor Advisory
Source: secalert@redhat.com
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.