CVE-2009-1100
Vulnerability Summary
Timeline
Description
Multiple unspecified vulnerabilities in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 17 and earlier, and 6 Update 12 and earlier, allow remote attackers to cause a denial of service (disk consumption) via vectors related to temporary font files and (1) "limits on Font creation," aka CR 6522586, and (2) another unspecified vector, aka CR 6632886.
CVSS Metrics
- v2.0•MEDIUM•Score: 5AV:N/AC:L/Au:N/C:N/I:N/A:P
EPSS Trends
Current EPSS score: 7.18%• Percentile: 92%
Affected Systems
- sun•jdk
≤ 1.5.0 | 1.5.0 | 1.5.0:update1 | 1.5.0:update10 | 1.5.0:update11 | 1.5.0:update11_b03 | 1.5.0:update12 | 1.5.0:update13 | 1.5.0:update14 | 1.5.0:update15 | 1.5.0:update16 | 1.5.0:update2 | 1.5.0:update3 | 1.5.0:update4 | 1.5.0:update5 | 1.5.0:update6 | 1.5.0:update7 | 1.5.0:update7_b03 | 1.5.0:update8 | 1.5.0:update9 | ≤ 1.6.0 | 1.6.0 | 1.6.0:update_10 | 1.6.0:update_11 | 1.6.0:update_3 | 1.6.0:update_4 | 1.6.0:update_5 | 1.6.0:update_6 | 1.6.0:update_7 | 1.6.0:update1 | 1.6.0:update1_b06 | 1.6.0:update2
- sun•jre
≤ 1.5.0 | 1.5.0 | 1.5.0:update1 | 1.5.0:update10 | 1.5.0:update11 | 1.5.0:update12 | 1.5.0:update13 | 1.5.0:update14 | 1.5.0:update15 | 1.5.0:update16 | 1.5.0:update2 | 1.5.0:update3 | 1.5.0:update4 | 1.5.0:update5 | 1.5.0:update6 | 1.5.0:update7 | 1.5.0:update8 | 1.5.0:update9 | ≤ 1.6.0 | 1.6.0 | 1.6.0:update_1 | 1.6.0:update_10 | 1.6.0:update_11 | 1.6.0:update_2 | 1.6.0:update_3 | 1.6.0:update_4 | 1.6.0:update_5 | 1.6.0:update_6 | 1.6.0:update_7
References (35)
- http://lists.opensuse.org/opensuse-security-announce/2009-07/msg00001.html
- http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&cc=us&objectID=c01745133
- http://secunia.com/advisories/35156
- http://lists.opensuse.org/opensuse-security-announce/2009-05/msg00003.html
- http://secunia.com/advisories/35776
- http://support.avaya.com/elmodocs2/security/ASA-2009-109.htm
- http://secunia.com/advisories/37460
- http://secunia.com/advisories/34489
- http://security.gentoo.org/glsa/glsa-200911-02.xml
- http://www.redhat.com/support/errata/RHSA-2009-1038.html
- https://rhn.redhat.com/errata/RHSA-2009-1198.html
- http://www.vmware.com/security/advisories/VMSA-2009-0016.html
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6224
- http://sunsolve.sun.com/search/document.do?assetkey=1-66-254608-1
- http://marc.info/?l=bugtraq&m=124344236532162&w=2
- http://www.redhat.com/support/errata/RHSA-2009-0394.html
- http://secunia.com/advisories/34495
- http://www.securitytracker.com/id?1021917
- http://sunsolve.sun.com/search/document.do?assetkey=1-21-118667-19-1
- http://secunia.com/advisories/36185
- http://secunia.com/advisories/35255
- http://www.vupen.com/english/advisories/2009/1426
- http://lists.opensuse.org/opensuse-security-announce/2009-06/msg00003.html
- http://www.securityfocus.com/archive/1/507985/100/0/threaded
- http://www.oracle.com/technetwork/topics/security/cpujul2009-091332.html
- http://www.redhat.com/support/errata/RHSA-2009-0392.html
- http://secunia.com/advisories/35223
- http://www.securityfocus.com/bid/34240
- http://secunia.com/advisories/34496
- http://www.ubuntu.com/usn/usn-748-1
- http://secunia.com/advisories/35416
- http://support.avaya.com/elmodocs2/security/ASA-2009-108.htm
- http://secunia.com/advisories/37386
- http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00001.html
- http://www.vupen.com/english/advisories/2009/3316