Lucene search

K
cveMitreCVE-2006-2426
HistoryMay 17, 2006 - 10:06 a.m.

CVE-2006-2426

2006-05-1710:06:00
mitre
web.nvd.nist.gov
52
cve-2006-2426
sun java
jre
jdk
sdk
denial of service
disk consumption
font.createfont
nvd

CVSS2

6.4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:P/A:P

AI Score

6.3

Confidence

Low

EPSS

0.422

Percentile

97.4%

Sun Java Runtime Environment (JRE) 1.5.0_6 and earlier, JDK 1.5.0_6 and earlier, and SDK 1.5.0_6 and earlier allows remote attackers to cause a denial of service (disk consumption) by using the Font.createFont function to create temporary files of arbitrary size in the %temp% directory.

Affected configurations

Nvd
Node
sunjdkMatch1.5.0update6
OR
sunjreMatch1.5.0update6
OR
sunsdkMatch1.5.0_6
VendorProductVersionCPE
sunjdk1.5.0cpe:2.3:a:sun:jdk:1.5.0:update6:*:*:*:*:*:*
sunjre1.5.0cpe:2.3:a:sun:jre:1.5.0:update6:*:*:*:*:*:*
sunsdk1.5.0_6cpe:2.3:a:sun:sdk:1.5.0_6:*:*:*:*:*:*:*

References

CVSS2

6.4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:P/A:P

AI Score

6.3

Confidence

Low

EPSS

0.422

Percentile

97.4%