Lucene search

K
nvd[email protected]NVD:CVE-2009-3880
HistoryNov 09, 2009 - 7:30 p.m.

CVE-2009-3880

2009-11-0919:30:00
CWE-264
web.nvd.nist.gov
4

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

AI Score

5.5

Confidence

Low

EPSS

0.005

Percentile

76.9%

The Abstract Window Toolkit (AWT) in Java Runtime Environment (JRE) in Sun Java SE 5.0 before Update 22 and 6 before Update 17, and OpenJDK, does not properly restrict the objects that may be sent to loggers, which allows attackers to obtain sensitive information via vectors related to the implementation of Component, KeyboardFocusManager, and DefaultKeyboardFocusManager, aka Bug Id 6664512.

Affected configurations

Nvd
Node
sunjreRange1.5.0update_21
OR
sunjreRange1.6.0update_16
OR
sunjreMatch1.5.0update_1
OR
sunjreMatch1.5.0update_11
OR
sunjreMatch1.5.0update_12
OR
sunjreMatch1.5.0update_13
OR
sunjreMatch1.5.0update_14
OR
sunjreMatch1.5.0update_15
OR
sunjreMatch1.5.0update_16
OR
sunjreMatch1.5.0update_17
OR
sunjreMatch1.5.0update_18
OR
sunjreMatch1.5.0update_19
OR
sunjreMatch1.5.0update_2
OR
sunjreMatch1.5.0update_20
OR
sunjreMatch1.5.0update_3
OR
sunjreMatch1.5.0update_4
OR
sunjreMatch1.5.0update_5
OR
sunjreMatch1.5.0update_6
OR
sunjreMatch1.5.0update_7
OR
sunjreMatch1.5.0update_8
OR
sunjreMatch1.5.0update_9
OR
sunjreMatch1.5.0update10
OR
sunjreMatch1.6.0update_1
OR
sunjreMatch1.6.0update_10
OR
sunjreMatch1.6.0update_11
OR
sunjreMatch1.6.0update_12
OR
sunjreMatch1.6.0update_13
OR
sunjreMatch1.6.0update_14
OR
sunjreMatch1.6.0update_15
OR
sunjreMatch1.6.0update_2
OR
sunjreMatch1.6.0update_3
OR
sunjreMatch1.6.0update_4
OR
sunjreMatch1.6.0update_5
OR
sunjreMatch1.6.0update_6
OR
sunjreMatch1.6.0update_7
OR
sunjreMatch1.6.0update_8
OR
sunjreMatch1.6.0update_9
OR
sunopenjdk
VendorProductVersionCPE
sunjre*cpe:2.3:a:sun:jre:*:update_21:*:*:*:*:*:*
sunjre*cpe:2.3:a:sun:jre:*:update_16:*:*:*:*:*:*
sunjre1.5.0cpe:2.3:a:sun:jre:1.5.0:update_1:*:*:*:*:*:*
sunjre1.5.0cpe:2.3:a:sun:jre:1.5.0:update_11:*:*:*:*:*:*
sunjre1.5.0cpe:2.3:a:sun:jre:1.5.0:update_12:*:*:*:*:*:*
sunjre1.5.0cpe:2.3:a:sun:jre:1.5.0:update_13:*:*:*:*:*:*
sunjre1.5.0cpe:2.3:a:sun:jre:1.5.0:update_14:*:*:*:*:*:*
sunjre1.5.0cpe:2.3:a:sun:jre:1.5.0:update_15:*:*:*:*:*:*
sunjre1.5.0cpe:2.3:a:sun:jre:1.5.0:update_16:*:*:*:*:*:*
sunjre1.5.0cpe:2.3:a:sun:jre:1.5.0:update_17:*:*:*:*:*:*
Rows per page:
1-10 of 381

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

AI Score

5.5

Confidence

Low

EPSS

0.005

Percentile

76.9%