CVE-2009-3728
Published Nov 9, 2009
Last updated 6 years ago
Overview
- Description
- Directory traversal vulnerability in the ICC_Profile.getInstance method in Java Runtime Environment (JRE) in Sun Java SE 5.0 before Update 22 and 6 before Update 17, and OpenJDK, allows remote attackers to determine the existence of local International Color Consortium (ICC) profile files via a .. (dot dot) in a pathname, aka Bug Id 6631533.
- Source
- secalert@redhat.com
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 5
- Impact score
- 2.9
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:P/I:N/A:N
Weaknesses
- nvd@nist.gov
- CWE-22
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:sun:jre:1.5.0:update1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A7FC09E8-7F30-4FE4-912E-588AA250E2A3" }, { "criteria": "cpe:2.3:a:sun:jre:1.5.0:update10:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A586DE4E-8A46-41DE-9FDB-5FDB81DCC87B" }, { "criteria": "cpe:2.3:a:sun:jre:1.5.0:update11:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9919D091-73D7-465A-80FF-F37D6CAF9F46" }, { "criteria": "cpe:2.3:a:sun:jre:1.5.0:update12:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "02565D6F-4CB2-4671-A4EF-3169BCFA6154" }, { "criteria": "cpe:2.3:a:sun:jre:1.5.0:update13:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "452A3E51-9EAC-451D-BA04-A1E7B7D917EB" }, { "criteria": "cpe:2.3:a:sun:jre:1.5.0:update14:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3E8C6AAC-C90B-4220-A69B-2A886A35CF5D" }, { "criteria": "cpe:2.3:a:sun:jre:1.5.0:update15:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "55231B6B-9298-4363-9B5A-14C2DA7B1F50" }, { "criteria": "cpe:2.3:a:sun:jre:1.5.0:update16:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E42CF0F7-418C-4BB6-9B73-FA3B9171D092" }, { "criteria": "cpe:2.3:a:sun:jre:1.5.0:update17:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A5467E9D-07D8-4BEB-84D5-A3136C133519" }, { "criteria": "cpe:2.3:a:sun:jre:1.5.0:update18:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B83B2CE1-45D7-47AD-BC0A-6EC74D5F8F5A" }, { "criteria": "cpe:2.3:a:sun:jre:1.5.0:update19:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8A32F326-EA92-43CD-930E-E527B60CDD3B" }, { "criteria": "cpe:2.3:a:sun:jre:1.5.0:update2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7EA5B9E9-654D-44F7-AE98-3D8B382804AC" }, { "criteria": "cpe:2.3:a:sun:jre:1.5.0:update20:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "04344167-530E-4A4D-90EF-74C684943DF1" }, { "criteria": "cpe:2.3:a:sun:jre:1.5.0:update21:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B0E0373B-201D-408F-9234-A7EFE8B4970D" }, { "criteria": "cpe:2.3:a:sun:jre:1.5.0:update3:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "44051CFE-D15D-4416-A123-F3E49C67A9E7" }, { "criteria": "cpe:2.3:a:sun:jre:1.5.0:update4:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F296ACF3-1373-429D-B991-8B5BA704A7EF" }, { "criteria": "cpe:2.3:a:sun:jre:1.5.0:update5:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B863420B-DE16-416A-9640-1A1340A9B855" }, { "criteria": "cpe:2.3:a:sun:jre:1.5.0:update6:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "724C972F-74FE-4044-BBC4-7E0E61FC9002" }, { "criteria": "cpe:2.3:a:sun:jre:1.5.0:update7:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "46F41C15-0EF4-4115-BFAA-EEAD56FAEEDB" }, { "criteria": "cpe:2.3:a:sun:jre:1.5.0:update8:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "EBE909DE-E55A-4BD3-A5BF-ADE407432193" }, { "criteria": "cpe:2.3:a:sun:jre:1.5.0:update9:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5DAC04D2-68FD-4793-A8E7-4690A543D7D4" }, { "criteria": "cpe:2.3:a:sun:jre:1.6.0:update_1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "09027C19-D442-446F-B7A8-21DB6787CF43" }, { "criteria": "cpe:2.3:a:sun:jre:1.6.0:update_2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7158D2C0-E9AC-4CD6-B777-EA7B7A181997" }, { "criteria": "cpe:2.3:a:sun:jre:1.6.0:update_3:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "90EC6C13-4B37-48E5-8199-A702A944D5A6" }, { "criteria": "cpe:2.3:a:sun:jre:1.6.0:update10:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B6339EF9-97AC-4675-9971-7435A4B31432" }, { "criteria": "cpe:2.3:a:sun:jre:1.6.0:update11:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6D1626F8-26F4-4EC5-A486-98808372425F" }, { "criteria": "cpe:2.3:a:sun:jre:1.6.0:update12:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "FA1BFE3B-3773-426B-9E69-250249E059C7" }, { "criteria": "cpe:2.3:a:sun:jre:1.6.0:update13:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "46621D4B-CA2B-4EAC-884E-9CC9486F2F94" }, { "criteria": "cpe:2.3:a:sun:jre:1.6.0:update14:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "37FED4C9-7501-4DF3-B05E-0B460CBB2D9E" }, { "criteria": "cpe:2.3:a:sun:jre:1.6.0:update15:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6958538A-0C2E-460F-A130-70515AFBB6A5" }, { "criteria": "cpe:2.3:a:sun:jre:1.6.0:update16:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "ABB1D4B3-54E6-455D-9238-B185DB012A43" }, { "criteria": "cpe:2.3:a:sun:jre:1.6.0:update4:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "360EF765-0C3A-4A13-9DA3-48928BB978E6" }, { "criteria": "cpe:2.3:a:sun:jre:1.6.0:update5:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "FBE651B3-3320-48E7-BDD5-74D3C609162C" }, { "criteria": "cpe:2.3:a:sun:jre:1.6.0:update6:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2F435AA3-B716-4B3B-8873-3646E18CA600" }, { "criteria": "cpe:2.3:a:sun:jre:1.6.0:update7:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4773DE1C-50EF-4561-B480-74C6BD64D449" }, { "criteria": "cpe:2.3:a:sun:jre:1.6.0:update8:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "BB2B5C85-D6EE-4C0B-9228-A724D6C780C9" }, { "criteria": "cpe:2.3:a:sun:jre:1.6.0:update9:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "60D59062-997B-44F1-95C6-619823F138A7" }, { "criteria": "cpe:2.3:a:sun:openjdk:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0E78309B-E13F-4B65-9F59-39A993B900AF" } ], "operator": "OR" } ] } ]