Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2006-6731


Multiple buffer overflows in Sun Java Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 7 and earlier, Java System Development Kit (SDK) and JRE 1.4.2_12 and earlier 1.4.x versions, and SDK and JRE 1.3.1_18 and earlier allow attackers to develop Java applets that read, write, or execute local files, possibly related to (1) integer overflows in the Java_sun_awt_image_ImagingLib_convolveBI, awt_parseRaster, and awt_parseColorModel functions; (2) a stack overflow in the Java_sun_awt_image_ImagingLib_lookupByteRaster function; and (3) improper handling of certain negative values in the Java_sun_font_SunLayoutEngine_nativeLayout function. NOTE: some of these details are obtained from third party information.


Published

2006-12-26T23:28:00.000

Last Modified

2025-04-09T00:30:58.490

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 9.3 (HIGH)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:C/I:C/A:C

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: COMPLETE
  • Integrity Impact: COMPLETE
  • Availability Impact: COMPLETE
Exploitability Score

8.6

Impact Score

10.0

Weaknesses
  • Type: Primary
    NVD-CWE-Other

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application sun jdk 1.5.0 Yes
Application sun jdk 1.5.0 Yes
Application sun jdk 1.5.0 Yes
Application sun jdk 1.5.0 Yes
Application sun jdk 1.5.0 Yes
Application sun jdk 1.5.0 Yes
Application sun jdk 1.5.0 Yes
Application sun jdk 1.5.0 Yes
Application sun jre 1.3.1 Yes
Application sun jre 1.3.1_2 Yes
Application sun jre 1.3.1_03 Yes
Application sun jre 1.3.1_04 Yes
Application sun jre 1.3.1_05 Yes
Application sun jre 1.3.1_06 Yes
Application sun jre 1.3.1_07 Yes
Application sun jre 1.3.1_08 Yes
Application sun jre 1.3.1_09 Yes
Application sun jre 1.3.1_10 Yes
Application sun jre 1.3.1_11 Yes
Application sun jre 1.3.1_12 Yes
Application sun jre 1.3.1_13 Yes
Application sun jre 1.3.1_14 Yes
Application sun jre 1.3.1_15 Yes
Application sun jre 1.3.1_16 Yes
Application sun jre 1.3.1_17 Yes
Application sun jre 1.3.1_18 Yes
Application sun jre 1.4.2 Yes
Application sun jre 1.4.2_1 Yes
Application sun jre 1.4.2_2 Yes
Application sun jre 1.4.2_3 Yes
Application sun jre 1.4.2_4 Yes
Application sun jre 1.4.2_5 Yes
Application sun jre 1.4.2_6 Yes
Application sun jre 1.4.2_7 Yes
Application sun jre 1.4.2_8 Yes
Application sun jre 1.4.2_9 Yes
Application sun jre 1.4.2_10 Yes
Application sun jre 1.4.2_11 Yes
Application sun jre 1.4.2_12 Yes
Application sun jre 1.5.0 Yes
Application sun jre 1.5.0 Yes
Application sun jre 1.5.0 Yes
Application sun jre 1.5.0 Yes
Application sun jre 1.5.0 Yes
Application sun jre 1.5.0 Yes
Application sun jre 1.5.0 Yes
Application sun jre 1.5.0 Yes
Application sun sdk 1.3.1 Yes
Application sun sdk 1.3.1_01 Yes
Application sun sdk 1.3.1_01a Yes
Application sun sdk 1.3.1_02 Yes
Application sun sdk 1.3.1_03 Yes
Application sun sdk 1.3.1_04 Yes
Application sun sdk 1.3.1_05 Yes
Application sun sdk 1.3.1_06 Yes
Application sun sdk 1.3.1_07 Yes
Application sun sdk 1.3.1_08 Yes
Application sun sdk 1.3.1_09 Yes
Application sun sdk 1.3.1_10 Yes
Application sun sdk 1.3.1_11 Yes
Application sun sdk 1.3.1_12 Yes
Application sun sdk 1.3.1_13 Yes
Application sun sdk 1.3.1_14 Yes
Application sun sdk 1.3.1_15 Yes
Application sun sdk 1.3.1_16 Yes
Application sun sdk 1.3.1_17 Yes
Application sun sdk 1.3.1_18 Yes
Application sun sdk 1.4.2 Yes
Application sun sdk 1.4.2_1 Yes
Application sun sdk 1.4.2_2 Yes
Application sun sdk 1.4.2_3 Yes
Application sun sdk 1.4.2_4 Yes
Application sun sdk 1.4.2_5 Yes
Application sun sdk 1.4.2_6 Yes
Application sun sdk 1.4.2_7 Yes
Application sun sdk 1.4.2_8 Yes
Application sun sdk 1.4.2_9 Yes
Application sun sdk 1.4.2_10 Yes
Application sun sdk 1.4.2_11 Yes
Application sun sdk 1.4.2_12 Yes

References