CyberSec.Space Logo
返回 CVE 浏览器

CVE-2009-1097

CRITICAL
9.3
CVSS Severity Score
EPSS Score0.1350%
EPSS Percentile22.90th
Published2009年3月25日
Last Modified2026年4月23日

Vulnerability Description

Multiple buffer overflows in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 6 Update 12 and earlier allow remote attackers to access files or execute arbitrary code via (1) a crafted PNG image that triggers an integer overflow during memory allocation for display on the splash screen, aka CR 6804996; and (2) a crafted GIF image from which unspecified values are used in calculation of offsets, leading to object-pointer corruption, aka CR 6804997.

Affected Platforms (CPE)

📦
Sun

Jdk

<= 1.6.0
📦
Sun

Jdk

= 1.6.0
📦
Sun

Jdk

= 1.6.0
📦
Sun

Jdk

= 1.6.0
📦
Sun

Jdk

= 1.6.0
📦
Sun

Jdk

= 1.6.0
📦
Sun

Jdk

= 1.6.0
📦
Sun

Jdk

= 1.6.0
📦
Sun

Jdk

= 1.6.0
📦
Sun

Jdk

= 1.6.0
📦
Sun

Jdk

= 1.6.0
📦
Sun

Jdk

= 1.6.0
📦
Sun

Jre

<= 1.6.0
📦
Sun

Jre

= 1.6.0
📦
Sun

Jre

= 1.6.0
📦
Sun

Jre

= 1.6.0
📦
Sun

Jre

= 1.6.0
📦
Sun

Jre

= 1.6.0
📦
Sun

Jre

= 1.6.0
📦
Sun

Jre

= 1.6.0
📦
Sun

Jre

= 1.6.0
📦
Sun

Jre

= 1.6.0
📦
Sun

Jre

= 1.6.0

References & Advisories

相关漏洞威胁