Vulnerabilities > Critical

DATE CVE VULNERABILITY TITLE RISK
2009-11-05 CVE-2009-3873 Buffer Errors vulnerability in SUN Jdk, JRE and SDK
The JPEG Image Writer in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to gain privileges via a crafted image file, related to a "quantization problem," aka Bug Id 6862968.
network
sun microsoft CWE-119
critical
9.3
2009-11-05 CVE-2009-3872 Multiple Security vulnerability in SUN Jdk, JRE and SDK
Unspecified vulnerability in the JPEG JFIF Decoder in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to gain privileges via a crafted image file, aka Bug Id 6862969.
network
sun microsoft
critical
9.3
2009-11-05 CVE-2009-3871 Buffer Errors vulnerability in SUN Jdk, JRE and SDK
Heap-based buffer overflow in the setBytePixels function in the Abstract Window Toolkit (AWT) in Java Runtime Environment (JRE) in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to execute arbitrary code via crafted arguments, aka Bug Id 6872358.
network
sun microsoft CWE-119
critical
9.3
2009-11-05 CVE-2009-3869 Buffer Errors vulnerability in SUN Jdk, JRE and SDK
Stack-based buffer overflow in the setDiffICM function in the Abstract Window Toolkit (AWT) in Java Runtime Environment (JRE) in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to execute arbitrary code via a crafted argument, aka Bug Id 6872357.
network
sun microsoft CWE-119
critical
9.3
2009-11-05 CVE-2009-3868 Buffer Errors vulnerability in SUN Jdk, JRE and SDK
Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK and JRE 1.4.x before 1.4.2_24 does not properly parse color profiles, which allows remote attackers to gain privileges via a crafted image file, aka Bug Id 6862970.
network
sun microsoft CWE-119
critical
9.3
2009-11-05 CVE-2009-3867 Buffer Errors vulnerability in SUN Jdk, JRE and SDK
Stack-based buffer overflow in the HsbParser.getSoundBank function in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to execute arbitrary code via a long file: URL in an argument, aka Bug Id 6854303.
network
sun microsoft CWE-119
critical
9.3
2009-11-05 CVE-2009-3866 Permissions, Privileges, and Access Controls vulnerability in SUN JDK and JRE
The Java Web Start Installer in Sun Java SE in JDK and JRE 6 before Update 17 does not properly use security model permissions when removing installer extensions, which allows remote attackers to execute arbitrary code by modifying a certain JNLP file to have a URL field that points to an unintended trusted application, aka Bug Id 6872824.
network
sun CWE-264
critical
9.3
2009-11-05 CVE-2009-3865 Code Injection vulnerability in SUN JDK and JRE
The launch method in the Deployment Toolkit plugin in Java Runtime Environment (JRE) in Sun Java SE in JDK and JRE 6 before Update 17 allows remote attackers to execute arbitrary commands via a crafted web page, aka Bug Id 6869752.
network
sun CWE-94
critical
9.3
2009-11-04 CVE-2009-3859 Buffer Errors vulnerability in Eeye products
Buffer overflow in eEye Retina WiFi Scanner 1.0.8.68, as used in Retina Network Security Scanner 5.10.14, allows user-assisted remote attackers to cause a denial of service (application crash) or execute arbitrary code via a .rws file with a long RWS010 entry.
network
eeye CWE-119
critical
9.3
2009-11-04 CVE-2009-3855 Remote Security vulnerability in Tivoli Storage Manager Express
Multiple unspecified vulnerabilities in the (1) UNIX and (2) Linux backup-archive clients, and the (3) OS/400 API client, in IBM Tivoli Storage Manager (TSM) 5.3 before 5.3.6.6, 5.4 before 5.4.2, and 5.5 before 5.5.1, when the MAILPROG option is enabled, allow attackers to read, modify, or delete arbitrary files via unknown vectors.
network
ibm
critical
9.3