CVE-2009-1671
Multiple buffer overflows in the Deployment Toolkit ActiveX control in deploytk.dll 6.0.130.3 in Sun Java SE Runtime Environment (aka JRE) 6 Update 13 allow remote attackers to execute arbitrary code via a long string argument to the (1) setInstallerType, (2) setAdditionalPackages, (3) compareVersion, (4) getStaticCLSID, or (5) launch method.
- Affected products
- Java Platform, Sun Java Runtime Environment
- Sun Jre
- = 6
- Fix
- Available
- CVSS 2.0
- 9.3 HIGH
- EPSS
- 10.3% (95th percentile)
- Weakness
- CWE-119
- NVD status
- Modified
- Published
- 2009-05-18
CVE-2009-1671 at NVD
1 known exploit for CVE-2009-1671
Proof-of-concept code and exploit modules indexed by Sploitus