CVE-2009-2676

Sun Java SE/JRE <6.14 - RCE

Title source: llm

Description

Unspecified vulnerability in JNLPAppletlauncher in Sun Java SE, and SE for Business, in JDK and JRE 6 Update 14 and earlier and JDK and JRE 5.0 Update 19 and earlier; and Java SE for Business in SDK and JRE 1.4.2_21 and earlier; allows remote attackers to create or modify arbitrary files via vectors involving an untrusted Java applet that accesses an old version of JNLPAppletLauncher.

Scores

EPSS 0.1422
EPSS Percentile 94.3%

Classification

Status draft

Affected Products (50)

sun/java_se
sun/java_se
sun/jdk < 1.5.0
sun/jdk < 1.6.0
sun/jdk
sun/jdk
sun/jdk
sun/jdk
sun/jdk
sun/jdk
sun/jdk
sun/jdk
sun/jdk
sun/jdk
sun/jdk
... and 35 more

Timeline

Published Aug 05, 2009
Tracked Since Feb 18, 2026