CVE-2006-2426
published 2006-05-17CVE-2006-2426: Sun Java Runtime Environment (JRE) 1.5.0_6 and earlier, JDK 1.5.0_6 and earlier, and SDK 1.5.0_6 and earlier allows remote attackers to cause a denial of…
PriorityP334medium6.4CVSS 2.0
AVNACLAuNCNIPAP
EXPLOIT
EPSS
12.69%
95.8th percentile
Sun Java Runtime Environment (JRE) 1.5.0_6 and earlier, JDK 1.5.0_6 and earlier, and SDK 1.5.0_6 and earlier allows remote attackers to cause a denial of service (disk consumption) by using the Font.createFont function to create temporary files of arbitrary size in the %temp% directory.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| sun | jdk | — | — |
| sun | jre | — | — |
| sun | sdk | — | — |
CVSS provenance
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:P
vendor_redhat6.4MEDIUM
vendor_ubuntu6.4MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-mwm5-6468-q7xv: Sun Java Runtime Environment (JRE) 1
ghsa_unreviewed·2022-05-01
CVE-2006-2426 [MEDIUM] GHSA-mwm5-6468-q7xv: Sun Java Runtime Environment (JRE) 1
Sun Java Runtime Environment (JRE) 1.5.0_6 and earlier, JDK 1.5.0_6 and earlier, and SDK 1.5.0_6 and earlier allows remote attackers to cause a denial of service (disk consumption) by using the Font.createFont function to create temporary files of arbitrary size in the %temp% directory.
Ubuntu
OpenJDK vulnerabilities
vendor_ubuntu·2009-03-26·CVSS 6.4
CVE-2009-1101 [MEDIUM] OpenJDK vulnerabilities
Title: OpenJDK vulnerabilities
Summary: OpenJDK vulnerabilities
It was discovered that font creation could leak temporary files.
If a user were tricked into loading a malicious program or applet,
a remote attacker could consume disk space, leading to a denial of
service. (CVE-2006-2426, CVE-2009-1100)
It was discovered that the lightweight HttpServer did not correctly close
files on dataless connections. A remote attacker could send specially
crafted requests, leading to a denial of service. (CVE-2009-1101)
The Java Runtime Environment did not correctly validate certain generated
code. If a user were tricked into running a malicious applet a remote
attacker could execute arbitrary code. (CVE-2009-1102)
It was discovered that LDAP connections did not close correctly.
A remote attacker
Red Hat
Untrusted applet causes DoS by filling up disk space
vendor_redhat·2006-05-14·CVSS 6.4
CVE-2006-2426 [MEDIUM] Untrusted applet causes DoS by filling up disk space
Untrusted applet causes DoS by filling up disk space
Sun Java Runtime Environment (JRE) 1.5.0_6 and earlier, JDK 1.5.0_6 and earlier, and SDK 1.5.0_6 and earlier allows remote attackers to cause a denial of service (disk consumption) by using the Font.createFont function to create temporary files of arbitrary size in the %temp% directory.
No detection rules found.
No writeups or analysis indexed.
http://secunia.com/advisories/20132http://secunia.com/advisories/20457http://secunia.com/advisories/34489http://secunia.com/advisories/34495http://secunia.com/advisories/34496http://secunia.com/advisories/34632http://secunia.com/advisories/34675http://securityreason.com/securityalert/909http://support.avaya.com/elmodocs2/security/ASA-2009-108.htmhttp://support.avaya.com/elmodocs2/security/ASA-2009-109.htmhttp://www.debian.org/security/2009/dsa-1769http://www.illegalaccess.org/exploit/FullDiskApplet.htmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2009:137http://www.mandriva.com/security/advisories?name=MDVSA-2009:162http://www.novell.com/linux/security/advisories/2006-06-02.htmlhttp://www.osvdb.org/25561http://www.redhat.com/support/errata/RHSA-2009-0392.htmlhttp://www.redhat.com/support/errata/RHSA-2009-0394.htmlhttp://www.securityfocus.com/archive/1/434001/100/0/threadedhttp://www.securityfocus.com/bid/17981http://www.ubuntu.com/usn/usn-748-1http://www.vupen.com/english/advisories/2006/1824https://exchange.xforce.ibmcloud.com/vulnerabilities/26493https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10609https://rhn.redhat.com/errata/RHSA-2009-0377.htmlhttp://secunia.com/advisories/20132http://secunia.com/advisories/20457http://secunia.com/advisories/34489http://secunia.com/advisories/34495http://secunia.com/advisories/34496http://secunia.com/advisories/34632http://secunia.com/advisories/34675http://securityreason.com/securityalert/909http://support.avaya.com/elmodocs2/security/ASA-2009-108.htmhttp://support.avaya.com/elmodocs2/security/ASA-2009-109.htmhttp://www.debian.org/security/2009/dsa-1769http://www.illegalaccess.org/exploit/FullDiskApplet.htmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2009:137http://www.mandriva.com/security/advisories?name=MDVSA-2009:162http://www.novell.com/linux/security/advisories/2006-06-02.htmlhttp://www.osvdb.org/25561http://www.redhat.com/support/errata/RHSA-2009-0392.htmlhttp://www.redhat.com/support/errata/RHSA-2009-0394.htmlhttp://www.securityfocus.com/archive/1/434001/100/0/threadedhttp://www.securityfocus.com/bid/17981http://www.ubuntu.com/usn/usn-748-1http://www.vupen.com/english/advisories/2006/1824https://exchange.xforce.ibmcloud.com/vulnerabilities/26493https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10609https://rhn.redhat.com/errata/RHSA-2009-0377.html
2006-05-17
Published