CVE-2006-6009
published 2006-11-21CVE-2006-6009: Unspecified vulnerability in the Java Runtime Environment (JRE) Swing library in JDK and JRE 5.0 Update 7 and earlier allows attackers to obtain certain…
PriorityP419medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
1.71%
74.6th percentile
Unspecified vulnerability in the Java Runtime Environment (JRE) Swing library in JDK and JRE 5.0 Update 7 and earlier allows attackers to obtain certain information via unknown attack vectors, related to an untrusted applet accessing data in other applets.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| sun | jdk | <= 1.5.0 | — |
| sun | jdk | — | — |
| sun | jre | <= 1.5.0 | — |
| sun | jre | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Sun JRE/JDK up to 5.0.7 Runtime Environment Swing Library information disclosure (XFDB-30304 / SBV-13101)
vuldb·2026-04-28·CVSS 5.0
CVE-2006-6009 [MEDIUM] Sun JRE/JDK up to 5.0.7 Runtime Environment Swing Library information disclosure (XFDB-30304 / SBV-13101)
A vulnerability was found in Sun JRE and JDK up to 5.0.7 and classified as critical. This affects an unknown function of the component Runtime Environment Swing Library. Executing a manipulation can lead to information disclosure.
This vulnerability is tracked as CVE-2006-6009. The attack can be launched remotely. No exploit exists.
It is suggested to upgrade the affected component.
GHSA
GHSA-76f6-r3ww-rr8c: Unspecified vulnerability in the Java Runtime Environment (JRE) Swing library in JDK and JRE 5
ghsa_unreviewed·2022-05-01
CVE-2006-6009 [MEDIUM] GHSA-76f6-r3ww-rr8c: Unspecified vulnerability in the Java Runtime Environment (JRE) Swing library in JDK and JRE 5
Unspecified vulnerability in the Java Runtime Environment (JRE) Swing library in JDK and JRE 5.0 Update 7 and earlier allows attackers to obtain certain information via unknown attack vectors, related to an untrusted applet accessing data in other applets.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://secunia.com/advisories/22910http://securitytracker.com/id?1017229http://sunsolve.sun.com/search/document.do?assetkey=1-26-102622-1http://www.securityfocus.com/bid/21077http://www.vupen.com/english/advisories/2006/4523https://exchange.xforce.ibmcloud.com/vulnerabilities/30304http://secunia.com/advisories/22910http://securitytracker.com/id?1017229http://sunsolve.sun.com/search/document.do?assetkey=1-26-102622-1http://www.securityfocus.com/bid/21077http://www.vupen.com/english/advisories/2006/4523https://exchange.xforce.ibmcloud.com/vulnerabilities/30304
2006-11-21
Published