CVE-2006-6736
published 2006-12-26CVE-2006-6736: Unspecified vulnerability in Sun Java Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 6 and earlier, Java System Development Kit (SDK) and…
PriorityP419medium4.3CVSS 2.0
AVNACMAuNCPINAN
EPSS
2.31%
81.4th percentile
Unspecified vulnerability in Sun Java Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 6 and earlier, Java System Development Kit (SDK) and JRE 1.4.2_12 and earlier 1.4.x versions, and SDK and JRE 1.3.1_18 and earlier allows attackers to use untrusted applets to "access data in other applets," aka "The second issue."
Affected
66 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| sun | jdk | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
security flaw
vendor_redhat·2007-01-04·CVSS 4.3
CVE-2006-6736 [MEDIUM] security flaw
security flaw
Unspecified vulnerability in Sun Java Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 6 and earlier, Java System Development Kit (SDK) and JRE 1.4.2_12 and earlier 1.4.x versions, and SDK and JRE 1.3.1_18 and earlier allows attackers to use untrusted applets to "access data in other applets," aka "The second issue."
GHSA
GHSA-prhw-3wm7-2p9g: Unspecified vulnerability in Sun Java Development Kit (JDK) and Java Runtime Environment (JRE) 5
ghsa_unreviewed·2022-05-01
CVE-2006-6736 [MEDIUM] GHSA-prhw-3wm7-2p9g: Unspecified vulnerability in Sun Java Development Kit (JDK) and Java Runtime Environment (JRE) 5
Unspecified vulnerability in Sun Java Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 6 and earlier, Java System Development Kit (SDK) and JRE 1.4.2_12 and earlier 1.4.x versions, and SDK and JRE 1.3.1_18 and earlier allows attackers to use untrusted applets to "access data in other applets," aka "The second issue."
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2006-6736 security flaw
bugzilla·2018-08-16·CVSS 4.3
CVE-2006-6736 [MEDIUM] CVE-2006-6736 security flaw
CVE-2006-6736 security flaw
Flaw bug created to hold information about an old flaw we knew something about. For more details see the MITRE CVE description.
Discussion:
MITRE description:
Unspecified vulnerability in Sun Java Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 6 and earlier, Java System Development Kit (SDK) and JRE 1.4.2_12 and earlier 1.4.x versions, and SDK and JRE 1.3.1_18 and earlier allows attackers to use untrusted applets to "access data in other applets," aka "The second issue."
Bugzilla
CVE-2006-6736 Multiple JRE flaws (CVE-2006-6737 CVE-2006-6745 CVE-2006-6731 CVE-2006-4339)
bugzilla·2007-02-09·CVSS 4.3
CVE-2006-6736 [MEDIUM] CVE-2006-6736 Multiple JRE flaws (CVE-2006-6737 CVE-2006-6745 CVE-2006-6731 CVE-2006-4339)
CVE-2006-6736 Multiple JRE flaws (CVE-2006-6737 CVE-2006-6745 CVE-2006-6731 CVE-2006-4339)
IBM fixed a number of flaws in their Java Runtime Environment in 1.5.0 SR3:
http://www-128.ibm.com/developerworks/java/jdk/alerts/
Two vulnerabilities in the Java Runtime Environment may
independently allow an untrusted applet to access data in other
applets. CVE-2006-6736 CVE-2006-6737 (sun#102732)
Two vulnerabilities in the Java(TM) Runtime Environment with
serialization may independently allow an untrusted applet or
application to elevate its privileges. (sun#102731) CVE-2006-6745
Two buffer overflow vulnerabilities in the Java(TM) Runtime
Environment may independently allow an untrusted applet to
elevate its privileges. For example, an applet may grant
itself permissions to read and write lo
Bugzilla
CVE-2006-6736 Multiple JRE flaws (CVE-2006-6737 CVE-2006-6731 CVE-2006-4339)
bugzilla·2007-02-02·CVSS 4.3
CVE-2006-6736 [MEDIUM] CVE-2006-6736 Multiple JRE flaws (CVE-2006-6737 CVE-2006-6731 CVE-2006-4339)
CVE-2006-6736 Multiple JRE flaws (CVE-2006-6737 CVE-2006-6731 CVE-2006-4339)
IBM fixed a number of flaws in their Java Runtime Environment in 1.3.1 SR10a. A
security update is required.
http://www-128.ibm.com/developerworks/java/jdk/alerts/
Two vulnerabilities in the Java Runtime Environment may
independently allow an untrusted applet to access data in other
applets. CVE-2006-6736 CVE-2006-6737 (sun#102732)
Two buffer overflow vulnerabilities in the Java(TM) Runtime
Environment may independently allow an untrusted applet to
elevate its privileges. For example, an applet may grant
itself permissions to read and write local files or execute
local applications that are accessible to the user running the
untrusted applet. (sun#102729) CVE-2006-6731
public=20060104,impact=critical
An RSA(1
Bugzilla
CVE-2006-6736 Multiple JRE flaws (CVE-2006-6737 CVE-2006-6745 CVE-2006-6731 CVE-2006-4339)
bugzilla·2007-02-02·CVSS 4.3
CVE-2006-6736 [MEDIUM] CVE-2006-6736 Multiple JRE flaws (CVE-2006-6737 CVE-2006-6745 CVE-2006-6731 CVE-2006-4339)
CVE-2006-6736 Multiple JRE flaws (CVE-2006-6737 CVE-2006-6745 CVE-2006-6731 CVE-2006-4339)
+++ This bug was initially created as a clone of Bug #226981 +++
IBM fixed a number of flaws in their Java Runtime Environment in 1.4.2 SR7. A
security update is required for java-ibm-1.4.2 for RHEL3 Extras
http://www-128.ibm.com/developerworks/java/jdk/alerts/
Two vulnerabilities in the Java Runtime Environment may
independently allow an untrusted applet to access data in other
applets. CVE-2006-6736 CVE-2006-6737 (sun#102732)
Two vulnerabilities in the Java(TM) Runtime Environment with
serialization may independently allow an untrusted applet or
application to elevate its privileges. (sun#102731) CVE-2006-6745
Two buffer overflow vulnerabilities in the Java(TM) Runtime
Environment may indepen
Bugzilla
CVE-2006-6736 Multiple JRE flaws (CVE-2006-6737 CVE-2006-6745 CVE-2006-6731 CVE-2006-4339)
bugzilla·2007-02-02·CVSS 4.3
CVE-2006-6736 [MEDIUM] CVE-2006-6736 Multiple JRE flaws (CVE-2006-6737 CVE-2006-6745 CVE-2006-6731 CVE-2006-4339)
CVE-2006-6736 Multiple JRE flaws (CVE-2006-6737 CVE-2006-6745 CVE-2006-6731 CVE-2006-4339)
IBM fixed a number of flaws in their Java Runtime Environment in 1.4.2 SR7. A
security update is required for java-ibm-1.4.2 for RHEL4 Extras
http://www-128.ibm.com/developerworks/java/jdk/alerts/
Two vulnerabilities in the Java Runtime Environment may
independently allow an untrusted applet to access data in other
applets. CVE-2006-6736 CVE-2006-6737 (sun#102732)
Two vulnerabilities in the Java(TM) Runtime Environment with
serialization may independently allow an untrusted applet or
application to elevate its privileges. (sun#102731) CVE-2006-6745
Two buffer overflow vulnerabilities in the Java(TM) Runtime
Environment may independently allow an untrusted applet to
elevate its privileges. For ex
http://docs.info.apple.com/article.html?artnum=307177http://lists.apple.com/archives/Security-announce/2007/Dec/msg00001.htmlhttp://lists.suse.com/archive/suse-security-announce/2007-Jan/0003.htmlhttp://secunia.com/advisories/23398http://secunia.com/advisories/23650http://secunia.com/advisories/23835http://secunia.com/advisories/24099http://secunia.com/advisories/24189http://secunia.com/advisories/25404http://secunia.com/advisories/26049http://secunia.com/advisories/26119http://secunia.com/advisories/28115http://security.gentoo.org/glsa/glsa-200701-15.xmlhttp://security.gentoo.org/glsa/glsa-200702-08.xmlhttp://securitytracker.com/id?1017427http://sunsolve.sun.com/search/document.do?assetkey=1-26-102732-1http://support.novell.com/techcenter/psdb/4f850d1e2b871db609de64ec70f0089c.htmlhttp://support.novell.com/techcenter/psdb/d2f549cc040cd81ae4a268bb5edfe918.htmlhttp://www.gentoo.org/security/en/glsa/glsa-200705-20.xmlhttp://www.novell.com/linux/security/advisories/2007_10_ibmjava.htmlhttp://www.novell.com/linux/security/advisories/2007_45_java.htmlhttp://www.redhat.com/support/errata/RHSA-2007-0062.htmlhttp://www.redhat.com/support/errata/RHSA-2007-0072.htmlhttp://www.redhat.com/support/errata/RHSA-2007-0073.htmlhttp://www.securityfocus.com/bid/21674http://www.vupen.com/english/advisories/2006/5075http://www.vupen.com/english/advisories/2007/4224https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9729http://docs.info.apple.com/article.html?artnum=307177http://lists.apple.com/archives/Security-announce/2007/Dec/msg00001.htmlhttp://lists.suse.com/archive/suse-security-announce/2007-Jan/0003.htmlhttp://secunia.com/advisories/23398http://secunia.com/advisories/23650http://secunia.com/advisories/23835http://secunia.com/advisories/24099http://secunia.com/advisories/24189http://secunia.com/advisories/25404http://secunia.com/advisories/26049http://secunia.com/advisories/26119http://secunia.com/advisories/28115http://security.gentoo.org/glsa/glsa-200701-15.xmlhttp://security.gentoo.org/glsa/glsa-200702-08.xmlhttp://securitytracker.com/id?1017427http://sunsolve.sun.com/search/document.do?assetkey=1-26-102732-1http://support.novell.com/techcenter/psdb/4f850d1e2b871db609de64ec70f0089c.htmlhttp://support.novell.com/techcenter/psdb/d2f549cc040cd81ae4a268bb5edfe918.htmlhttp://www.gentoo.org/security/en/glsa/glsa-200705-20.xmlhttp://www.novell.com/linux/security/advisories/2007_10_ibmjava.htmlhttp://www.novell.com/linux/security/advisories/2007_45_java.htmlhttp://www.redhat.com/support/errata/RHSA-2007-0062.htmlhttp://www.redhat.com/support/errata/RHSA-2007-0072.htmlhttp://www.redhat.com/support/errata/RHSA-2007-0073.htmlhttp://www.securityfocus.com/bid/21674http://www.vupen.com/english/advisories/2006/5075http://www.vupen.com/english/advisories/2007/4224https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9729
2006-12-26
Published