CVE-2009-2205Improper Restriction of Operations within the Bounds of a Memory Buffer in Apple Java 1.4

Severity
6.8MEDIUMNVD
EPSS
0.8%
top 25.30%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 9
Latest updateMay 2

Description

Stack-based buffer overflow in the Java Web Start command launcher in Java for Mac OS X 10.5 before Update 5 allows attackers to execute arbitrary code or cause a denial of service (application crash) via unspecified vectors.

CVSS vector

AV:N/AC:M/C:P/I:P/A:PExploitability: 8.6 | Impact: 6.4

Affected Packages5 packages

NVDapple/mac_os_x9 versions+8
NVDapple/mac_os_x_server9 versions+8

Patches

🔴Vulnerability Details

2
GHSA
GHSA-82xg-93p7-mqqc: Stack-based buffer overflow in the Java Web Start command launcher in Java for Mac OS X 102022-05-02
CVEList
CVE-2009-2205: Stack-based buffer overflow in the Java Web Start command launcher in Java for Mac OS X 102009-09-09
CVE-2009-2205 — Apple Java 1.4 vulnerability | cvebase