CVE-2009-1719

CVSS V2 High 7.5 CVSS V3 None
Description
The Aqua Look and Feel for Java implementation in Java 1.5 on Mac OS X 10.5 allows remote attackers to execute arbitrary code via a call to the undocumented apple.laf.CColourUIResource constructor with a crafted value in the first argument, which is dereferenced as a pointer.
Overview
  • CVE ID
  • CVE-2009-1719
  • Assigner
  • cve@mitre.org
  • Vulnerability Status
  • Modified
  • Published Version
  • 2009-06-16T23:30:00
  • Last Modified Date
  • 2018-10-10T19:38:12
CPE Configuration (Product)
CPE Vulnerable Operator Version Start Version End
AND
cpe:2.3:a:apple:mac_os_x:10.5.6:*:*:*:*:*:*:* 0 OR
cpe:2.3:o:apple:mac_os_x:10.5:*:*:*:*:*:*:* 0 OR
cpe:2.3:o:apple:mac_os_x:10.5.0:*:*:*:*:*:*:* 0 OR
cpe:2.3:o:apple:mac_os_x:10.5.1:*:*:*:*:*:*:* 0 OR
cpe:2.3:o:apple:mac_os_x:10.5.2:*:*:*:*:*:*:* 0 OR
cpe:2.3:o:apple:mac_os_x:10.5.2:2008-002:*:*:*:*:*:* 0 OR
cpe:2.3:o:apple:mac_os_x:10.5.3:*:*:*:*:*:*:* 0 OR
cpe:2.3:o:apple:mac_os_x:10.5.4:*:*:*:*:*:*:* 0 OR
cpe:2.3:o:apple:mac_os_x:10.5.5:*:*:*:*:*:*:* 0 OR
cpe:2.3:o:apple:mac_os_x:10.5.6:*:*:*:*:*:*:* 0 OR
cpe:2.3:o:apple:mac_os_x:10.5.7:*:*:*:*:*:*:* 0 OR
cpe:2.3:o:apple:mac_os_x_server:10.5:*:*:*:*:*:*:* 0 OR
cpe:2.3:o:apple:mac_os_x_server:10.5.0:*:*:*:*:*:*:* 0 OR
cpe:2.3:o:apple:mac_os_x_server:10.5.1:*:*:*:*:*:*:* 0 OR
cpe:2.3:o:apple:mac_os_x_server:10.5.2:*:*:*:*:*:*:* 0 OR
cpe:2.3:o:apple:mac_os_x_server:10.5.3:*:*:*:*:*:*:* 0 OR
cpe:2.3:o:apple:mac_os_x_server:10.5.4:*:*:*:*:*:*:* 0 OR
cpe:2.3:o:apple:mac_os_x_server:10.5.5:*:*:*:*:*:*:* 0 OR
cpe:2.3:o:apple:mac_os_x_server:10.5.6:*:*:*:*:*:*:* 0 OR
cpe:2.3:o:apple:mac_os_x_server:10.5.7:*:*:*:*:*:*:* 0 OR
cpe:2.3:a:sun:jre:1.5.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:sun:jre:1.5.0:update1:*:*:*:*:*:* 1 OR
cpe:2.3:a:sun:jre:1.5.0:update10:*:*:*:*:*:* 1 OR
cpe:2.3:a:sun:jre:1.5.0:update11:*:*:*:*:*:* 1 OR
cpe:2.3:a:sun:jre:1.5.0:update12:*:*:*:*:*:* 1 OR
cpe:2.3:a:sun:jre:1.5.0:update13:*:*:*:*:*:* 1 OR
cpe:2.3:a:sun:jre:1.5.0:update14:*:*:*:*:*:* 1 OR
cpe:2.3:a:sun:jre:1.5.0:update15:*:*:*:*:*:* 1 OR
cpe:2.3:a:sun:jre:1.5.0:update16:*:*:*:*:*:* 1 OR
cpe:2.3:a:sun:jre:1.5.0:update17:*:*:*:*:*:* 1 OR
cpe:2.3:a:sun:jre:1.5.0:update2:*:*:*:*:*:* 1 OR
cpe:2.3:a:sun:jre:1.5.0:update3:*:*:*:*:*:* 1 OR
cpe:2.3:a:sun:jre:1.5.0:update4:*:*:*:*:*:* 1 OR
cpe:2.3:a:sun:jre:1.5.0:update5:*:*:*:*:*:* 1 OR
cpe:2.3:a:sun:jre:1.5.0:update6:*:*:*:*:*:* 1 OR
cpe:2.3:a:sun:jre:1.5.0:update7:*:*:*:*:*:* 1 OR
cpe:2.3:a:sun:jre:1.5.0:update8:*:*:*:*:*:* 1 OR
cpe:2.3:a:sun:jre:1.5.0:update9:*:*:*:*:*:* 1 OR
cpe:2.3:a:sun:jre:1.5.0_11-b03:*:*:*:*:*:*:* 1 OR
CVSS Version 2
  • Version
  • 2.0
  • Vector String
  • AV:N/AC:L/Au:N/C:P/I:P/A:P
  • Access Vector
  • NETWORK
  • Access Compatibility
  • LOW
  • Authentication
  • NONE
  • Confidentiality Impact
  • PARTIAL
  • Integrity Impact
  • PARTIAL
  • Availability Impact
  • PARTIAL
  • Base Score
  • 7.5
  • Severity
  • HIGH
  • Exploitability Score
  • 10
  • Impact Score
  • 6.4
History
Created Old Value New Value Data Type Notes
2022-05-10 18:32:47 Added to TrackCVE