CVE
- Id
- 39911
- CVE No.
- CVE-2009-2476
- Status
- Candidate
- Description
- The Java Management Extensions (JMX) implementation in Sun Java SE 6 before Update 15, and OpenJDK, does not properly enforce OpenType checks, which allows context-dependent attackers to bypass intended access restrictions by leveraging finalizer resurrection to obtain a reference to a privileged object.
- Phase
- Assigned (20090715)
- Votes
- None (candidate not yet proposed)
- Comments
Related CVE References
Id | CVE Id | CVE No. | Reference | Actions |
---|---|---|---|---|
438622 | 39911 | CVE-2009-2476 | CONFIRM:http://java.sun.com/javase/6/webnotes/6u15.html | View |
438623 | 39911 | CVE-2009-2476 | CONFIRM:http://sunsolve.sun.com/search/document.do?assetkey=1-21-125139-16-1 | View |
438624 | 39911 | CVE-2009-2476 | CONFIRM:https://bugzilla.redhat.com/show_bug.cgi?id=513220 | View |
438625 | 39911 | CVE-2009-2476 | APPLE:APPLE-SA-2009-09-03-1 | View |
438626 | 39911 | CVE-2009-2476 | URL:http://lists.apple.com/archives/security-announce/2009/Sep/msg00000.html | View |
438627 | 39911 | CVE-2009-2476 | FEDORA:FEDORA-2009-8329 | View |
438628 | 39911 | CVE-2009-2476 | URL:https://www.redhat.com/archives/fedora-package-announce/2009-August/msg00310.html | View |
438629 | 39911 | CVE-2009-2476 | FEDORA:FEDORA-2009-8337 | View |
438630 | 39911 | CVE-2009-2476 | URL:https://www.redhat.com/archives/fedora-package-announce/2009-August/msg00325.html | View |
438631 | 39911 | CVE-2009-2476 | GENTOO:GLSA-200911-02 | View |
438632 | 39911 | CVE-2009-2476 | URL:http://security.gentoo.org/glsa/glsa-200911-02.xml | View |
438633 | 39911 | CVE-2009-2476 | MANDRIVA:MDVSA-2009:209 | View |
438634 | 39911 | CVE-2009-2476 | URL:http://www.mandriva.com/security/advisories?name=MDVSA-2009:209 | View |
438635 | 39911 | CVE-2009-2476 | REDHAT:RHSA-2009:1200 | View |
438636 | 39911 | CVE-2009-2476 | URL:https://rhn.redhat.com/errata/RHSA-2009-1200.html | View |
438637 | 39911 | CVE-2009-2476 | REDHAT:RHSA-2009:1201 | View |
438638 | 39911 | CVE-2009-2476 | URL:https://rhn.redhat.com/errata/RHSA-2009-1201.html | View |
438639 | 39911 | CVE-2009-2476 | SUSE:SUSE-SR:2009:016 | View |
438640 | 39911 | CVE-2009-2476 | URL:http://lists.opensuse.org/opensuse-security-announce/2009-10/msg00001.html | View |
438641 | 39911 | CVE-2009-2476 | OVAL:oval:org.mitre.oval:def:10381 | View |
438642 | 39911 | CVE-2009-2476 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10381 | View |
438643 | 39911 | CVE-2009-2476 | SECUNIA:36162 | View |
438644 | 39911 | CVE-2009-2476 | URL:http://secunia.com/advisories/36162 | View |
438645 | 39911 | CVE-2009-2476 | SECUNIA:36176 | View |
438646 | 39911 | CVE-2009-2476 | URL:http://secunia.com/advisories/36176 | View |
438647 | 39911 | CVE-2009-2476 | SECUNIA:36180 | View |
438648 | 39911 | CVE-2009-2476 | URL:http://secunia.com/advisories/36180 | View |
438649 | 39911 | CVE-2009-2476 | SECUNIA:37386 | View |
438650 | 39911 | CVE-2009-2476 | URL:http://secunia.com/advisories/37386 | View |
438651 | 39911 | CVE-2009-2476 | VUPEN:ADV-2009-2543 | View |
Related JVN
Id | JVN No. | Title | Summary | CVE No. | CVE Id | CVSS_v2 | CVSS_v3 | JVN URL | Actions |
---|---|---|---|---|---|---|---|---|---|
39935 | JVNDB-2009-000020 | Movable Type におけるクロスサイトスクリプティングの脆弱性 | Movable Type には、クロスサイトスクリプティングの脆弱性が存在します。 | CVE-2009-2480 | 39911 | 4.3 | http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-000020.html | View |