Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2009-1719

Quick assessment

Affected
n/a n/a
Exploitation
High exploitation probability; assess promptly
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Solaris系统的Java运行时环境(JRE)为JAVA应用程序提供可靠的运行环境。 Java实现的Aqua Look and Feel界面包中没有正确地验证对apple.laf.CColourUIResource(long, int, int ,int, int)构建器所传送的参数,如果向第一个参数传送了超长的整数值,该值会被解释为到Objective-C对象的指针。通过创建特殊的内存结构并向第一个参数传送指针,攻击者就可以执行任意代码 。

AI Predicted 8.1 Difficulty: Easy EPSS 5.12% · P92

Possible ATT&CK Techniques 1 AI

T1190 · Exploit Public-Facing Application
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2009-1719

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
The Aqua Look and Feel for Java implementation in Java 1.5 on Mac OS X 10.5 allows remote attackers to execute arbitrary code via a call to the undocumented apple.laf.CColourUIResource constructor with a crafted value in the first argument, which is dereferenced as a pointer.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Sun Java运行时环境Aqua Look and Feel界面包权限提升漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Solaris系统的Java运行时环境(JRE)为JAVA应用程序提供可靠的运行环境。 Java实现的Aqua Look and Feel界面包中没有正确地验证对apple.laf.CColourUIResource(long, int, int ,int, int)构建器所传送的参数,如果向第一个参数传送了超长的整数值,该值会被解释为到Objective-C对象的指针。通过创建特殊的内存结构并向第一个参数传送指针,攻击者就可以执行任意代码 。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
- n/a n/a -

II. Public POCs for CVE-2009-1719

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2009-1719

请登录查看更多情报信息。

Vendor Advisories for CVE-2009-1719 (6)

Mailing List Discussions for CVE-2009-1719 (1)

Same Patch Batch · n/a · 2009-06-16 · 18 CVEs total

CVE-2009-2083 Drupal Taxonomy Manager Administrative Page跨站脚本攻击漏洞
CVE-2009-2081 phpWebThings "help.php" 目录遍历漏洞
CVE-2009-2080 MRCGIGUY The Ticket System "admin.php" 权限许可漏洞
CVE-2009-2079 Drupal "Taxonomy Manager Administrative Page" 跨站脚本攻击漏洞
CVE-2009-2078 Drupal Booktree多个跨站脚本攻击漏洞
CVE-2009-2077 Angrydonuts Views模块安全绕过和访问控制漏洞
CVE-2009-2076 Drupal 模块"Views" 跨站脚本攻击漏洞
CVE-2009-2075 Angrydonuts Nodequeue安全绕过和访问控制漏洞
CVE-2009-2074 Drupal 模块"Nodequeue" 跨站脚本攻击漏洞
CVE-2009-1389 Linux kernel 缓冲区错误漏洞
CVE-2009-2082 Creative Web Solutions Multiple level CMS "insidepage.php" SQL注入漏洞
CVE-2009-2011 DX Studio Player shell.execute JavaScript API方法远程任意外壳指令注入漏洞
CVE-2009-1390 Mutt 'mutt_ssl.c' X.509 Certificate Chain 安全绕过漏洞
CVE-2008-5515 Apache Tomcat 路径遍历漏洞
CVE-2009-2084 Llnl Simple Linux Utility for Resource Management本地特权升级漏洞
CVE-2009-1761 CA ARCserve Backup消息引擎拒绝服务漏洞
CVE-2009-1391 Compress::Raw::Zlib Perl模块单字节溢出漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2009-1719

No comments yet


Leave a comment