CVE-2009-3869 is a critical stack-based buffer overflow vulnerability affecting the Abstract Window Toolkit (AWT) in Sun Java SE JDK and JRE versions 5.0 (before Update 22), 6 (before Update 17), 1.3.x (before 1.3.1_27), and 1.4.x (before 1.4.2_24). This flaw allows remote attackers to execute arbitrary code by supplying a specially crafted argument. With a CVSS score of 9.3, it is highly severe, requiring no authentication and moderate attack complexity, leading to complete compromise of confidentiality, integrity, and availability. While not on the CISA KEV catalog or currently experiencing active exploitation, a Metasploit module exists, indicating readily available exploit code, though community discussion and media coverage are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.5.0CPE matchmatch criteria | cpe:2.3:a:sun:jdk:1.5.0:update_1:*:*:*:*:*:* | ||
1.5.0CPE matchmatch criteria | cpe:2.3:a:sun:jdk:1.5.0:update_10:*:*:*:*:*:* | ||
1.5.0CPE matchmatch criteria | cpe:2.3:a:sun:jdk:1.5.0:update_11:*:*:*:*:*:* | ||
1.5.0CPE matchmatch criteria | cpe:2.3:a:sun:jdk:1.5.0:update_12:*:*:*:*:*:* | ||
1.5.0CPE matchmatch criteria | cpe:2.3:a:sun:jdk:1.5.0:update_13:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.