Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2006-6731

25
FAUCET Score

CVE-2006-6731 describes multiple buffer overflows in various versions of Sun Java Development Kit (JDK), Java Runtime Environment (JRE), and Java System Development Kit (SDK). These vulnerabilities, potentially stemming from integer overflows, a stack overflow, and improper handling of negative values, could allow malicious Java applets to read, write, or execute local files. With a CVSS score of 9.3, this is a critical vulnerability, allowing unauthenticated attackers to achieve complete compromise (confidentiality, integrity, availability) with medium attack complexity over a network. Despite its high severity, there is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
1.5.0CPE matchmatch criteria
cpe:2.3:a:sun:jdk:1.5.0:-:*:*:*:*:*:*
1.5.0CPE matchmatch criteria
cpe:2.3:a:sun:jdk:1.5.0:update1:*:*:*:*:*:*
1.5.0CPE matchmatch criteria
cpe:2.3:a:sun:jdk:1.5.0:update2:*:*:*:*:*:*
1.5.0CPE matchmatch criteria
cpe:2.3:a:sun:jdk:1.5.0:update3:*:*:*:*:*:*
1.5.0CPE matchmatch criteria
cpe:2.3:a:sun:jdk:1.5.0:update4:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

9.3HIGH

AV:N/AC:M/Au:N/C:C/I:C/A:C

Confidentiality Impact
COMPLETE
Integrity Impact
COMPLETE
Availability Impact
COMPLETE
Access Vector
NETWORK
Access Complexity
MEDIUM
Authentication
NONE
Exploitability Score
8.6
Impact Score
10.0
CvssVersion
2.0

Exploit Intelligence

EPSS Score
3.75%
Probability of exploitation in next 30 days
EPSS Percentile
88.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0375 is in the 50th percentile among its peer group of 8,920 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (5)

redhatpatch availablevia redhat_api
Product: Extras for RHEL 3Fixed in: java-1.4.2-ibm-0:1.4.2.7-1jpp.4.el3
View patch
redhatpatch availablevia redhat_api
Product: Extras for RHEL 4Fixed in: java-1.4.2-ibm-0:1.4.2.7-1jpp.4.el4
View patch
redhatpatch availablevia redhat_api
Product: Extras for RHEL 4Fixed in: java-1.5.0-ibm-1:1.5.0.3-1jpp.3.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 2.1Fixed in: IBMJava2-JRE-1:1.3.1-12
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 2.1Fixed in: IBMJava2-SDK-1:1.3.1-11
View patch

Vendor Advisories (1)

redhatCVE-2006-6731Critical

security flaw

Jan 4, 2007

References

dev2dev.bea.com / pub/advisory/243
Third Party Advisory
docs.info.apple.com / article.html
Third Party Advisory
h20000.www2.hp.com / bizsupport/TechSupport/Document.jsp
Third Party Advisory
lists.apple.com / archives/Security-announce/2007/Dec/msg00001.html
Mailing ListThird Party Advisory
lists.suse.com / archive/suse-security-announce/2007-Jan/0003.html
Mailing ListThird Party Advisory
scary.beasts.org / security/CESA-2005-008.txt
Third Party Advisory
secunia.com / advisories/23445
Third Party Advisory
secunia.com / advisories/23650
Third Party Advisory
secunia.com / advisories/23835
Third Party Advisory
secunia.com / advisories/24099
Third Party Advisory
secunia.com / advisories/24189
Third Party Advisory
secunia.com / advisories/24468
Third Party Advisory
secunia.com / advisories/25283
Third Party Advisory
secunia.com / advisories/25404
Third Party Advisory
secunia.com / advisories/28115
Third Party Advisory
security.gentoo.org / glsa/glsa-200701-15.xml
Third Party Advisory
security.gentoo.org / glsa/glsa-200702-08.xml
Third Party Advisory
securitytracker.com / id
Third Party AdvisoryVDB Entry
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10134
Third Party Advisory
sunsolve.sun.com / search/document.do
Broken Link
gentoo.org / security/en/glsa/glsa-200705-20.xml
Third Party Advisory
kb.cert.org / vuls/id/149457
Third Party AdvisoryUS Government Resource
kb.cert.org / vuls/id/939609
Third Party AdvisoryUS Government Resource
novell.com / linux/security/advisories/2007_10_ibmjava.html
Third Party Advisory
redhat.com / support/errata/RHSA-2007-0062.html
Third Party Advisory
redhat.com / support/errata/RHSA-2007-0072.html
Third Party Advisory
redhat.com / support/errata/RHSA-2007-0073.html
Third Party AdvisoryVDB Entry
securityfocus.com / bid/21675
PatchThird Party AdvisoryVDB Entry
us-cert.gov / cas/techalerts/TA07-022A.html
Third Party AdvisoryUS Government Resource
vupen.com / english/advisories/2006/5073
Permissions Required
vupen.com / english/advisories/2007/0936
Permissions Required
vupen.com / english/advisories/2007/1814
Permissions Required
vupen.com / english/advisories/2007/4224
Permissions Required