CVE-2009-1098 describes a critical buffer overflow vulnerability in multiple versions of Java SE Development Kit (JDK) and Java Runtime Environment (JRE), including 5.0 Update 17 and earlier, and 6 Update 12 and earlier. This flaw allows remote attackers to access files or execute arbitrary code by enticing a user to open a specially crafted GIF image. The vulnerability carries a CVSS score of 9.3, indicating critical severity. It is exploitable over the network with medium attack complexity, potentially leading to complete compromise of confidentiality, integrity, and availability. Despite its high severity, there is no evidence of active exploitation (not in KEV), nor are there public exploits available in Metasploit or ExploitDB. Community discussion and media coverage for this CVE are minimal, suggesting it has not garnered significant attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.5.0CPE matchmatch criteria | cpe:2.3:a:sun:jdk:*:update17:*:*:*:*:*:* | ||
<= 1.6.0CPE matchmatch criteria | cpe:2.3:a:sun:jdk:*:update_12:*:*:*:*:*:* | ||
1.5.0CPE matchmatch criteria | cpe:2.3:a:sun:jdk:1.5.0:*:*:*:*:*:*:* | ||
1.5.0CPE matchmatch criteria | cpe:2.3:a:sun:jdk:1.5.0:update1:*:*:*:*:*:* | ||
1.5.0CPE matchmatch criteria | cpe:2.3:a:sun:jdk:1.5.0:update10:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.