CVE-2009-1100 describes multiple unspecified denial-of-service vulnerabilities in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) versions 5.0 Update 17 and earlier, and 6 Update 12 and earlier. These flaws allow remote attackers to exhaust disk space through the creation of temporary font files, specifically related to "limits on Font creation" (CR 6522586) and another unspecified vector (CR 6632886). The vulnerability has a CVSS score of 5.0, indicating a medium severity with a network attack vector, low attack complexity, no authentication required, and a partial impact on availability (disk consumption). There is no evidence of active exploitation, no known exploit code in Metasploit, Nuclei, or ExploitDB, and it has received no community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.5.0CPE matchmatch criteria | cpe:2.3:a:sun:jdk:*:update17:*:*:*:*:*:* | ||
1.5.0CPE matchmatch criteria | cpe:2.3:a:sun:jdk:1.5.0:*:*:*:*:*:*:* | ||
1.5.0CPE matchmatch criteria | cpe:2.3:a:sun:jdk:1.5.0:update1:*:*:*:*:*:* | ||
1.5.0CPE matchmatch criteria | cpe:2.3:a:sun:jdk:1.5.0:update10:*:*:*:*:*:* | ||
1.5.0CPE matchmatch criteria | cpe:2.3:a:sun:jdk:1.5.0:update11:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:N/I:N/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.