The Java Plug-in in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 6 Update 12, 11, and 10 does not properly parse crossdomain.xml files, which allows remote attackers to bypass intended access restrictions and connect to arbitrary sites via unknown vectors, aka CR 6798948.
References
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2009-03-25T23:00:00
Updated: 2018-10-10T18:57:01
Reserved: 2009-03-25T00:00:00
Link: CVE-2009-1106
JSON object: View
NVD Information
Status : Modified
Published: 2009-03-25T23:30:00.467
Modified: 2018-10-10T19:34:17.027
Link: CVE-2009-1106
JSON object: View
Redhat Information
No data.
CWE