Vulnerability Database

299,038

Total vulnerabilities in the database

CVE-2009-3886

The Java Web Start implementation in Sun Java SE 6 before Update 17 does not properly handle the interaction between a signed JAR file and a JNLP (1) application or (2) applet, which has unspecified impact and attack vectors, related to a "regression," aka Bug Id 6870531.

  • Published: Nov 9, 2009
  • Updated: Apr 13, 2023
  • CVE: CVE-2009-3886
  • Severity: High
  • Exploit:

CVSS v2:

  • Severity: High
  • Score: 7.5
  • AV:N/AC:L/Au:N/C:P/I:P/A:P

No CWE or OWASP classifications available.

Software From Fixed in
sun / jre 1.6.0-update_3 1.6.0-update_3.x
sun / jre 1.6.0-update_5 1.6.0-update_5.x
sun / jre 1.6.0-update_13 1.6.0-update_13.x
sun / jre 1.6.0-update_1 1.6.0-update_1.x
sun / jre 1.6.0-update_2 1.6.0-update_2.x
sun / jre 1.6.0-update_15 1.6.0-update_15.x
sun / jre 1.6.0-update_6 1.6.0-update_6.x
sun / jre 1.6.0-update_10 1.6.0-update_10.x
sun / jre 1.6.0-update_8 1.6.0-update_8.x
sun / jre 1.6.0-update_7 1.6.0-update_7.x
sun / jre 1.6.0-update_14 1.6.0-update_14.x
sun / jre - 1.6.0.x
sun / jre 1.6.0-update_4 1.6.0-update_4.x
sun / jre 1.6.0-update_9 1.6.0-update_9.x
sun / jre 1.6.0-update_12 1.6.0-update_12.x
sun / jre 1.6.0-update_11 1.6.0-update_11.x