CVE-2006-2426
Last modified
CVE-2006-2426 is a vulnerability of currently unknown severity. Sun Java Runtime Environment (JRE) 1.5.0_6 and earlier, JDK 1.5.0_6 and earlier, and SDK 1.5.0_6 and earlier allows remote attackers to cause a denial of service (disk consumption) by using the Font.createFont function to create temporary files of arbitrary size in the %temp% directory.. EPSS estimates a 12.69% chance of exploitation in the next 30 days.
Description
Sun Java Runtime Environment (JRE) 1.5.0_6 and earlier, JDK 1.5.0_6 and earlier, and SDK 1.5.0_6 and earlier allows remote attackers to cause a denial of service (disk consumption) by using the Font.createFont function to create temporary files of arbitrary size in the %temp% directory.
Metrics
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Sun | Jdk | 1.5.0 | Update6 |
| Sun | Jre | 1.5.0 | Update6 |
| Sun | Sdk | 1.5.0_6 | — |
References
- http://secunia.com/advisories/20132Vendor Advisory
- http://secunia.com/advisories/20132Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2006-2426?
How severe is CVE-2006-2426?
How do I fix CVE-2006-2426?
Are you affected by CVE-2006-2426?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
