CVE-2009-2720: Medium severity java vulnerability
Published Aug 10, 2009
·Updated
Unspecified vulnerability in the javax.swing.plaf.synth.SynthContext.isSubregion method in the Swing implementation in Sun Java SE 6 before Update 15 allows context-dependent attackers to cause a denial of service (NullPointerException in the Jemmy library) via unknown vectors.
Affected Software
1 affected component
Java<=6
Remediation
Patch Available
Event History
Aug 10, 2009
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2009-2720?
CVE-2009-2720 has been classified as a vulnerability that can lead to denial of service.
2
How does CVE-2009-2720 affect Java SE users?
CVE-2009-2720 can allow context-dependent attackers to cause a NullPointerException, impacting application stability.
3
What versions of Java SE are affected by CVE-2009-2720?
CVE-2009-2720 affects Sun Java SE 6 prior to Update 15.
4
Is there a patch available for CVE-2009-2720?
Yes, users are advised to update to Java SE 6 Update 15 or later to mitigate CVE-2009-2720.
5
What types of attacks are possible due to CVE-2009-2720?
CVE-2009-2720 can lead to a Denial of Service attack through the exploitation of the SynthContext.isSubregion method.