Tenable calculates a dynamic VPR for every vulnerability. VPR combines vulnerability information with threat intelligence and machine learning algorithms to predict which vulnerabilities are most likely to be exploited in attacks. Read more about what VPR is and how it is different from CVSS.
VPR Score: 9.3
https://access.redhat.com/security/cve/cve-2009-2409
https://access.redhat.com/security/cve/cve-2009-3728
https://access.redhat.com/security/cve/cve-2009-3867
https://access.redhat.com/security/cve/cve-2009-3868
https://access.redhat.com/security/cve/cve-2009-3869
https://access.redhat.com/security/cve/cve-2009-3871
https://access.redhat.com/security/cve/cve-2009-3873
https://access.redhat.com/security/cve/cve-2009-3874
https://access.redhat.com/security/cve/cve-2009-3875
https://access.redhat.com/security/cve/cve-2009-3876
https://access.redhat.com/security/cve/cve-2009-3877
https://access.redhat.com/security/cve/cve-2009-3879
https://access.redhat.com/security/cve/cve-2009-3880
https://access.redhat.com/security/cve/cve-2009-3881
https://access.redhat.com/security/cve/cve-2009-3882
https://access.redhat.com/security/cve/cve-2009-3883
https://access.redhat.com/security/cve/cve-2009-3884
Severity: Critical
ID: 42455
File Name: redhat-RHSA-2009-1571.nasl
Version: 1.33
Type: local
Agent: unix
Family: Red Hat Local Security Checks
Published: 11/11/2009
Updated: 1/14/2021
Dependencies: 12634
Risk Factor: Critical
VPR Score: 9.3
Base Score: 10
Temporal Score: 7.8
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C
Temporal Vector: E:POC/RL:OF/RC:C
CPE: p-cpe:/a:redhat:enterprise_linux:java-1.5.0-sun, p-cpe:/a:redhat:enterprise_linux:java-1.5.0-sun-demo, p-cpe:/a:redhat:enterprise_linux:java-1.5.0-sun-devel, p-cpe:/a:redhat:enterprise_linux:java-1.5.0-sun-jdbc, p-cpe:/a:redhat:enterprise_linux:java-1.5.0-sun-plugin, p-cpe:/a:redhat:enterprise_linux:java-1.5.0-sun-src, cpe:/o:redhat:enterprise_linux:4, cpe:/o:redhat:enterprise_linux:4.8, cpe:/o:redhat:enterprise_linux:5, cpe:/o:redhat:enterprise_linux:5.4
Required KB Items: Host/local_checks_enabled, Host/RedHat/release, Host/RedHat/rpm-list, Host/cpu
Exploit Available: true
Exploit Ease: Exploits are available
Patch Publication Date: 11/10/2009
Vulnerability Publication Date: 7/30/2009
CANVAS (CANVAS)
Core Impact
Metasploit (Sun Java JRE AWT setDiffICM Buffer Overflow)
CVE: CVE-2009-2409, CVE-2009-3728, CVE-2009-3867, CVE-2009-3868, CVE-2009-3869, CVE-2009-3871, CVE-2009-3873, CVE-2009-3874, CVE-2009-3875, CVE-2009-3876, CVE-2009-3877, CVE-2009-3879, CVE-2009-3880, CVE-2009-3881, CVE-2009-3882, CVE-2009-3883, CVE-2009-3884, CVE-2010-0079
BID: 36881