Loading...
Loading...
The Java Plug-in in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 6 Update 12, 11, and 10 does not properly parse crossdomain.xml files, which allows remote attackers to bypass intended access restrictions and connect to arbitrary sites via unknown vectors, aka CR 6798948.
March 25, 2009
April 23, 2026
See which npm, PyPI, Go, and Maven packages are affected by CVE-2009-1106
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.