← Vulnerability feed

Vulnerability record · CVE-2009-3869 · published 5 November 2009

CVE-2009-3869: Sun Java SE AWT setDiffICM Stack Buffer Overflow

Sun · Jdk

A stack-based buffer overflow exists in the setDiffICM function of the Abstract Window Toolkit (AWT) in Sun Java SE. A crafted argument can overflow a stack buffer, and because the affected component is reachable through Java content, the flaw can lead to arbitrary code execution. The issue affects multiple JDK/JRE/SDK release lines and was fixed in vendor updates.

9.3 CVSS 2.0 High EPSS 65% · top 0.8% CWE-119 · Memory buffer overflow
9.3CVSS 2.0 base score
65%EPSS exploitation probability, 30 days
NoNot in CISA KEV
3Affected product versions listed by NVD
54References
16 Jun 2026Last modified by NVD

Description

Stack-based buffer overflow in the setDiffICM function in the Abstract Window Toolkit (AWT) in Java Runtime Environment (JRE) in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to execute arbitrary code via a crafted argument, aka Bug Id 6872357.

AV:N/AC:M/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

high priorityThe flaw allows remote code execution with complete impact and has a very high EPSS percentile, though it is not listed in KEV and requires medium attack complexity.

What it is

A stack-based buffer overflow exists in the setDiffICM function of the Abstract Window Toolkit (AWT) in Sun Java SE. A crafted argument can overflow a stack buffer, and because the affected component is reachable through Java content, the flaw can lead to arbitrary code execution. The issue affects multiple JDK/JRE/SDK release lines and was fixed in vendor updates.

Impact

A remote attacker can execute arbitrary code in the context of the Java process, potentially leading to full compromise of the host running the vulnerable JRE. The CVSS 2.0 vector indicates complete confidentiality, integrity, and availability impact.

Attack surface

The vulnerability is network-reachable (AV:N) with no authentication required (Au:N), but exploitation requires medium complexity (AC:M), consistent with a crafted argument being supplied to the setDiffICM function. User interaction is not explicitly stated in the record, but the AWT context suggests a Java application or applet path may be involved.

Exploitation

The record does not list this CVE in CISA KEV and provides no exploit tags, but EPSS is high at 0.65461 (99.225th percentile), indicating a meaningful probability of exploitation activity. No ransomware group usage is documented.

What to do

  • Apply the vendor patch by upgrading to JDK/JRE 5.0 Update 22 or later, JDK/JRE 6 Update 17 or later, SDK/JRE 1.3.1_27 or later, or SDK/JRE 1.4.2_24 or later as applicable.
  • Disable or restrict Java applet and Web Start execution in browsers and clients where the vulnerable JRE cannot be immediately updated.
  • Remove or isolate end-of-life Java 1.3.x, 1.4.x, 5.0, and 6 releases from production and user endpoints.
  • Apply the referenced vendor advisories and distribution updates (for example, Red Hat, Apple, Gentoo, Mandriva, openSUSE) where the affected JRE is packaged.
  • Monitor for and block untrusted Java content delivery paths until patching is complete.

Detection

  • Inventory endpoints and servers for installed Java versions matching the affected release lines (JDK/JRE 5.0 before Update 22, JDK/JRE 6 before Update 17, SDK/JRE 1.3.x before 1.3.1_27, SDK/JRE 1.4.x before 1.4.2_24).
  • Monitor for crashes or abnormal termination of java.exe/javaw processes that could indicate stack corruption attempts.
  • Use application allowlisting or browser telemetry to detect unexpected Java applet or Web Start execution.
  • Review proxy and endpoint logs for delivery of Java archives from untrusted or unusual sources.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://java.sun.com/javase/6/webnotes/6u17.html Vendor Advisory
http://lists.apple.com/archives/security-announce/2009/Dec/msg00000.html
http://lists.apple.com/archives/security-announce/2009/Dec/msg00001.html
http://lists.opensuse.org/opensuse-security-announce/2009-11/msg00010.html
http://marc.info/?l=bugtraq&m=126566824131534&w=2
http://marc.info/?l=bugtraq&m=131593453929393&w=2
http://marc.info/?l=bugtraq&m=134254866602253&w=2
http://secunia.com/advisories/37231 Vendor Advisory
http://secunia.com/advisories/37239
http://secunia.com/advisories/37386
http://secunia.com/advisories/37581
http://secunia.com/advisories/37841
http://security.gentoo.org/glsa/glsa-200911-02.xml
http://securitytracker.com/id?1023132
http://sunsolve.sun.com/search/document.do?assetkey=1-66-270474-1 PatchVendor Advisory
http://support.apple.com/kb/HT3969
http://support.apple.com/kb/HT3970
http://www.mandriva.com/security/advisories?name=MDVSA-2010:084
http://www.oracle.com/technetwork/topics/security/cpujan2010-084891.html
http://www.redhat.com/support/errata/RHSA-2009-1694.html
http://www.securityfocus.com/bid/36881
http://www.vupen.com/english/advisories/2009/3131 PatchVendor Advisory
http://zerodayinitiative.com/advisories/ZDI-09-078/ Patch
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10741
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11262
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7400
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8566
http://java.sun.com/javase/6/webnotes/6u17.html Vendor Advisory
http://lists.apple.com/archives/security-announce/2009/Dec/msg00000.html
http://lists.apple.com/archives/security-announce/2009/Dec/msg00001.html
http://lists.opensuse.org/opensuse-security-announce/2009-11/msg00010.html
http://marc.info/?l=bugtraq&m=126566824131534&w=2
http://marc.info/?l=bugtraq&m=131593453929393&w=2
http://marc.info/?l=bugtraq&m=134254866602253&w=2
http://secunia.com/advisories/37231 Vendor Advisory
http://secunia.com/advisories/37239
http://secunia.com/advisories/37386
http://secunia.com/advisories/37581
http://secunia.com/advisories/37841
http://security.gentoo.org/glsa/glsa-200911-02.xml

Track CVE-2009-3869 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2013-2465Oracle Java SE JRE 2D sandbox bypass and code executionCVE-2013-2465 is an unspecified vulnerability in the 2D component of Oracle Java SE JRE (7 Update 21 and earlier, 6 Update 45 and earlier, 5.0 Update…KEVEPSS 99%analysed9.8CVE-2012-0507Oracle Java SE JRE AtomicReferenceArray type confusion sandbox bypassCVE-2012-0507 is an unspecified vulnerability in the Java Runtime Environment (JRE) Concurrency component affecting Java SE 7 Update 2 and earlier, 6…KEVEPSS 98%analysed10.0CVE-2013-5809Oracle jre vulnerabilityUnspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, and Java SE Embedded 7u40 and ear…EPSS 5.9%10.0CVE-2013-5814Oracle jre vulnerabilityUnspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, and Java SE Embedded 7u40 and ear…EPSS 6.3%10.0CVE-2013-5817Oracle jdk vulnerabilityUnspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, and Java SE Embedded 7u40 and ear…EPSS 6.3%10.0CVE-2013-5824Oracle jdk vulnerabilityUnspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, and Java SE Embedded 7u40 and earlier allows remote attackers…EPSS 5.6%10.0CVE-2013-5782Oracle jre vulnerabilityUnspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, JRockit R28.2.8 and earlier, JRoc…EPSS 6.3%10.0CVE-2013-5787Oracle jdk vulnerabilityUnspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, and Java SE Embedded 7u40 and earlier allows remote attackers…EPSS 5.6%

Source: NIST National Vulnerability Database (record CVE-2009-3869), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.