CVE-2009-1190

EUVD-2022-5585
Algorithmic complexity vulnerability in the java.util.regex.Pattern.compile method in Sun Java Development Kit (JDK) before 1.6, when used with spring.jar in SpringSource Spring Framework 1.1.0 through 2.5.6 and 3.0.0.M1 through 3.0.0.M2 and dm Server 1.0.0 through 1.0.2, allows remote attackers to cause a denial of service (CPU consumption) via serializable data with a long regex string containing multiple optional groups, a related issue to CVE-2004-2540.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:N/I:N/A:P
Base Score
CVSS 3.x
EPSS Score
Percentile: 80%
Affected Products (NVD)
VendorProductVersion
sunjdk
𝑥
≤ 1.5.0
sunjdk
1.1.0
sunjdk
1.1.6
sunjdk
1.1.6
sunjdk
1.1.7b:b
sunjdk
1.1.7b:b
sunjdk
1.1.8
sunjdk
1.1.8
sunjdk
1.1.8
sunjdk
1.1.8
sunjdk
1.1.8
sunjdk
1.1.8
sunjdk
1.2.0
sunjdk
1.2.1
sunjdk
1.2.1
sunjdk
1.2.2
sunjdk
1.2.2
sunjdk
1.3.0
sunjdk
1.3.0_01:_01
sunjdk
1.3.0_02:_02
sunjdk
1.3.0_03:_03
sunjdk
1.3.0_04:_04
sunjdk
1.3.0_05:_05
sunjdk
1.3.1
sunjdk
1.3.1
sunjdk
1.3.1
sunjdk
1.3.1_01:_01
sunjdk
1.3.1_01a:_01a
sunjdk
1.3.1_02:_02
sunjdk
1.3.1_03:_03
sunjdk
1.3.1_04:_04
sunjdk
1.3.1_05:_05
sunjdk
1.3.1_06:_06
sunjdk
1.3.1_07:_07
sunjdk
1.3.1_08:_08
sunjdk
1.3.1_09:_09
sunjdk
1.3.1_10:_10
sunjdk
1.3.1_11:_11
sunjdk
1.3.1_12:_12
sunjdk
1.3.1_13:_13
sunjdk
1.3.1_14:_14
sunjdk
1.3.1_15:_15
sunjdk
1.3.1_16:_16
sunjdk
1.3.1_17:_17
sunjdk
1.3.1_18:_18
sunjdk
1.3.1_19:_19
sunjdk
1.3.1_20:_20
sunjdk
1.3.1_21:_21
sunjdk
1.3.1_22:_22
sunjdk
1.3.1_23:_23
sunjdk
1.3.1_24:_24
sunjdk
1.3.1_25:_25
sunjdk
1.3.1_26:_26
sunjdk
1.3.1_27:_27
sunjdk
1.3.1_28:_28
sunjdk
1.4.0
sunjdk
1.4.0_01:_01
sunjdk
1.4.0_02:_02
sunjdk
1.4.0_03:_03
sunjdk
1.4.0_04:_04
sunjdk
1.4.1
sunjdk
1.4.1_01:_01
sunjdk
1.4.1_02:_02
sunjdk
1.4.1_03:_03
sunjdk
1.4.1_04:_04
sunjdk
1.4.1_05:_05
sunjdk
1.4.1_06:_06
sunjdk
1.4.1_07:_07
sunjdk
1.4.2
sunjdk
1.4.2_1:_1
sunjdk
1.4.2_2:_2
sunjdk
1.4.2_3:_3
sunjdk
1.4.2_4:_4
sunjdk
1.4.2_5:_5
sunjdk
1.4.2_6:_6
sunjdk
1.4.2_7:_7
sunjdk
1.4.2_8:_8
sunjdk
1.4.2_9:_9
sunjdk
1.4.2_10:_10
sunjdk
1.4.2_11:_11
sunjdk
1.4.2_12:_12
sunjdk
1.4.2_13:_13
sunjdk
1.4.2_14:_14
sunjdk
1.4.2_15:_15
sunjdk
1.4.2_16:_16
sunjdk
1.4.2_17:_17
sunjdk
1.4.2_18:_18
sunjdk
1.4.2_19:_19
sunjdk
1.5.0
sunjdk
1.5.0
sunjdk
1.5.0
sunjdk
1.5.0
sunjdk
1.5.0
sunjdk
1.5.0
sunjdk
1.5.0
sunjdk
1.5.0
sunjdk
1.5.0
sunjdk
1.5.0
sunjdk
1.5.0
sunjdk
1.5.0
sunjdk
1.5.0
sunjdk
1.5.0
sunjdk
1.5.0
sunjdk
1.5.0
sunjdk
1.5.0
sunjdk
1.5.0
sunjdk
1.5.0
sunjdk
1.5.0
sunjdk
1.5.0
sunjdk
1.5.0
sunjdk
1.5.0
sunjdk
1.5.0
sunjdk
1.5.0
sunjdk
1.5.0
sunjdk
1.5.0
sunjdk
1.5.0
sunjdk
1.5.0
sunjdk
1.5.0
sunjdk
1.5.0
sunjdk
1.5.0
sunjdk
1.5.0
sunjdk
1.5.0
sunjdk
1.5.0
sunjdk
1.5.0
sunjdk
1.5.0
sunjdk
1.5.0
sunjdk
1.5.0
sunjdk
1.5.0
sunjdk
1.5.0
sunjdk
1.5.0
sunjdk
1.5.0
sunjdk
1.5.0
sunjdk
1.5.0
sunjdk
1.5.0
sunjdk
1.5.0
sunjdk
1.5.0
sunjdk
1.5.0
sunjdk
1.5.0_03:_03
sunjdk
1.5.0_03:_03
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
java
dapper
dne
hardy
dne
intrepid
dne
jaunty
dne
karmic
dne
lucid
dne
maverick
dne
natty
dne
openjdk-6
dapper
dne
hardy
not-affected
intrepid
not-affected
jaunty
not-affected
karmic
not-affected
lucid
not-affected
maverick
not-affected
natty
not-affected
sun-java5
dapper
ignored
hardy
ignored
intrepid
ignored
jaunty
ignored
karmic
dne
lucid
dne
maverick
dne
natty
dne
sun-java6
dapper
dne
hardy
not-affected
intrepid
not-affected
jaunty
not-affected
karmic
not-affected
lucid
not-affected
maverick
not-affected
natty
not-affected
Common Weakness Enumeration