AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2009-3880

MEDIUM · CVSS 5 EPSS 1.79%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2009-11-09 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2009-3880
Severity
MEDIUM
CVSS
5
EPSS
1.79%
Java

Original NVD Description

The Abstract Window Toolkit (AWT) in Java Runtime Environment (JRE) in Sun Java SE 5.0 before Update 22 and 6 before Update 17, and OpenJDK, does not properly restrict the objects that may be sent to loggers, which allows attackers to obtain sensitive information via vectors related to the implementation of Component, KeyboardFocusManager, and DefaultKeyboardFocusManager, aka Bug Id 6664512.