Multiple unspecified vulnerabilities in Sun Java Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 7 and earlier, and Java System Development Kit (SDK) and JRE 1.4.2_12 and earlier 1.4.x versions, allow attackers to develop Java applets or applications that are able to gain privileges, related to serialization in JRE.
Conclusion & alert: CVE-2006-6745 is rated Moderate Risk (62.2/100): CVSS Critical severity, with medium exploitation likelihood (EPSS 3.06%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 14.77% | 3.06% | -11.71% |
| 2 | 2026-03-05 | 23.43% | 14.77% | -8.66% |
| 3 | 2026-01-19 | — | 23.43% | — |
Full EPSS history (16 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 9.3 | 2.0 | HIGH |
|
8.6 | 10.0 | [email protected] |
| vendor | priority | summary | link |
|---|---|---|---|
alpine
|
— | CVE-2006-6745: no source package rows; 0 state rows across 0 repos (none); fixed 0, open 0. | https://security.alpinelinux.org/vuln/CVE-2006-6745 |
gentoo
|
normal | CVE-2006-6745: 3 GLSA(s) (200701-15, 200702-08, 200705-20), 5 atom(s) (app-emulation/emul-linux-x86-java, dev-java/blackdown-jdk, dev-java/blackdown-jre, dev-java/sun-jdk, dev-java/sun-jre-bin); latest impact normal. | https://bugs.gentoo.org/buglist.cgi?quicksearch=CVE-2006-6745 |
redhat
|
critical | — | https://access.redhat.com/security/cve/CVE-2006-6745 |
ubuntu
|
negligible | CVE-2006-6745 negligible priority: Ubuntu has no source package entries, 0 status rows across 0 suites (none): no status rows. | https://ubuntu.com/security/CVE-2006-6745 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| sun | j2se | 1.4 | cpe:2.3:a:sun:j2se:1.4:*:sdk:*:*:*:*:* |
| sun | j2se | 1.4.1 | cpe:2.3:a:sun:j2se:1.4.1:*:sdk:*:*:*:*:* |
| sun | j2se | 1.4.2 | cpe:2.3:a:sun:j2se:1.4.2:*:sdk:*:*:*:*:* |
| sun | j2se | 1.4.2_01 | cpe:2.3:a:sun:j2se:1.4.2_01:*:sdk:*:*:*:*:* |
| sun | j2se | 1.4.2_02 | cpe:2.3:a:sun:j2se:1.4.2_02:*:sdk:*:*:*:*:* |
| sun | j2se | 1.4.2_03 | cpe:2.3:a:sun:j2se:1.4.2_03:*:sdk:*:*:*:*:* |
| sun | j2se | 1.4.2_04 | cpe:2.3:a:sun:j2se:1.4.2_04:*:sdk:*:*:*:*:* |
| sun | j2se | 1.4.2_05 | cpe:2.3:a:sun:j2se:1.4.2_05:*:sdk:*:*:*:*:* |
| sun | j2se | 1.4.2_06 | cpe:2.3:a:sun:j2se:1.4.2_06:*:sdk:*:*:*:*:* |
| sun | j2se | 1.4.2_07 | cpe:2.3:a:sun:j2se:1.4.2_07:*:sdk:*:*:*:*:* |
| sun | j2se | 1.4.2_08 | cpe:2.3:a:sun:j2se:1.4.2_08:*:*:*:*:*:*:* |
| sun | j2se | 1.4.2_09 | cpe:2.3:a:sun:j2se:1.4.2_09:*:*:*:*:*:*:* |
| sun | j2se | 1.4.2_10 | cpe:2.3:a:sun:j2se:1.4.2_10:*:*:*:*:*:*:* |
| sun | j2se | 1.4.2_11 | cpe:2.3:a:sun:j2se:1.4.2_11:*:*:*:*:*:*:* |
| sun | j2se | 1.4.2_12 | cpe:2.3:a:sun:j2se:1.4.2_12:*:*:*:*:*:*:* |
| sun | j2se | 5.0 | cpe:2.3:a:sun:j2se:5.0:*:sdk:*:*:*:*:* |
| sun | j2se | 5.0_update1 | cpe:2.3:a:sun:j2se:5.0_update1:*:sdk:*:*:*:*:* |
| sun | j2se | 5.0_update2 | cpe:2.3:a:sun:j2se:5.0_update2:*:sdk:*:*:*:*:* |
| sun | j2se | 5.0_update3 | cpe:2.3:a:sun:j2se:5.0_update3:*:*:*:*:*:*:* |
| sun | j2se | 5.0_update4 | cpe:2.3:a:sun:j2se:5.0_update4:*:*:*:*:*:*:* |
| sun | j2se | 5.0_update5 | cpe:2.3:a:sun:j2se:5.0_update5:*:*:*:*:*:*:* |
| sun | j2se | 5.0_update6 | cpe:2.3:a:sun:j2se:5.0_update6:*:*:*:*:*:*:* |
| sun | j2se | 5.0_update7 | cpe:2.3:a:sun:j2se:5.0_update7:*:*:*:*:*:*:* |
| sun | jre | 1.4.1 | cpe:2.3:a:sun:jre:1.4.1:*:*:*:*:*:*:* |
| sun | jre | 1.4.2 | cpe:2.3:a:sun:jre:1.4.2:*:*:*:*:*:*:* |
| sun | jre | 1.4.2_1 | cpe:2.3:a:sun:jre:1.4.2_1:*:*:*:*:*:*:* |
| sun | jre | 1.4.2_2 | cpe:2.3:a:sun:jre:1.4.2_2:*:*:*:*:*:*:* |
| sun | jre | 1.4.2_3 | cpe:2.3:a:sun:jre:1.4.2_3:*:*:*:*:*:*:* |
| sun | jre | 1.4.2_4 | cpe:2.3:a:sun:jre:1.4.2_4:*:*:*:*:*:*:* |
| sun | jre | 1.4.2_5 | cpe:2.3:a:sun:jre:1.4.2_5:*:*:*:*:*:*:* |
| sun | jre | 1.4.2_6 | cpe:2.3:a:sun:jre:1.4.2_6:*:*:*:*:*:*:* |
| sun | jre | 1.4.2_7 | cpe:2.3:a:sun:jre:1.4.2_7:*:*:*:*:*:*:* |
| sun | jre | 1.4.2_8 | cpe:2.3:a:sun:jre:1.4.2_8:*:*:*:*:*:*:* |
| sun | jre | 1.4.2_9 | cpe:2.3:a:sun:jre:1.4.2_9:*:*:*:*:*:*:* |
| sun | jre | 1.4.2_10 | cpe:2.3:a:sun:jre:1.4.2_10:*:*:*:*:*:*:* |
| sun | jre | 1.4.2_11 | cpe:2.3:a:sun:jre:1.4.2_11:*:*:*:*:*:*:* |
| sun | jre | 1.4.2_12 | cpe:2.3:a:sun:jre:1.4.2_12:*:*:*:*:*:*:* |
| sun | jre | 1.4.2_13 | cpe:2.3:a:sun:jre:1.4.2_13:*:*:*:*:*:*:* |
| sun | jre | 1.5.0 | cpe:2.3:a:sun:jre:1.5.0:*:*:*:*:*:*:* |
| sun | jre | 1.5.0 | cpe:2.3:a:sun:jre:1.5.0:update1:*:*:*:*:*:* |
| sun | jre | 1.5.0 | cpe:2.3:a:sun:jre:1.5.0:update2:*:*:*:*:*:* |
| sun | jre | 1.5.0 | cpe:2.3:a:sun:jre:1.5.0:update3:*:*:*:*:*:* |
| sun | jre | 1.5.0 | cpe:2.3:a:sun:jre:1.5.0:update4:*:*:*:*:*:* |
| sun | jre | 1.5.0 | cpe:2.3:a:sun:jre:1.5.0:update5:*:*:*:*:*:* |
| sun | jre | 1.5.0 | cpe:2.3:a:sun:jre:1.5.0:update6:*:*:*:*:*:* |
| sun | jre | 1.5.0 | cpe:2.3:a:sun:jre:1.5.0:update7:*:*:*:*:*:* |