Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mrwf-5889-vpvm

Опубликовано: 02 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The Deployment Toolkit ActiveX control in deploytk.dll 6.0.130.3 in Sun Java SE Runtime Environment (aka JRE) 6 Update 13 allows remote attackers to (1) execute arbitrary code via a .jnlp URL in the argument to the launch method, and might allow remote attackers to launch JRE installation processes via the (2) installLatestJRE or (3) installJRE method.

The Deployment Toolkit ActiveX control in deploytk.dll 6.0.130.3 in Sun Java SE Runtime Environment (aka JRE) 6 Update 13 allows remote attackers to (1) execute arbitrary code via a .jnlp URL in the argument to the launch method, and might allow remote attackers to launch JRE installation processes via the (2) installLatestJRE or (3) installJRE method.

EPSS

Процентиль: 91%
0.06538
Низкий

Дефекты

CWE-119

Связанные уязвимости

nvd
больше 16 лет назад

The Deployment Toolkit ActiveX control in deploytk.dll 6.0.130.3 in Sun Java SE Runtime Environment (aka JRE) 6 Update 13 allows remote attackers to (1) execute arbitrary code via a .jnlp URL in the argument to the launch method, and might allow remote attackers to launch JRE installation processes via the (2) installLatestJRE or (3) installJRE method.

EPSS

Процентиль: 91%
0.06538
Низкий

Дефекты

CWE-119