Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qwm3-gpj3-x6c9

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The getFirstInTableInstance function in the IcedTea-Web plugin before 1.2.1 returns an uninitialized pointer when the instance_to_id_map hash is empty, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted web page, which causes an uninitialized memory location to be read.

The getFirstInTableInstance function in the IcedTea-Web plugin before 1.2.1 returns an uninitialized pointer when the instance_to_id_map hash is empty, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted web page, which causes an uninitialized memory location to be read.

EPSS

Процентиль: 75%
0.00891
Низкий

Дефекты

CWE-119

Связанные уязвимости

ubuntu
около 13 лет назад

The getFirstInTableInstance function in the IcedTea-Web plugin before 1.2.1 returns an uninitialized pointer when the instance_to_id_map hash is empty, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted web page, which causes an uninitialized memory location to be read.

redhat
около 13 лет назад

The getFirstInTableInstance function in the IcedTea-Web plugin before 1.2.1 returns an uninitialized pointer when the instance_to_id_map hash is empty, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted web page, which causes an uninitialized memory location to be read.

nvd
около 13 лет назад

The getFirstInTableInstance function in the IcedTea-Web plugin before 1.2.1 returns an uninitialized pointer when the instance_to_id_map hash is empty, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted web page, which causes an uninitialized memory location to be read.

debian
около 13 лет назад

The getFirstInTableInstance function in the IcedTea-Web plugin before ...

oracle-oval
около 13 лет назад

ELSA-2012-1132: icedtea-web security update (IMPORTANT)

EPSS

Процентиль: 75%
0.00891
Низкий

Дефекты

CWE-119