Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wg7g-m9g6-qcmw

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The IcedTea-Web plugin before 1.2.1 does not properly handle NPVariant NPStrings without NUL terminators, which allows remote attackers to cause a denial of service (crash), obtain sensitive information from memory, or execute arbitrary code via a crafted Java applet.

The IcedTea-Web plugin before 1.2.1 does not properly handle NPVariant NPStrings without NUL terminators, which allows remote attackers to cause a denial of service (crash), obtain sensitive information from memory, or execute arbitrary code via a crafted Java applet.

EPSS

Процентиль: 85%
0.02475
Низкий

Дефекты

CWE-119

Связанные уязвимости

ubuntu
около 13 лет назад

The IcedTea-Web plugin before 1.2.1 does not properly handle NPVariant NPStrings without NUL terminators, which allows remote attackers to cause a denial of service (crash), obtain sensitive information from memory, or execute arbitrary code via a crafted Java applet.

redhat
около 13 лет назад

The IcedTea-Web plugin before 1.2.1 does not properly handle NPVariant NPStrings without NUL terminators, which allows remote attackers to cause a denial of service (crash), obtain sensitive information from memory, or execute arbitrary code via a crafted Java applet.

nvd
около 13 лет назад

The IcedTea-Web plugin before 1.2.1 does not properly handle NPVariant NPStrings without NUL terminators, which allows remote attackers to cause a denial of service (crash), obtain sensitive information from memory, or execute arbitrary code via a crafted Java applet.

debian
около 13 лет назад

The IcedTea-Web plugin before 1.2.1 does not properly handle NPVariant ...

oracle-oval
около 13 лет назад

ELSA-2012-1132: icedtea-web security update (IMPORTANT)

EPSS

Процентиль: 85%
0.02475
Низкий

Дефекты

CWE-119