Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2010-1423

Опубликовано: 15 апр. 2010
Источник: nvd
CVSS2: 9.3
EPSS Средний

Описание

Argument injection vulnerability in the URI handler in (a) Java NPAPI plugin and (b) Java Deployment Toolkit in Java 6 Update 10, 19, and other versions, when running on Windows and possibly on Linux, allows remote attackers to execute arbitrary code via the (1) -J or (2) -XXaltjvm argument to javaws.exe, which is processed by the launch method. NOTE: some of these details are obtained from third party information.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:oracle:jdk:*:update19:*:*:*:*:*:*
Версия до 1.6.0 (включая)
cpe:2.3:a:oracle:jdk:1.6.0:update10:*:*:*:*:*:*
cpe:2.3:a:oracle:jre:*:update19:*:*:*:*:*:*
Версия до 1.6.0 (включая)
cpe:2.3:a:oracle:jre:1.6.0:update_10:*:*:*:*:*:*

EPSS

Процентиль: 99%
0.68947
Средний

9.3 Critical

CVSS2

Дефекты

CWE-78

Связанные уязвимости

ubuntu
больше 15 лет назад

Argument injection vulnerability in the URI handler in (a) Java NPAPI plugin and (b) Java Deployment Toolkit in Java 6 Update 10, 19, and other versions, when running on Windows and possibly on Linux, allows remote attackers to execute arbitrary code via the (1) -J or (2) -XXaltjvm argument to javaws.exe, which is processed by the launch method. NOTE: some of these details are obtained from third party information.

redhat
больше 15 лет назад

Argument injection vulnerability in the URI handler in (a) Java NPAPI plugin and (b) Java Deployment Toolkit in Java 6 Update 10, 19, and other versions, when running on Windows and possibly on Linux, allows remote attackers to execute arbitrary code via the (1) -J or (2) -XXaltjvm argument to javaws.exe, which is processed by the launch method. NOTE: some of these details are obtained from third party information.

debian
больше 15 лет назад

Argument injection vulnerability in the URI handler in (a) Java NPAPI ...

github
больше 3 лет назад

Argument injection vulnerability in the URI handler in (a) Java NPAPI plugin and (b) Java Deployment Toolkit in Java 6 Update 10, 19, and other versions, when running on Windows and possibly on Linux, allows remote attackers to execute arbitrary code via the (1) -J or (2) -XXaltjvm argument to javaws.exe, which is processed by the launch method. NOTE: some of these details are obtained from third party information.

EPSS

Процентиль: 99%
0.68947
Средний

9.3 Critical

CVSS2

Дефекты

CWE-78