Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-11772

Опубликовано: 17 июл. 2019
Источник: nvd
CVSS3: 9.8
CVSS2: 7.5
EPSS Низкий

Описание

In Eclipse OpenJ9 prior to 0.15, the String.getBytes(int, int, byte[], int) method does not verify that the provided byte array is non-null nor that the provided index is in bounds when compiled by the JIT. This allows arbitrary writes to any 32-bit address or beyond the end of a byte array within Java code run under a SecurityManager.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:eclipse:openj9:*:*:*:*:*:*:*:*
Версия до 0.15.0 (исключая)

EPSS

Процентиль: 75%
0.00871
Низкий

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-787
CWE-787

Связанные уязвимости

CVSS3: 9.8
redhat
больше 6 лет назад

In Eclipse OpenJ9 prior to 0.15, the String.getBytes(int, int, byte[], int) method does not verify that the provided byte array is non-null nor that the provided index is in bounds when compiled by the JIT. This allows arbitrary writes to any 32-bit address or beyond the end of a byte array within Java code run under a SecurityManager.

CVSS3: 9.8
github
больше 3 лет назад

In Eclipse OpenJ9 prior to 0.15, the String.getBytes(int, int, byte[], int) method does not verify that the provided byte array is non-null nor that the provided index is in bounds when compiled by the JIT. This allows arbitrary writes to any 32-bit address or beyond the end of a byte array within Java code run under a SecurityManager.

CVSS3: 9.8
fstec
больше 6 лет назад

Уязвимость метода String.getBytes(int, int, byte[], int) виртуальной машины Eclipse OpenJ9, позволяющая нарушителю выполнить произвольный код

suse-cvrf
больше 6 лет назад

Security update for java-1_8_0-ibm

suse-cvrf
больше 6 лет назад

Security update for java-1_8_0-ibm

EPSS

Процентиль: 75%
0.00871
Низкий

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-787
CWE-787