Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2012-3423

Опубликовано: 31 июл. 2012
Источник: redhat
CVSS2: 5.1
EPSS Низкий

Описание

The IcedTea-Web plugin before 1.2.1 does not properly handle NPVariant NPStrings without NUL terminators, which allows remote attackers to cause a denial of service (crash), obtain sensitive information from memory, or execute arbitrary code via a crafted Java applet.

Дополнительная информация

Статус:

Important
https://bugzilla.redhat.com/show_bug.cgi?id=841345icedtea-web: incorrect handling of not 0-terminated strings

EPSS

Процентиль: 85%
0.02475
Низкий

5.1 Medium

CVSS2

Связанные уязвимости

ubuntu
больше 13 лет назад

The IcedTea-Web plugin before 1.2.1 does not properly handle NPVariant NPStrings without NUL terminators, which allows remote attackers to cause a denial of service (crash), obtain sensitive information from memory, or execute arbitrary code via a crafted Java applet.

nvd
больше 13 лет назад

The IcedTea-Web plugin before 1.2.1 does not properly handle NPVariant NPStrings without NUL terminators, which allows remote attackers to cause a denial of service (crash), obtain sensitive information from memory, or execute arbitrary code via a crafted Java applet.

debian
больше 13 лет назад

The IcedTea-Web plugin before 1.2.1 does not properly handle NPVariant ...

github
больше 3 лет назад

The IcedTea-Web plugin before 1.2.1 does not properly handle NPVariant NPStrings without NUL terminators, which allows remote attackers to cause a denial of service (crash), obtain sensitive information from memory, or execute arbitrary code via a crafted Java applet.

oracle-oval
больше 13 лет назад

ELSA-2012-1132: icedtea-web security update (IMPORTANT)

EPSS

Процентиль: 85%
0.02475
Низкий

5.1 Medium

CVSS2

Уязвимость CVE-2012-3423