Логотип exploitDog
bind:"GHSA-gvgc-rxmh-5hvw" OR bind:"CVE-2010-4476"
Консоль
Логотип exploitDog

exploitDog

bind:"GHSA-gvgc-rxmh-5hvw" OR bind:"CVE-2010-4476"

Количество 8

Количество 8

github логотип

GHSA-gvgc-rxmh-5hvw

около 3 лет назад

Apache Tomcat affected by infinite loop in Double.parseDouble method in Java Runtime Environment

EPSS: Средний
ubuntu логотип

CVE-2010-4476

больше 14 лет назад

The Double.parseDouble method in Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 23 and earlier, 5.0 Update 27 and earlier, and 1.4.2_29 and earlier, as used in OpenJDK, Apache, JBossweb, and other products, allows remote attackers to cause a denial of service via a crafted string that triggers an infinite loop of estimations during conversion to a double-precision binary floating-point number, as demonstrated using 2.2250738585072012e-308.

CVSS2: 5
EPSS: Средний
redhat логотип

CVE-2010-4476

больше 14 лет назад

The Double.parseDouble method in Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 23 and earlier, 5.0 Update 27 and earlier, and 1.4.2_29 and earlier, as used in OpenJDK, Apache, JBossweb, and other products, allows remote attackers to cause a denial of service via a crafted string that triggers an infinite loop of estimations during conversion to a double-precision binary floating-point number, as demonstrated using 2.2250738585072012e-308.

CVSS2: 5
EPSS: Средний
nvd логотип

CVE-2010-4476

больше 14 лет назад

The Double.parseDouble method in Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 23 and earlier, 5.0 Update 27 and earlier, and 1.4.2_29 and earlier, as used in OpenJDK, Apache, JBossweb, and other products, allows remote attackers to cause a denial of service via a crafted string that triggers an infinite loop of estimations during conversion to a double-precision binary floating-point number, as demonstrated using 2.2250738585072012e-308.

CVSS2: 5
EPSS: Средний
debian логотип

CVE-2010-4476

больше 14 лет назад

The Double.parseDouble method in Java Runtime Environment (JRE) in Ora ...

CVSS2: 5
EPSS: Средний
oracle-oval логотип

ELSA-2011-0336

больше 14 лет назад

ELSA-2011-0336: tomcat5 security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2011-0214

больше 14 лет назад

ELSA-2011-0214: java-1.6.0-openjdk security update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2011-0335

больше 14 лет назад

ELSA-2011-0335: tomcat6 security and bug fix update (IMPORTANT)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-gvgc-rxmh-5hvw

Apache Tomcat affected by infinite loop in Double.parseDouble method in Java Runtime Environment

44%
Средний
около 3 лет назад
ubuntu логотип
CVE-2010-4476

The Double.parseDouble method in Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 23 and earlier, 5.0 Update 27 and earlier, and 1.4.2_29 and earlier, as used in OpenJDK, Apache, JBossweb, and other products, allows remote attackers to cause a denial of service via a crafted string that triggers an infinite loop of estimations during conversion to a double-precision binary floating-point number, as demonstrated using 2.2250738585072012e-308.

CVSS2: 5
44%
Средний
больше 14 лет назад
redhat логотип
CVE-2010-4476

The Double.parseDouble method in Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 23 and earlier, 5.0 Update 27 and earlier, and 1.4.2_29 and earlier, as used in OpenJDK, Apache, JBossweb, and other products, allows remote attackers to cause a denial of service via a crafted string that triggers an infinite loop of estimations during conversion to a double-precision binary floating-point number, as demonstrated using 2.2250738585072012e-308.

CVSS2: 5
44%
Средний
больше 14 лет назад
nvd логотип
CVE-2010-4476

The Double.parseDouble method in Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 23 and earlier, 5.0 Update 27 and earlier, and 1.4.2_29 and earlier, as used in OpenJDK, Apache, JBossweb, and other products, allows remote attackers to cause a denial of service via a crafted string that triggers an infinite loop of estimations during conversion to a double-precision binary floating-point number, as demonstrated using 2.2250738585072012e-308.

CVSS2: 5
44%
Средний
больше 14 лет назад
debian логотип
CVE-2010-4476

The Double.parseDouble method in Java Runtime Environment (JRE) in Ora ...

CVSS2: 5
44%
Средний
больше 14 лет назад
oracle-oval логотип
ELSA-2011-0336

ELSA-2011-0336: tomcat5 security update (IMPORTANT)

больше 14 лет назад
oracle-oval логотип
ELSA-2011-0214

ELSA-2011-0214: java-1.6.0-openjdk security update (MODERATE)

больше 14 лет назад
oracle-oval логотип
ELSA-2011-0335

ELSA-2011-0335: tomcat6 security and bug fix update (IMPORTANT)

больше 14 лет назад

Уязвимостей на страницу