Lucene search

K
cve[email protected]CVE-2010-0538
HistoryOct 03, 2022 - 4:21 p.m.

CVE-2010-0538

2022-10-0316:21:13
CWE-399
web.nvd.nist.gov
30
apple
java
mac os x
cve-2010-0538
remote attackers
arbitrary code
denial of service
crafted applet

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

7.8 High

AI Score

Confidence

Low

0.01 Low

EPSS

Percentile

83.3%

Apple Java for Mac OS X 10.5 before Update 7 and Java for Mac OS X 10.6 before Update 2 do not properly handle mediaLibImage objects, which allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds memory access and application crash) via a crafted applet, related to the com.sun.medialib.mlib package.

Affected configurations

NVD
Node
applejava
AND
applemac_os_xMatch10.5
OR
applemac_os_xMatch10.5.0
OR
applemac_os_xMatch10.5.1
OR
applemac_os_xMatch10.5.2
OR
applemac_os_xMatch10.5.3
OR
applemac_os_xMatch10.5.4
OR
applemac_os_xMatch10.5.5
OR
applemac_os_xMatch10.5.6
Node
applejava
AND
applemac_os_xMatch10.6
OR
applemac_os_xMatch10.6.0
OR
applemac_os_xMatch10.6.1
CPENameOperatorVersion
apple:javaapple javaeq*

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

7.8 High

AI Score

Confidence

Low

0.01 Low

EPSS

Percentile

83.3%