Lucene search

K
cve[email protected]CVE-2010-0539
HistoryOct 03, 2022 - 4:21 p.m.

CVE-2010-0539

2022-10-0316:21:10
CWE-189
web.nvd.nist.gov
31
cve
2010-0539
apple
java
mac os x
update
remote attackers
arbitrary code
denial of service
crafted applet

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

7.8 High

AI Score

Confidence

High

0.011 Low

EPSS

Percentile

84.7%

Integer signedness error in the window drawing implementation in Apple Java for Mac OS X 10.5 before Update 7 and Java for Mac OS X 10.6 before Update 2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted applet.

Affected configurations

NVD
Node
applejava_1.5Match023
AND
applemac_os_xMatch10.5
OR
applemac_os_xMatch10.5.0
OR
applemac_os_xMatch10.5.1
OR
applemac_os_xMatch10.5.2
OR
applemac_os_xMatch10.5.3
OR
applemac_os_xMatch10.5.4
OR
applemac_os_xMatch10.5.5
OR
applemac_os_xMatch10.5.6
Node
applejava_1.6Match017
AND
applemac_os_xMatch10.6
OR
applemac_os_xMatch10.6.0
OR
applemac_os_xMatch10.6.1
CPENameOperatorVersion
apple:java_1.5apple java 1.5eq0

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

7.8 High

AI Score

Confidence

High

0.011 Low

EPSS

Percentile

84.7%