Lucene search

K
cveMitreCVE-2010-1423
HistoryApr 15, 2010 - 9:30 p.m.

CVE-2010-1423

2010-04-1521:30:00
CWE-78
mitre
web.nvd.nist.gov
61
cve-2010-1423
java
npapi
deployment toolkit
argument injection
vulnerability
remote code execution

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

8

Confidence

Low

EPSS

0.931

Percentile

99.1%

Argument injection vulnerability in the URI handler in (a) Java NPAPI plugin and (b) Java Deployment Toolkit in Java 6 Update 10, 19, and other versions, when running on Windows and possibly on Linux, allows remote attackers to execute arbitrary code via the (1) -J or (2) -XXaltjvm argument to javaws.exe, which is processed by the launch method. NOTE: some of these details are obtained from third party information.

Affected configurations

Nvd
Node
oraclejdkRange1.6.0update19
OR
oraclejdkMatch1.6.0update10
OR
oraclejreRange1.6.0update19
OR
oraclejreMatch1.6.0update_10
VendorProductVersionCPE
oraclejrecpe:/a:oracle:jre::update19::
oraclejdkcpe:/a:oracle:jdk::update19::
oraclejdk1.6.0cpe:/a:oracle:jdk:1.6.0:update10::
oraclejre1.6.0cpe:/a:oracle:jre:1.6.0:update_10::

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

8

Confidence

Low

EPSS

0.931

Percentile

99.1%