4.3

CVE-2007-0012

Sun JRE 5.0 before update 14 allows remote attackers to cause a denial of service (Internet Explorer crash) via an object tag with an encoded applet and an undefined name attribute, which triggers a NULL pointer dereference in jpiexp32.dll when the applet is decoded and passed to the JVM.

Data is provided by the National Vulnerability Database (NVD)
SunJre Updateupdate10 Version <= 1.5.0
SunJre Updateupdate11 Version <= 1.5.0
SunJre Updateupdate12 Version <= 1.5.0
SunJre Updateupdate13 Version <= 1.5.0
SunJre Updateupdate7 Version <= 1.5.0
SunJre Updateupdate8 Version <= 1.5.0
SunJre Updateupdate9 Version <= 1.5.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.69% 0.693
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:N/A:P
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.