4.3

CVE-2007-0012

Sun JRE 5.0 before update 14 allows remote attackers to cause a denial of service (Internet Explorer crash) via an object tag with an encoded applet and an undefined name attribute, which triggers a NULL pointer dereference in jpiexp32.dll when the applet is decoded and passed to the JVM.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Sun ≫ Jre Update update10 Version <= 1.5.0
Sun ≫ Jre Update update11 Version <= 1.5.0
Sun ≫ Jre Update update12 Version <= 1.5.0
Sun ≫ Jre Update update13 Version <= 1.5.0
Sun ≫ Jre Update update7 Version <= 1.5.0
Sun ≫ Jre Update update8 Version <= 1.5.0
Sun ≫ Jre Update update9 Version <= 1.5.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.88% 0.768
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:N/A:P
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

http://securityreason.com/securityalert/3527
http://www.securityfocus.com/archive/1/485942/100/0/threaded
http://www.securityfocus.com/bid/27185
https://exchange.xforce.ibmcloud.com/vulnerabilities/39549