9.8

CVE-2010-0840

Warning

Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, and 1.4.2_25 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.  NOTE: the previous information was obtained from the March 2010 CPU.  Oracle has not commented on claims from a reliable researcher that this is related to improper checks when executing privileged methods in the Java Runtime Environment (JRE), which allows attackers to execute arbitrary code via (1) an untrusted object that extends the trusted class but has not modified a certain method, or (2) "a similar trust issue with interfaces," aka "Trusted Methods Chaining Remote Code Execution Vulnerability."

Data is provided by the National Vulnerability Database (NVD)
OracleJre Version1.4.2_25
OracleJre Version1.5.0 Updateupdate23
OracleJre Version1.6.0 Updateupdate18
OpensuseOpensuse Version11.0
OpensuseOpensuse Version11.1
OpensuseOpensuse Version11.2
CanonicalUbuntu Linux Version8.04 SwEdition-
CanonicalUbuntu Linux Version8.10
CanonicalUbuntu Linux Version9.04
CanonicalUbuntu Linux Version9.10

25.05.2022: CISA Known Exploited Vulnerabilities (KEV) Catalog

Oracle JRE Unspecified Vulnerability

Vulnerability

Unspecified vulnerability in the Java Runtime Environment (JRE) in Java SE component allows remote attackers to affect confidentiality, integrity, and availability via Unknown vectors.

Description

Apply updates per vendor instructions.

Required actions
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 92.55% 0.997
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
134c704f-9b21-4f2e-91b3-4a467353bcc0 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
http://www.securityfocus.com/archive/1/516397/100/0/threaded
Third Party Advisory
Broken Link
VDB Entry
http://secunia.com/advisories/40545
Vendor Advisory
Broken Link
http://secunia.com/advisories/39819
Vendor Advisory
Broken Link
http://support.apple.com/kb/HT4171
Third Party Advisory
Release Notes
http://secunia.com/advisories/39317
Vendor Advisory
Broken Link
http://secunia.com/advisories/39292
Vendor Advisory
Broken Link
http://secunia.com/advisories/43308
Vendor Advisory
Broken Link
http://support.apple.com/kb/HT4170
Third Party Advisory
Release Notes
http://ubuntu.com/usn/usn-923-1
Third Party Advisory
http://secunia.com/advisories/39659
Vendor Advisory
Broken Link
http://secunia.com/advisories/40211
Vendor Advisory
Broken Link
http://www.securityfocus.com/archive/1/510528/100/0/threaded
Third Party Advisory
Broken Link
VDB Entry
http://www.securityfocus.com/bid/39065
Third Party Advisory
Broken Link
VDB Entry