CVE-2010-0840

Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, and 1.4.2_25 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.  NOTE: the previous information was obtained from the March 2010 CPU.  Oracle has not commented on claims from a reliable researcher that this is related to improper checks when executing privileged methods in the Java Runtime Environment (JRE), which allows attackers to execute arbitrary code via (1) an untrusted object that extends the trusted class but has not modified a certain method, or (2) "a similar trust issue with interfaces," aka "Trusted Methods Chaining Remote Code Execution Vulnerability."
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
oracleCNA
---
---
CVEADP
---
---
CISA-ADPADP
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 99%
VendorProductVersion
oraclejre
1.4.2_25:_25
oraclejre
1.5.0
oraclejre
1.6.0
opensuseopensuse
11.0
opensuseopensuse
11.1
opensuseopensuse
11.2
canonicalubuntu_linux
8.04
canonicalubuntu_linux
8.10
canonicalubuntu_linux
9.04
canonicalubuntu_linux
9.10
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
openjdk-6
natty
not-affected
maverick
not-affected
lucid
not-affected
karmic
Fixed 6b16-1.6.1-3ubuntu3
released
jaunty
Fixed 6b14-1.4.1-0ubuntu13
released
intrepid
Fixed 6b12-0ubuntu6.7
released
hardy
Fixed 6b11-2ubuntu2.2
released
dapper
dne
sun-java5
natty
dne
maverick
dne
lucid
dne
karmic
dne
jaunty
ignored
intrepid
ignored
hardy
ignored
dapper
ignored
sun-java6
natty
not-affected
maverick
not-affected
lucid
not-affected
karmic
Fixed 6.20dlj-0ubuntu1.9.10
released
jaunty
Fixed 6.20dlj-0ubuntu1.9.04
released
intrepid
ignored
hardy
Fixed 6.20dlj-0ubuntu1.8.04
released
dapper
dne
References