CVE-2010-1423
15.04.2010, 21:30
Argument injection vulnerability in the URI handler in (a) Java NPAPI plugin and (b) Java Deployment Toolkit in Java 6 Update 10, 19, and other versions, when running on Windows and possibly on Linux, allows remote attackers to execute arbitrary code via the (1) -J or (2) -XXaltjvm argument to javaws.exe, which is processed by the launch method. NOTE: some of these details are obtained from third party information.
Vendor | Product | Version |
---|---|---|
oracle | jdk | 𝑥 ≤ 1.6.0 |
oracle | jdk | 1.6.0 |
oracle | jre | 𝑥 ≤ 1.6.0 |
oracle | jre | 1.6.0 |
𝑥
= Vulnerable software versions

Ubuntu Releases
References