CVE-2010-4476

EUVD-2022-4017
The Double.parseDouble method in Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 23 and earlier, 5.0 Update 27 and earlier, and 1.4.2_29 and earlier, as used in OpenJDK, Apache, JBossweb, and other products, allows remote attackers to cause a denial of service via a crafted string that triggers an infinite loop of estimations during conversion to a double-precision binary floating-point number, as demonstrated using 2.2250738585072012e-308.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:N/I:N/A:P
Base Score
CVSS 3.x
EPSS Score
Percentile: 97%
Affected Products (NVD)
VendorProductVersion
sunjre
𝑥
≤ 1.6.0
sunjre
1.6.0
sunjre
1.6.0
sunjre
1.6.0
sunjre
1.6.0
sunjre
1.6.0
sunjre
1.6.0
sunjre
1.6.0
sunjre
1.6.0
sunjre
1.6.0
sunjre
1.6.0
sunjre
1.6.0
sunjre
1.6.0
sunjre
1.6.0
sunjre
1.6.0
sunjre
1.6.0
sunjre
1.6.0
sunjre
1.6.0
sunjre
1.6.0
sunjre
1.6.0
sunjre
1.6.0
sunjre
1.6.0
sunjdk
𝑥
≤ 1.6.0
sunjdk
1.6.0
sunjdk
1.6.0
sunjdk
1.6.0
sunjdk
1.6.0
sunjdk
1.6.0
sunjdk
1.6.0
sunjdk
1.6.0
sunjdk
1.6.0
sunjdk
1.6.0
sunjdk
1.6.0
sunjdk
1.6.0
sunjdk
1.6.0
sunjdk
1.6.0
sunjdk
1.6.0
sunjdk
1.6.0
sunjdk
1.6.0
sunjdk
1.6.0
sunjdk
1.6.0
sunjdk
1.6.0
sunjdk
1.6.0
sunjdk
1.6.0
sunjdk
1.6.0
sunjdk
𝑥
≤ 1.5.0
sunjdk
1.5.0
sunjdk
1.5.0
sunjdk
1.5.0
sunjdk
1.5.0
sunjdk
1.5.0
sunjdk
1.5.0
sunjdk
1.5.0
sunjdk
1.5.0
sunjdk
1.5.0
sunjdk
1.5.0
sunjdk
1.5.0
sunjdk
1.5.0
sunjdk
1.5.0
sunjdk
1.5.0
sunjdk
1.5.0
sunjdk
1.5.0
sunjdk
1.5.0
sunjdk
1.5.0
sunjdk
1.5.0
sunjdk
1.5.0
sunjdk
1.5.0
sunjdk
1.5.0
sunjdk
1.5.0
sunjdk
1.5.0
sunjdk
1.5.0
sunjdk
1.5.0
sunjdk
1.5.0
sunsdk
𝑥
≤ 1.4.2_29
sunsdk
1.4.2
sunsdk
1.4.2_1:_1
sunsdk
1.4.2_02:_02
sunsdk
1.4.2_3:_3
sunsdk
1.4.2_4:_4
sunsdk
1.4.2_5:_5
sunsdk
1.4.2_6:_6
sunsdk
1.4.2_7:_7
sunsdk
1.4.2_8:_8
sunsdk
1.4.2_9:_9
sunsdk
1.4.2_10:_10
sunsdk
1.4.2_11:_11
sunsdk
1.4.2_12:_12
sunsdk
1.4.2_13:_13
sunsdk
1.4.2_14:_14
sunsdk
1.4.2_15:_15
sunsdk
1.4.2_16:_16
sunsdk
1.4.2_17:_17
sunsdk
1.4.2_18:_18
sunsdk
1.4.2_19:_19
sunsdk
1.4.2_20:_20
sunsdk
1.4.2_21:_21
sunsdk
1.4.2_22:_22
sunsdk
1.4.2_23:_23
sunsdk
1.4.2_24:_24
sunsdk
1.4.2_25:_25
sunsdk
1.4.2_26:_26
sunsdk
1.4.2_27:_27
sunsdk
1.4.2_28:_28
sunjre
𝑥
≤ 1.5.0
sunjre
1.5.0
sunjre
1.5.0
sunjre
1.5.0
sunjre
1.5.0
sunjre
1.5.0
sunjre
1.5.0
sunjre
1.5.0
sunjre
1.5.0
sunjre
1.5.0
sunjre
1.5.0
sunjre
1.5.0
sunjre
1.5.0
sunjre
1.5.0
sunjre
1.5.0
sunjre
1.5.0
sunjre
1.5.0
sunjre
1.5.0
sunjre
1.5.0
sunjre
1.5.0
sunjre
1.5.0
sunjre
1.5.0
sunjre
1.5.0
sunjre
1.5.0
sunjre
1.5.0
sunjre
1.5.0
sunjre
1.5.0
sunjre
1.5.0
sunjre
𝑥
≤ 1.4.2_29
sunjre
1.4.2
sunjre
1.4.2_1:_1
sunjre
1.4.2_2:_2
sunjre
1.4.2_3:_3
sunjre
1.4.2_4:_4
sunjre
1.4.2_5:_5
sunjre
1.4.2_6:_6
sunjre
1.4.2_7:_7
sunjre
1.4.2_8:_8
sunjre
1.4.2_9:_9
sunjre
1.4.2_10:_10
sunjre
1.4.2_11:_11
sunjre
1.4.2_12:_12
sunjre
1.4.2_13:_13
sunjre
1.4.2_14:_14
sunjre
1.4.2_15:_15
sunjre
1.4.2_16:_16
sunjre
1.4.2_17:_17
sunjre
1.4.2_18:_18
sunjre
1.4.2_19:_19
sunjre
1.4.2_20:_20
sunjre
1.4.2_21:_21
sunjre
1.4.2_22:_22
sunjre
1.4.2_23:_23
sunjre
1.4.2_24:_24
sunjre
1.4.2_25:_25
sunjre
1.4.2_26:_26
sunjre
1.4.2_27:_27
sunjre
1.4.2_28:_28
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
openjdk-6
dapper
dne
hardy
Fixed 6b27-1.12.3-0ubuntu1~08.04.1
released
karmic
Fixed 6b20-1.9.7-0ubuntu1~9.10.1
released
lucid
Fixed 6b20-1.9.7-0ubuntu1~10.04.1
released
maverick
Fixed 6b20-1.9.7-0ubuntu1
released
natty
Fixed 6b22-1.10-0ubuntu1
released
oneiric
Fixed 6b22-1.10-0ubuntu1
released
openjdk-6b18
dapper
dne
hardy
dne
karmic
Fixed 6b18-1.8.7-0ubuntu1~9.10.1
released
lucid
Fixed 6b18-1.8.7-0ubuntu1~10.04.2
released
maverick
Fixed 6b18-1.8.7-0ubuntu2.1
released
natty
Fixed 6b18-1.8.7-0ubuntu5
released
oneiric
Fixed 6b18-1.8.7-0ubuntu5
released
sun-java5
dapper
ignored
hardy
ignored
karmic
dne
lucid
dne
maverick
dne
natty
dne
oneiric
dne
sun-java6
dapper
dne
hardy
Fixed 6.24-1build0.8.04.1
released
karmic
Fixed 6.24-1build0.9.10.1
released
lucid
Fixed 6.24-1build0.10.04.1
released
maverick
Fixed 6.24-1build0.10.10.1
released
natty
Fixed 6.24-1build0.10.10.1
released
oneiric
not-affected
References