V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2010-4351
DEB
High

The JNLP SecurityManager in IcedTea (IcedTea.so) 1.7 before 1.7.7, 1.8 before 1.8.4, and 1.9 before 1.9.4 for Java OpenJDK returns from the…

CVSS
7.5
High
EPSS
0.03
p82
Published
2010-01-01
Updated
2010-01-01
Description

The JNLP SecurityManager in IcedTea (IcedTea.so) 1.7 before 1.7.7, 1.8 before 1.8.4, and 1.9 before 1.9.4 for Java OpenJDK returns from the checkPermission method instead of throwing an exception in certain circumstances, which might allow context-dependent attackers to bypass the intended security policy by creating instances of ClassLoader.

Tags · CWE
CWE-264
CWE-393
Affected products
Java-1.6.0-openjdkOpenjdk-6Openjdk-6Openjdk-6Openjdk-6Sun-java5Sun-java6Icedtea
CVSS vector
AV:N/AC:L/Au:N/C:P/I:P/A:P
Timeline
2010-01-01
Published
2010-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Authentication
Au: N
None (N)
Confidentiality Impact
C: P
Partial
Integrity Impact
I: P
Partial
Availability Impact
A: P
Partial
Exploit indicators
EPSS
0.025 · p82
Known exploited (KEV)
No
Known exploits — Сканер-ВС
No Сканер-ВС checks registered for this vulnerability yet.
Affected products
ProductVendorStatus
java-1.6.0-openjdkTracked
openjdk-6Tracked
openjdk-6Tracked
openjdk-6Tracked
openjdk-6Tracked
sun-java5Tracked
sun-java6Tracked
icedtea*Tracked
Source databases
DEB
CVE
RED
UBU