Stack-based buffer overflow in javaws.exe in Sun Java Web Start in JRE 5.0 Update 11 and earlier, and 6.0 Update 1 and earlier, allows remote attackers to execute arbitrary code via a long codebase attribute in a JNLP file.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Java | — | Upgrade to Apple Java version 1.5.0.13Upgrade to Apple Java version 1.4.2.16 | Jan 26, 2012 | Jul 10, 2007 |
| Gentoo Linux | — | Upgrade dev-java/sun-jre-bin.Upgrade dev-java/sun-jdk.Upgrade app-emulation/emul-linux-x86-java. | Oct 30, 2017 | Jul 10, 2007 |
| Suse | — | Upgrade java-1_4_2-ibm-pluginUpgrade java-1_4_2-ibm-jdbcUpgrade java-1_4_2-ibm | Feb 17, 2015 | Jul 9, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub