[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248392

 
 

909

 
 

195452

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2010-3561Date: (C)2010-10-19   (M)2024-02-22


Unspecified vulnerability in the CORBA component in Oracle Java SE and Java for Business 6 Update 21 and 5.0 Update 25 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the October 2010 CPU. Oracle has not commented on claims from a reliable downstream vendor that this involves the use of the privileged accept method in the ServerSocket class, which does not limit which hosts can connect and allows remote attackers to bypass intended network access restrictions.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 7.5
Exploit Score: 10.0
Impact Score: 6.4
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: LOW
Authentication: NONE
Confidentiality: PARTIAL
Integrity: PARTIAL
Availability: PARTIAL
  
Reference:
http://www.securityfocus.com/archive/1/516397/100/0/threaded
SECUNIA-41972
SECUNIA-42377
SECUNIA-42974
BID-44013
ADV-2010-3086
FEDORA-2010-16240
FEDORA-2010-16294
FEDORA-2010-16312
GLSA-201406-32
HPSBMU02799
RHSA-2010:0768
RHSA-2010:0770
RHSA-2010:0865
SSRT100333
SUSE-SR:2010:019
USN-1010-1
http://support.avaya.com/css/P8/documents/100114315
http://support.avaya.com/css/P8/documents/100114327
http://support.avaya.com/css/P8/documents/100123193
http://www.hitachi.co.jp/Prod/comp/soft1/security/info/vuls/HS10-030/index.html
http://www.oracle.com/technetwork/topics/security/cpujan2011-194091.html
http://www.oracle.com/technetwork/topics/security/javacpuoct2010-176258.html
http://www.vmware.com/security/advisories/VMSA-2011-0003.html
https://bugzilla.redhat.com/show_bug.cgi?id=639880
oval:org.mitre.oval:def:12200
oval:org.mitre.oval:def:12437

CPE    89
cpe:/a:sun:jdk:1.5.0:update17
cpe:/a:sun:jdk:1.5.0:update18
cpe:/a:sun:jdk:1.5.0:update19
cpe:/a:sun:jdk:1.5.0:update13
...
OVAL    9
oval:org.mitre.oval:def:12200
oval:org.secpod.oval:def:201839
oval:org.secpod.oval:def:700014
oval:org.secpod.oval:def:103243
...

© SecPod Technologies