[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248392

 
 

909

 
 

195452

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2010-4471Date: (C)2011-02-17   (M)2024-04-19


Unspecified vulnerability in the Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 23 and earlier, and 5.0 Update 27 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality via unknown vectors related to 2D. NOTE: the previous information was obtained from the February 2011 CPU. Oracle has not commented on claims from a downstream vendor that this issue is related to the exposure of system properties via vectors related to Font.createFont and exception text.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 5.0
Exploit Score: 10.0
Impact Score: 2.9
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: LOW
Authentication: NONE
Confidentiality: PARTIAL
Integrity: NONE
Availability: NONE
  
Reference:
SECUNIA-43350
SECUNIA-44954
BID-46399
DSA-2224
FEDORA-2011-1631
FEDORA-2011-1645
GLSA-201406-32
HPSBMU02799
MDVSA-2011:054
RHSA-2011:0282
RHSA-2011:0880
SSRT100867
http://www.hitachi.co.jp/Prod/comp/soft1/global/security/info/vuls/HS11-003/index.html
http://www.oracle.com/technetwork/topics/security/cpuapr2011-301950.html
http://www.oracle.com/technetwork/topics/security/javacpufeb2011-304611.html
oracle-runtime-information-disclosure(65405)
oval:org.mitre.oval:def:12089
oval:org.mitre.oval:def:14417

CPE    95
cpe:/a:sun:jdk:1.5.0:update17
cpe:/a:sun:jdk:1.5.0:update18
cpe:/a:sun:jdk:1.5.0:update19
cpe:/a:sun:jdk:1.5.0:update13
...
OVAL    21
oval:org.secpod.oval:def:400013
oval:org.secpod.oval:def:505809
oval:org.secpod.oval:def:505811
oval:org.secpod.oval:def:3051
...

© SecPod Technologies