Attacker Value
Unknown
(0 users assessed)
Exploitability
Unknown
(0 users assessed)
User Interaction
Unknown
Privileges Required
Unknown
Attack Vector
Unknown
0

CVE-2010-0840

Disclosure Date: April 01, 2010
Exploited in the Wild
Add MITRE ATT&CK tactics and techniques that apply to this CVE.

Description

Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, and 1.4.2_25 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the March 2010 CPU. Oracle has not commented on claims from a reliable researcher that this is related to improper checks when executing privileged methods in the Java Runtime Environment (JRE), which allows attackers to execute arbitrary code via (1) an untrusted object that extends the trusted class but has not modified a certain method, or (2) “a similar trust issue with interfaces,” aka “Trusted Methods Chaining Remote Code Execution Vulnerability.”

Add Assessment

No one has assessed this topic. Be the first to add your voice to the community.

CVSS V3 Severity and Metrics
Base Score:
None
Impact Score:
Unknown
Exploitability Score:
Unknown
Vector:
Unknown
Attack Vector (AV):
Unknown
Attack Complexity (AC):
Unknown
Privileges Required (PR):
Unknown
User Interaction (UI):
Unknown
Scope (S):
Unknown
Confidentiality (C):
Unknown
Integrity (I):
Unknown
Availability (A):
Unknown

General Information

Vendors

  • sun

Products

  • jdk,
  • jdk 1.5.0,
  • jdk 1.6.0,
  • jre,
  • jre 1.4.2,
  • jre 1.4.2 1,
  • jre 1.4.2 10,
  • jre 1.4.2 11,
  • jre 1.4.2 12,
  • jre 1.4.2 13,
  • jre 1.4.2 14,
  • jre 1.4.2 15,
  • jre 1.4.2 16,
  • jre 1.4.2 17,
  • jre 1.4.2 18,
  • jre 1.4.2 19,
  • jre 1.4.2 2,
  • jre 1.4.2 20,
  • jre 1.4.2 21,
  • jre 1.4.2 22,
  • jre 1.4.2 23,
  • jre 1.4.2 24,
  • jre 1.4.2 3,
  • jre 1.4.2 4,
  • jre 1.4.2 5,
  • jre 1.4.2 6,
  • jre 1.4.2 7,
  • jre 1.4.2 8,
  • jre 1.4.2 9,
  • jre 1.5.0,
  • jre 1.6.0,
  • sdk,
  • sdk 1.4.2,
  • sdk 1.4.2 02,
  • sdk 1.4.2 1,
  • sdk 1.4.2 10,
  • sdk 1.4.2 11,
  • sdk 1.4.2 12,
  • sdk 1.4.2 13,
  • sdk 1.4.2 14,
  • sdk 1.4.2 15,
  • sdk 1.4.2 16,
  • sdk 1.4.2 17,
  • sdk 1.4.2 18,
  • sdk 1.4.2 19,
  • sdk 1.4.2 20,
  • sdk 1.4.2 21,
  • sdk 1.4.2 22,
  • sdk 1.4.2 23,
  • sdk 1.4.2 24,
  • sdk 1.4.2 3,
  • sdk 1.4.2 4,
  • sdk 1.4.2 5,
  • sdk 1.4.2 6,
  • sdk 1.4.2 7,
  • sdk 1.4.2 8,
  • sdk 1.4.2 9

Exploited in the Wild

Reported by:

References

Advisory

Additional Info

Technical Analysis