← All CVEs

CVE-2010-1423

high · 9.3

Argument injection vulnerability in the URI handler in (a) Java NPAPI plugin and (b) Java Deployment Toolkit in Java 6 Update 10, 19, and other versions, when running on Windows and possibly on Linux, allows remote attackers to execute arbitrary code via the (1) -J or (2) -XXaltjvm argument to javaws.exe, which is processed by the launch method. NOTE: some of these details are obtained from third party information.

9.3
CVSS
55.6%
EPSS (exploit prob.)
99th
EPSS percentile
2010-04-15
Published

AV:N/AC:M/Au:N/C:C/I:C/A:C

Weaknesses

CWE-78

Affected products

VendorProductAffected versions
oraclejdk<= 1.6.0
oraclejdk1.6.0
oraclejre<= 1.6.0
oraclejre1.6.0

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2010-1423