CVE-2010-1423

Severity CVSS v4.0:
Pending analysis
Type:
CWE-78 OS Command Injections
Publication date:
15/04/2010
Last modified:
11/04/2025

Description

Argument injection vulnerability in the URI handler in (a) Java NPAPI plugin and (b) Java Deployment Toolkit in Java 6 Update 10, 19, and other versions, when running on Windows and possibly on Linux, allows remote attackers to execute arbitrary code via the (1) -J or (2) -XXaltjvm argument to javaws.exe, which is processed by the launch method. NOTE: some of these details are obtained from third party information.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:oracle:jdk:*:update19:*:*:*:*:*:* 1.6.0 (including)
cpe:2.3:a:oracle:jdk:1.6.0:update10:*:*:*:*:*:*
cpe:2.3:a:oracle:jre:*:update19:*:*:*:*:*:* 1.6.0 (including)
cpe:2.3:a:oracle:jre:1.6.0:update_10:*:*:*:*:*:*