CVE-2010-0388

Severity CVSS v4.0:
Pending analysis
Type:
CWE-134 Format String Vulnerability
Publication date:
25/01/2010
Last modified:
11/04/2025

Description

Format string vulnerability in the WebDAV implementation in webservd in Sun Java System Web Server 7.0 Update 6 allows remote attackers to cause a denial of service (daemon crash) and possibly have unspecified other impact via format string specifiers in the encoding attribute of the XML declaration in a PROPFIND request.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:sun:java_system_web_server:7.0:update_6:*:*:*:*:*:*