Vulnerability Name: | CVE-2005-0836 (CCN-19756) | ||||||||
Assigned: | 2005-03-16 | ||||||||
Published: | 2005-03-16 | ||||||||
Updated: | 2016-10-18 | ||||||||
Summary: | Argument injection vulnerability in Java Web Start for J2SE 1.4.2 up to 1.4.2_06 allows untrusted applications to gain privileges via the value parameter of a property tag in a JNLP file. | ||||||||
CVSS v3 Severity: | 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||
CVSS v2 Severity: | 10.0 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Gain Privileges | ||||||||
References: | Source: CCN Type: BugTraq Mailing List, Fri Mar 18 2005 - 13:08:08 CST Java Web Start argument injection vulnerability Source: MITRE Type: CNA CVE-2005-0418 Source: MITRE Type: CNA CVE-2005-0836 Source: CCN Type: Conectiva Linux Security Announcement CLSA-2005:977 Java vulnerabilities Source: MISC Type: UNKNOWN http://jouko.iki.fi/adv/ws.html Source: FULLDISC Type: UNKNOWN 20050318 Java Web Start argument injection vulnerability Source: CCN Type: SA14640 Java Web Start JNLP File Command Line Argument Injection Vulnerability Source: SECUNIA Type: Vendor Advisory 14640 Source: CCN Type: Sun Alert ID: 57740 Security Vulnerability With Java Web Start Source: SUNALERT Type: UNKNOWN 57740 Source: SUNALERT Type: UNKNOWN 200255 Source: SUNALERT Type: UNKNOWN 1000200 Source: CCN Type: CIAC INFORMATION BULLETIN P-161 Security Vulnerability with Java Web Start Source: CCN Type: GLSA-200503-28 Sun Java: Web Start argument injection vulnerability Source: GENTOO Type: Patch, Vendor Advisory GLSA-200503-28 Source: SUSE Type: UNKNOWN SUSE-SA:2005:032 Source: CCN Type: OSVDB ID: 14899 Sun Java Web Start JNLP File Arbitrary Command Execution Source: BID Type: Patch 12847 Source: CCN Type: BID-12847 Sun Java Web Start System Property Tags Remote Unauthorized Access Vulnerability Source: XF Type: UNKNOWN java-web-start-gain-privileges(19756) Source: SUSE Type: SUSE-SA:2005:032 SUN Java security problems | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
Oval Definitions | |||||||||
| |||||||||
BACK |