CVE-2010-0886 describes an unspecified vulnerability within the Java Deployment Toolkit component of Oracle Java SE and Java for Business JDK and JRE versions 6 Update 10 through 19. This flaw allows remote attackers to compromise confidentiality, integrity, and availability through unknown vectors. With a CVSS score of 10.0, it represents a critical risk, indicating a network-exploitable vulnerability requiring no authentication, leading to complete compromise. While not on CISA's KEV catalog, exploit modules are available in Metasploit and ExploitDB, demonstrating its exploitability, despite a lack of significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.6.0CPE matchmatch criteria | cpe:2.3:a:sun:jre:1.6.0:update10:*:*:*:*:*:* | ||
1.6.0CPE matchmatch criteria | cpe:2.3:a:sun:jre:1.6.0:update11:*:*:*:*:*:* | ||
1.6.0CPE matchmatch criteria | cpe:2.3:a:sun:jre:1.6.0:update12:*:*:*:*:*:* | ||
1.6.0CPE matchmatch criteria | cpe:2.3:a:sun:jre:1.6.0:update13:*:*:*:*:*:* | ||
1.6.0CPE matchmatch criteria | cpe:2.3:a:sun:jre:1.6.0:update14:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.