CVE-2010-3552 is a critical, unspecified vulnerability within the New Java Plug-in component of Oracle Java SE and Java for Business 6 Update 21, affecting both Sun JDK and JRE. With a CVSS score of 10.0, it allows remote attackers to compromise confidentiality, integrity, and availability with no authentication or user interaction required. While not listed in CISA's KEV catalog, public exploit code exists, including Metasploit modules and ExploitDB entries, indicating its exploitability. Despite the high severity and available exploits, there is no recorded community discussion or media coverage for this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.6.0CPE matchmatch criteria | cpe:2.3:a:sun:jre:*:update_21:*:*:*:*:*:* | ||
1.6.0CPE matchmatch criteria | cpe:2.3:a:sun:jre:1.6.0:*:*:*:*:*:*:* | ||
1.6.0CPE matchmatch criteria | cpe:2.3:a:sun:jre:1.6.0:update_1:*:*:*:*:*:* | ||
1.6.0CPE matchmatch criteria | cpe:2.3:a:sun:jre:1.6.0:update_10:*:*:*:*:*:* | ||
1.6.0CPE matchmatch criteria | cpe:2.3:a:sun:jre:1.6.0:update_11:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.