CVE-2010-0838 is an unspecified vulnerability in the Java 2D component of Oracle Java SE and Java for Business versions 6 Update 18, 5.0 Update, and 23. It is suspected to be a stack-based buffer overflow in the readMabCurveData function within the CMM module of the JVM. With a CVSS score of 7.5, this vulnerability is considered highly severe, allowing remote attackers to compromise confidentiality, integrity, and availability with low attack complexity. While not actively exploited in the wild, public exploit code exists, specifically a Metasploit module, though there is minimal community discussion or media coverage surrounding it.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.6.0CPE matchmatch criteria | cpe:2.3:a:sun:jre:*:update_18:*:*:*:*:*:* | ||
1.6.0CPE matchmatch criteria | cpe:2.3:a:sun:jre:1.6.0:*:*:*:*:*:*:* | ||
1.6.0CPE matchmatch criteria | cpe:2.3:a:sun:jre:1.6.0:update_1:*:*:*:*:*:* | ||
1.6.0CPE matchmatch criteria | cpe:2.3:a:sun:jre:1.6.0:update_10:*:*:*:*:*:* | ||
1.6.0CPE matchmatch criteria | cpe:2.3:a:sun:jre:1.6.0:update_11:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.