Description
Format string vulnerability in the WebDAV implementation in webservd in Sun Java System Web Server 7.0 Update 6 allows remote attackers to cause a denial of service (daemon crash) and possibly have unspecified other impact via format string specifiers in the encoding attribute of the XML declaration in a PROPFIND request.
Exploits (1)
Scores
EPSS
0.0195
EPSS Percentile
83.5%
Details
CWE
CWE-134
Status
published
Products (1)
sun/java_system_web_server
7.0 update_6
Published
Jan 25, 2010
Tracked Since
Feb 18, 2026