CVE-2010-0838

Oracle Java SE/Jav for Bus <23 - Info Disclosure

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2010-0838. PoCs published by Abysssec.

AI-analyzed exploit summary This exploit targets a stack overflow vulnerability in Java CMM's readMabCurveData function (CVE-2010-0838). It generates a malicious ICM file and an HTML page to trigger the vulnerability, executing shellcode when the Java applet is loaded.

Description

Unspecified vulnerability in the Java 2D component in Oracle Java SE and Java for Business 6 Update 18, 5.0, Update, and 23 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the March 2010 CPU. Oracle has not commented on claims from a reliable researcher that this is a stack-based buffer overflow using an untrusted size value in the readMabCurveData function in the CMM module in the JVM.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Abysssec · pythonremotewindows
https://www.exploit-db.com/exploits/15056

This exploit targets a stack overflow vulnerability in Java CMM's readMabCurveData function (CVE-2010-0838). It generates a malicious ICM file and an HTML page to trigger the vulnerability, executing shellcode when the Java applet is loaded.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Java Runtime Environment < 6.19
No auth needed
Prerequisites: Victim must visit the crafted HTML page with a vulnerable JRE version
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (37)

Core 37
Core References
Vendor Advisory vendor-advisory x_refsource_mandriva
http://www.mandriva.com/security/advisories?name=MDVSA-2010:084
Mailing List vendor-advisory x_refsource_apple
http://lists.apple.com/archives/security-announce/2010//May/msg00001.html
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10482
Mailing List vendor-advisory x_refsource_hp
http://marc.info/?l=bugtraq&m=134254866602253&w=2
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/39317
Vendor Advisory vendor-advisory x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2010-0383.html
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/40545
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2010/1454
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/39819
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/510534/100/0/threaded
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/39069
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2010/1107
Vendor Advisory vendor-advisory x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2010-0338.html
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2010/1793
Mailing List vendor-advisory x_refsource_apple
http://lists.apple.com/archives/security-announce/2010//May/msg00002.html
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/43308
Third Party Advisory x_refsource_misc
http://www.zerodayinitiative.com/advisories/ZDI-10-061
Various Sources vendor-advisory x_refsource_hp
http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02273751
Mailing List vendor-advisory x_refsource_hp
http://marc.info/?l=bugtraq&m=127557596201693&w=2
Vendor Advisory vendor-advisory x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2010-0339.html
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/39292
Vendor Advisory x_refsource_confirm
http://support.apple.com/kb/HT4170
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/39659
Vendor Advisory vendor-advisory x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2010-0471.html
Various Sources vendor-advisory x_refsource_ubuntu
http://ubuntu.com/usn/usn-923-1
Vendor Advisory vendor-advisory x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2010-0337.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/57346
Vendor Advisory x_refsource_confirm
http://support.apple.com/kb/HT4171
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A13923
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/516397/100/0/threaded
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2010/1191

Scores

EPSS 0.1490
EPSS Percentile 96.3%

Details

Status published
Products (5)
sun/jdk 1.6.0 (17 CPE variants)
sun/jdk 1.5.0 (22 CPE variants)
sun/jdk < 1.5.0
sun/jdk < 1.6.0
sun/jre 1.6.0 (9 CPE variants)
Published Apr 01, 2010
Tracked Since Feb 18, 2026