Exploitation Summary
EIP tracks 1 public exploit for CVE-2010-0838. PoCs published by Abysssec.
AI-analyzed exploit summary This exploit targets a stack overflow vulnerability in Java CMM's readMabCurveData function (CVE-2010-0838). It generates a malicious ICM file and an HTML page to trigger the vulnerability, executing shellcode when the Java applet is loaded.
Description
Unspecified vulnerability in the Java 2D component in Oracle Java SE and Java for Business 6 Update 18, 5.0, Update, and 23 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the March 2010 CPU. Oracle has not commented on claims from a reliable researcher that this is a stack-based buffer overflow using an untrusted size value in the readMabCurveData function in the CMM module in the JVM.
Exploits (1)
This exploit targets a stack overflow vulnerability in Java CMM's readMabCurveData function (CVE-2010-0838). It generates a malicious ICM file and an HTML page to trigger the vulnerability, executing shellcode when the Java applet is loaded.