{"api_version":"1","generated_at":"2026-07-23T06:06:29+00:00","cve":"CVE-2010-0840","urls":{"html":"https://cve.report/CVE-2010-0840","api":"https://cve.report/api/cve/CVE-2010-0840.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2010-0840","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2010-0840"},"summary":{"title":"CVE-2010-0840","description":"Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, and 1.4.2_25 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.  NOTE: the previous information was obtained from the March 2010 CPU.  Oracle has not commented on claims from a reliable researcher that this is related to improper checks when executing privileged methods in the Java Runtime Environment (JRE), which allows attackers to execute arbitrary code via (1) an untrusted object that extends the trusted class but has not modified a certain method, or (2) \"a similar trust issue with interfaces,\" aka \"Trusted Methods Chaining Remote Code Execution Vulnerability.\"","state":"PUBLISHED","assigner":"oracle","published_at":"2010-04-01 16:30:00","updated_at":"2026-04-21 18:07:32"},"problem_types":["NVD-CWE-noinfo","n/a","CWE-noinfo Not enough information"],"metrics":[{"version":"3.1","source":"nvd@nist.gov","type":"Primary","score":"9.8","severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"}},{"version":"3.1","source":"ADP","type":"DECLARED","score":"9.8","severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","data":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.1"}},{"version":"3.1","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","score":"9.8","severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"}},{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://www.securityfocus.com/archive/1/516397/100/0/threaded","name":"http://www.securityfocus.com/archive/1/516397/100/0/threaded","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Third Party Advisory","VDB Entry"],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2010/1191","name":"http://www.vupen.com/english/advisories/2010/1191","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Vendor Advisory"],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2010/1454","name":"http://www.vupen.com/english/advisories/2010/1454","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Vendor Advisory"],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://support.apple.com/kb/HT4170","name":"http://support.apple.com/kb/HT4170","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Third Party Advisory"],"title":"About the security content of Java for Mac OS X 10.5 Update 7","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.mandriva.com/security/advisories?name=MDVSA-2010:084","name":"http://www.mandriva.com/security/advisories?name=MDVSA-2010:084","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"Advisories | Mandriva","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.html","name":"http://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes"],"title":"VMware vCenter Server 4.1 Update 1 Release Notes","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.oracle.com/technetwork/topics/security/cpuoct2010-175626.html","name":"http://www.oracle.com/technetwork/topics/security/cpuoct2010-175626.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Third Party Advisory"],"title":"Oracle Critical Patch Update Pre-Release Announcement - October 2010","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.zerodayinitiative.com/advisories/ZDI-10-056","name":"http://www.zerodayinitiative.com/advisories/ZDI-10-056","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"Zero Day Initiative","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/39317","name":"http://secunia.com/advisories/39317","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Vendor Advisory"],"title":"SUSE Update for Multiple Packages - Advisories - Community","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.redhat.com/support/errata/RHSA-2010-0339.html","name":"http://www.redhat.com/support/errata/RHSA-2010-0339.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"rhn.redhat.com | Red Hat Support","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/39819","name":"http://secunia.com/advisories/39819","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Vendor Advisory"],"title":"Apple Mac OS X update for Java - Advisories - Community","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://marc.info/?l=bugtraq&m=127557596201693&w=2","name":"http://marc.info/?l=bugtraq&m=127557596201693&w=2","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List"],"title":"'[security bulletin] HPSBUX02524 SSRT100089 rev.1 - HP-UX Running Java, Remote Execution of Arbitrary' - MARC","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vmware.com/security/advisories/VMSA-2011-0003.html","name":"http://www.vmware.com/security/advisories/VMSA-2011-0003.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"VMSA-2011-0003","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.apple.com/archives/security-announce/2010//May/msg00001.html","name":"http://lists.apple.com/archives/security-announce/2010//May/msg00001.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Third Party Advisory"],"title":"APPLE-SA-2010-05-18-1 Java for Mac OS X 10.6 Update 2","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/40211","name":"http://secunia.com/advisories/40211","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Vendor Advisory"],"title":"Red Hat update for java-1.5.0-ibm - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/39659","name":"http://secunia.com/advisories/39659","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Vendor Advisory"],"title":"Red Hat update for java-1.6.0-ibm - Advisories - Community","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9974","name":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9974","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"Repository  /  Oval Repository","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/39292","name":"http://secunia.com/advisories/39292","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Vendor Advisory"],"title":"Ubuntu update for openjdk-6 - Advisories - Community","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2010/1793","name":"http://www.vupen.com/english/advisories/2010/1793","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Vendor Advisory"],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/39065","name":"http://www.securityfocus.com/bid/39065","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Third Party Advisory","VDB Entry"],"title":"Oracle Java SE and Java for Business JRE Trusted Method Chaining Remote Code Execution Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.redhat.com/support/errata/RHSA-2010-0489.html","name":"http://www.redhat.com/support/errata/RHSA-2010-0489.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"Support | Red Hat","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://marc.info/?l=bugtraq&m=134254866602253&w=2","name":"http://marc.info/?l=bugtraq&m=134254866602253&w=2","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List"],"title":"'[security bulletin] HPSBMU02799 SSRT100867 rev.1 - HP Network Node Manager i (NNMi) v9.0x Running JD' - MARC","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/43308","name":"http://secunia.com/advisories/43308","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Vendor Advisory"],"title":"VMware vCenter / ESX Server Update for Oracle (Sun) JRE - Advisories - Community","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.redhat.com/support/errata/RHSA-2010-0383.html","name":"http://www.redhat.com/support/errata/RHSA-2010-0383.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"rhn.redhat.com | Red Hat Support","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.oracle.com/technetwork/topics/security/javacpumar2010-083341.html","name":"http://www.oracle.com/technetwork/topics/security/javacpumar2010-083341.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Third Party Advisory"],"title":"Oracle Java SE and Java for Business Critical Patch Update Advisory - March 2010","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://support.apple.com/kb/HT4171","name":"http://support.apple.com/kb/HT4171","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Third Party Advisory"],"title":"About the security content of Java for Mac OS X 10.6 Update 2","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.redhat.com/support/errata/RHSA-2010-0338.html","name":"http://www.redhat.com/support/errata/RHSA-2010-0338.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"Support","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2010-04/msg00001.html","name":"http://lists.opensuse.org/opensuse-security-announce/2010-04/msg00001.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Third Party Advisory"],"title":"[security-announce] SUSE Security Summary Report: SUSE-SR:2010:008","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2010/1523","name":"http://www.vupen.com/english/advisories/2010/1523","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Vendor Advisory"],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/40545","name":"http://secunia.com/advisories/40545","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Vendor Advisory"],"title":"HP Systems Insight Manager Multiple Vulnerabilities - Advisories - Community","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/archive/1/510528/100/0/threaded","name":"http://www.securityfocus.com/archive/1/510528/100/0/threaded","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Third Party Advisory","VDB Entry"],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2010-09/msg00006.html","name":"http://lists.opensuse.org/opensuse-security-announce/2010-09/msg00006.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Third Party Advisory"],"title":"[security-announce] SUSE Security Summary Report: SUSE-SR:2010:017","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2010-05/msg00001.html","name":"http://lists.opensuse.org/opensuse-security-announce/2010-05/msg00001.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Third Party Advisory"],"title":"[security-announce] SUSE Security Summary Report: SUSE-SR:2010:011","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://ubuntu.com/usn/usn-923-1","name":"http://ubuntu.com/usn/usn-923-1","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"USN-923-1: OpenJDK vulnerabilities | Ubuntu","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.redhat.com/support/errata/RHSA-2010-0471.html","name":"http://www.redhat.com/support/errata/RHSA-2010-0471.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"rhn.redhat.com | Red Hat Support","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2010/1107","name":"http://www.vupen.com/english/advisories/2010/1107","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A13971","name":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A13971","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"Repository  /  Oval Repository","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2010-0840","name":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2010-0840","refsource":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["US Government Resource"],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"http://www.redhat.com/support/errata/RHSA-2010-0337.html","name":"http://www.redhat.com/support/errata/RHSA-2010-0337.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"Support","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02273751","name":"http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02273751","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"","mime":"","httpstatus":"-1","archivestatus":"404"},{"url":"http://lists.apple.com/archives/security-announce/2010//May/msg00002.html","name":"http://lists.apple.com/archives/security-announce/2010//May/msg00002.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Third Party Advisory"],"title":"APPLE-SA-2010-05-18-2 Java for Mac OS X 10.5 Update 7","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2010-0840","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2010-0840","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[{"source":"ADP","time":"2022-05-25T00:00:00.000Z","lang":"en","value":"CVE-2010-0840 added to CISA KEV"}],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2010","cve_id":"840","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"canonical","cpe5":"ubuntu_linux","cpe6":"8.04","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"-","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2010","cve_id":"840","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"canonical","cpe5":"ubuntu_linux","cpe6":"8.10","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2010","cve_id":"840","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"canonical","cpe5":"ubuntu_linux","cpe6":"9.04","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2010","cve_id":"840","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"canonical","cpe5":"ubuntu_linux","cpe6":"9.10","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2010","cve_id":"840","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"opensuse","cpe5":"opensuse","cpe6":"11.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2010","cve_id":"840","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"opensuse","cpe5":"opensuse","cpe6":"11.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2010","cve_id":"840","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"opensuse","cpe5":"opensuse","cpe6":"11.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2010","cve_id":"840","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"oracle","cpe5":"jre","cpe6":"1.4.2_25","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2010","cve_id":"840","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"oracle","cpe5":"jre","cpe6":"1.5.0","cpe7":"update23","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2010","cve_id":"840","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"oracle","cpe5":"jre","cpe6":"1.6.0","cpe7":"update18","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":{"cve_year":"2010","cve_id":"840","cve":"CVE-2010-0840","vendorProject":"Oracle","product":"Java Runtime Environment (JRE)","vulnerabilityName":"Oracle JRE Unspecified Vulnerability","dateAdded":"2022-05-25","shortDescription":"Unspecified vulnerability in the Java Runtime Environment (JRE) in Java SE component allows remote attackers to affect confidentiality, integrity, and availability via Unknown vectors.","requiredAction":"Apply updates per vendor instructions.","dueDate":"2022-06-15","knownRansomwareCampaignUse":"Unknown","notes":"https://nvd.nist.gov/vuln/detail/CVE-2010-0840","cwes":"","catalogVersion":"2026.07.22","updated_at":"2026-07-22 20:07:15"},"epss":{"cve_year":"2010","cve_id":"840","cve":"CVE-2010-0840","epss":"0.963190000","percentile":"0.998740000","score_date":"2026-07-22","updated_at":"2026-07-23 00:09:33"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T00:59:39.358Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"APPLE-SA-2010-05-18-1","tags":["vendor-advisory","x_refsource_APPLE","x_transferred"],"url":"http://lists.apple.com/archives/security-announce/2010//May/msg00001.html"},{"name":"HPSBMU02799","tags":["vendor-advisory","x_refsource_HP","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=134254866602253&w=2"},{"name":"20100405 ZDI-10-056: Sun Java Runtime Environment Trusted Methods Chaining Remote Code Execution Vulnerability","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.securityfocus.com/archive/1/510528/100/0/threaded"},{"name":"39317","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/39317"},{"name":"RHSA-2010:0383","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://www.redhat.com/support/errata/RHSA-2010-0383.html"},{"name":"40545","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/40545"},{"name":"ADV-2010-1454","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2010/1454"},{"name":"oval:org.mitre.oval:def:13971","tags":["vdb-entry","signature","x_refsource_OVAL","x_transferred"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A13971"},{"name":"39819","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/39819"},{"name":"ADV-2010-1107","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2010/1107"},{"name":"RHSA-2010:0338","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://www.redhat.com/support/errata/RHSA-2010-0338.html"},{"name":"ADV-2010-1793","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2010/1793"},{"name":"APPLE-SA-2010-05-18-2","tags":["vendor-advisory","x_refsource_APPLE","x_transferred"],"url":"http://lists.apple.com/archives/security-announce/2010//May/msg00002.html"},{"name":"SUSE-SR:2010:011","tags":["vendor-advisory","x_refsource_SUSE","x_transferred"],"url":"http://lists.opensuse.org/opensuse-security-announce/2010-05/msg00001.html"},{"name":"43308","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/43308"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.oracle.com/technetwork/topics/security/cpuoct2010-175626.html"},{"name":"SSRT100179","tags":["vendor-advisory","x_refsource_HP","x_transferred"],"url":"http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02273751"},{"name":"SSRT100089","tags":["vendor-advisory","x_refsource_HP","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=127557596201693&w=2"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.oracle.com/technetwork/topics/security/javacpumar2010-083341.html"},{"name":"RHSA-2010:0339","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://www.redhat.com/support/errata/RHSA-2010-0339.html"},{"name":"HPSBUX02524","tags":["vendor-advisory","x_refsource_HP","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=127557596201693&w=2"},{"name":"39292","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/39292"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://support.apple.com/kb/HT4170"},{"name":"ADV-2010-1523","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2010/1523"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.html"},{"name":"39065","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/39065"},{"name":"SUSE-SR:2010:008","tags":["vendor-advisory","x_refsource_SUSE","x_transferred"],"url":"http://lists.opensuse.org/opensuse-security-announce/2010-04/msg00001.html"},{"name":"39659","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/39659"},{"name":"RHSA-2010:0471","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://www.redhat.com/support/errata/RHSA-2010-0471.html"},{"name":"SUSE-SR:2010:017","tags":["vendor-advisory","x_refsource_SUSE","x_transferred"],"url":"http://lists.opensuse.org/opensuse-security-announce/2010-09/msg00006.html"},{"name":"USN-923-1","tags":["vendor-advisory","x_refsource_UBUNTU","x_transferred"],"url":"http://ubuntu.com/usn/usn-923-1"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.vmware.com/security/advisories/VMSA-2011-0003.html"},{"name":"RHSA-2010:0337","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://www.redhat.com/support/errata/RHSA-2010-0337.html"},{"name":"RHSA-2010:0489","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://www.redhat.com/support/errata/RHSA-2010-0489.html"},{"name":"HPSBMA02547","tags":["vendor-advisory","x_refsource_HP","x_transferred"],"url":"http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02273751"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.zerodayinitiative.com/advisories/ZDI-10-056"},{"name":"40211","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/40211"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://support.apple.com/kb/HT4171"},{"name":"oval:org.mitre.oval:def:9974","tags":["vdb-entry","signature","x_refsource_OVAL","x_transferred"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9974"},{"name":"MDVSA-2010:084","tags":["vendor-advisory","x_refsource_MANDRIVA","x_transferred"],"url":"http://www.mandriva.com/security/advisories?name=MDVSA-2010:084"},{"name":"20110211 VMSA-2011-0003 Third party component updates for VMware vCenter Server, vCenter Update Manager, ESXi and ESX","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.securityfocus.com/archive/1/516397/100/0/threaded"},{"name":"ADV-2010-1191","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2010/1191"}],"title":"CVE Program Container"},{"metrics":[{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.1"}},{"other":{"content":{"id":"CVE-2010-0840","options":[{"Exploitation":"active"},{"Automatable":"yes"},{"Technical Impact":"total"}],"role":"CISA Coordinator","timestamp":"2025-02-10T18:55:12.239252Z","version":"2.0.3"},"type":"ssvc"}},{"other":{"content":{"dateAdded":"2022-05-25","reference":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2010-0840"},"type":"kev"}}],"problemTypes":[{"descriptions":[{"description":"CWE-noinfo Not enough information","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2025-10-22T00:05:52.754Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"references":[{"tags":["government-resource"],"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2010-0840"}],"timeline":[{"lang":"en","time":"2022-05-25T00:00:00.000Z","value":"CVE-2010-0840 added to CISA KEV"}],"title":"CISA ADP Vulnrichment"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2010-03-30T00:00:00.000Z","descriptions":[{"lang":"en","value":"Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, and 1.4.2_25 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.  NOTE: the previous information was obtained from the March 2010 CPU.  Oracle has not commented on claims from a reliable researcher that this is related to improper checks when executing privileged methods in the Java Runtime Environment (JRE), which allows attackers to execute arbitrary code via (1) an untrusted object that extends the trusted class but has not modified a certain method, or (2) \"a similar trust issue with interfaces,\" aka \"Trusted Methods Chaining Remote Code Execution Vulnerability.\""}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2018-10-10T18:57:01.000Z","orgId":"43595867-4340-4103-b7a2-9a5208d29a85","shortName":"oracle"},"references":[{"name":"APPLE-SA-2010-05-18-1","tags":["vendor-advisory","x_refsource_APPLE"],"url":"http://lists.apple.com/archives/security-announce/2010//May/msg00001.html"},{"name":"HPSBMU02799","tags":["vendor-advisory","x_refsource_HP"],"url":"http://marc.info/?l=bugtraq&m=134254866602253&w=2"},{"name":"20100405 ZDI-10-056: Sun Java Runtime Environment Trusted Methods Chaining Remote Code Execution Vulnerability","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.securityfocus.com/archive/1/510528/100/0/threaded"},{"name":"39317","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/39317"},{"name":"RHSA-2010:0383","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://www.redhat.com/support/errata/RHSA-2010-0383.html"},{"name":"40545","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/40545"},{"name":"ADV-2010-1454","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2010/1454"},{"name":"oval:org.mitre.oval:def:13971","tags":["vdb-entry","signature","x_refsource_OVAL"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A13971"},{"name":"39819","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/39819"},{"name":"ADV-2010-1107","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2010/1107"},{"name":"RHSA-2010:0338","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://www.redhat.com/support/errata/RHSA-2010-0338.html"},{"name":"ADV-2010-1793","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2010/1793"},{"name":"APPLE-SA-2010-05-18-2","tags":["vendor-advisory","x_refsource_APPLE"],"url":"http://lists.apple.com/archives/security-announce/2010//May/msg00002.html"},{"name":"SUSE-SR:2010:011","tags":["vendor-advisory","x_refsource_SUSE"],"url":"http://lists.opensuse.org/opensuse-security-announce/2010-05/msg00001.html"},{"name":"43308","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/43308"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.oracle.com/technetwork/topics/security/cpuoct2010-175626.html"},{"name":"SSRT100179","tags":["vendor-advisory","x_refsource_HP"],"url":"http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02273751"},{"name":"SSRT100089","tags":["vendor-advisory","x_refsource_HP"],"url":"http://marc.info/?l=bugtraq&m=127557596201693&w=2"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.oracle.com/technetwork/topics/security/javacpumar2010-083341.html"},{"name":"RHSA-2010:0339","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://www.redhat.com/support/errata/RHSA-2010-0339.html"},{"name":"HPSBUX02524","tags":["vendor-advisory","x_refsource_HP"],"url":"http://marc.info/?l=bugtraq&m=127557596201693&w=2"},{"name":"39292","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/39292"},{"tags":["x_refsource_CONFIRM"],"url":"http://support.apple.com/kb/HT4170"},{"name":"ADV-2010-1523","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2010/1523"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.html"},{"name":"39065","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/39065"},{"name":"SUSE-SR:2010:008","tags":["vendor-advisory","x_refsource_SUSE"],"url":"http://lists.opensuse.org/opensuse-security-announce/2010-04/msg00001.html"},{"name":"39659","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/39659"},{"name":"RHSA-2010:0471","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://www.redhat.com/support/errata/RHSA-2010-0471.html"},{"name":"SUSE-SR:2010:017","tags":["vendor-advisory","x_refsource_SUSE"],"url":"http://lists.opensuse.org/opensuse-security-announce/2010-09/msg00006.html"},{"name":"USN-923-1","tags":["vendor-advisory","x_refsource_UBUNTU"],"url":"http://ubuntu.com/usn/usn-923-1"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.vmware.com/security/advisories/VMSA-2011-0003.html"},{"name":"RHSA-2010:0337","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://www.redhat.com/support/errata/RHSA-2010-0337.html"},{"name":"RHSA-2010:0489","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://www.redhat.com/support/errata/RHSA-2010-0489.html"},{"name":"HPSBMA02547","tags":["vendor-advisory","x_refsource_HP"],"url":"http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02273751"},{"tags":["x_refsource_MISC"],"url":"http://www.zerodayinitiative.com/advisories/ZDI-10-056"},{"name":"40211","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/40211"},{"tags":["x_refsource_CONFIRM"],"url":"http://support.apple.com/kb/HT4171"},{"name":"oval:org.mitre.oval:def:9974","tags":["vdb-entry","signature","x_refsource_OVAL"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9974"},{"name":"MDVSA-2010:084","tags":["vendor-advisory","x_refsource_MANDRIVA"],"url":"http://www.mandriva.com/security/advisories?name=MDVSA-2010:084"},{"name":"20110211 VMSA-2011-0003 Third party component updates for VMware vCenter Server, vCenter Update Manager, ESXi and ESX","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.securityfocus.com/archive/1/516397/100/0/threaded"},{"name":"ADV-2010-1191","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2010/1191"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"secalert_us@oracle.com","ID":"CVE-2010-0840","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, and 1.4.2_25 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.  NOTE: the previous information was obtained from the March 2010 CPU.  Oracle has not commented on claims from a reliable researcher that this is related to improper checks when executing privileged methods in the Java Runtime Environment (JRE), which allows attackers to execute arbitrary code via (1) an untrusted object that extends the trusted class but has not modified a certain method, or (2) \"a similar trust issue with interfaces,\" aka \"Trusted Methods Chaining Remote Code Execution Vulnerability.\""}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"APPLE-SA-2010-05-18-1","refsource":"APPLE","url":"http://lists.apple.com/archives/security-announce/2010//May/msg00001.html"},{"name":"HPSBMU02799","refsource":"HP","url":"http://marc.info/?l=bugtraq&m=134254866602253&w=2"},{"name":"20100405 ZDI-10-056: Sun Java Runtime Environment Trusted Methods Chaining Remote Code Execution Vulnerability","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/510528/100/0/threaded"},{"name":"39317","refsource":"SECUNIA","url":"http://secunia.com/advisories/39317"},{"name":"RHSA-2010:0383","refsource":"REDHAT","url":"http://www.redhat.com/support/errata/RHSA-2010-0383.html"},{"name":"40545","refsource":"SECUNIA","url":"http://secunia.com/advisories/40545"},{"name":"ADV-2010-1454","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2010/1454"},{"name":"oval:org.mitre.oval:def:13971","refsource":"OVAL","url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A13971"},{"name":"39819","refsource":"SECUNIA","url":"http://secunia.com/advisories/39819"},{"name":"ADV-2010-1107","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2010/1107"},{"name":"RHSA-2010:0338","refsource":"REDHAT","url":"http://www.redhat.com/support/errata/RHSA-2010-0338.html"},{"name":"ADV-2010-1793","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2010/1793"},{"name":"APPLE-SA-2010-05-18-2","refsource":"APPLE","url":"http://lists.apple.com/archives/security-announce/2010//May/msg00002.html"},{"name":"SUSE-SR:2010:011","refsource":"SUSE","url":"http://lists.opensuse.org/opensuse-security-announce/2010-05/msg00001.html"},{"name":"43308","refsource":"SECUNIA","url":"http://secunia.com/advisories/43308"},{"name":"http://www.oracle.com/technetwork/topics/security/cpuoct2010-175626.html","refsource":"CONFIRM","url":"http://www.oracle.com/technetwork/topics/security/cpuoct2010-175626.html"},{"name":"SSRT100179","refsource":"HP","url":"http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02273751"},{"name":"SSRT100089","refsource":"HP","url":"http://marc.info/?l=bugtraq&m=127557596201693&w=2"},{"name":"http://www.oracle.com/technetwork/topics/security/javacpumar2010-083341.html","refsource":"CONFIRM","url":"http://www.oracle.com/technetwork/topics/security/javacpumar2010-083341.html"},{"name":"RHSA-2010:0339","refsource":"REDHAT","url":"http://www.redhat.com/support/errata/RHSA-2010-0339.html"},{"name":"HPSBUX02524","refsource":"HP","url":"http://marc.info/?l=bugtraq&m=127557596201693&w=2"},{"name":"39292","refsource":"SECUNIA","url":"http://secunia.com/advisories/39292"},{"name":"http://support.apple.com/kb/HT4170","refsource":"CONFIRM","url":"http://support.apple.com/kb/HT4170"},{"name":"ADV-2010-1523","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2010/1523"},{"name":"http://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.html","refsource":"CONFIRM","url":"http://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.html"},{"name":"39065","refsource":"BID","url":"http://www.securityfocus.com/bid/39065"},{"name":"SUSE-SR:2010:008","refsource":"SUSE","url":"http://lists.opensuse.org/opensuse-security-announce/2010-04/msg00001.html"},{"name":"39659","refsource":"SECUNIA","url":"http://secunia.com/advisories/39659"},{"name":"RHSA-2010:0471","refsource":"REDHAT","url":"http://www.redhat.com/support/errata/RHSA-2010-0471.html"},{"name":"SUSE-SR:2010:017","refsource":"SUSE","url":"http://lists.opensuse.org/opensuse-security-announce/2010-09/msg00006.html"},{"name":"USN-923-1","refsource":"UBUNTU","url":"http://ubuntu.com/usn/usn-923-1"},{"name":"http://www.vmware.com/security/advisories/VMSA-2011-0003.html","refsource":"CONFIRM","url":"http://www.vmware.com/security/advisories/VMSA-2011-0003.html"},{"name":"RHSA-2010:0337","refsource":"REDHAT","url":"http://www.redhat.com/support/errata/RHSA-2010-0337.html"},{"name":"RHSA-2010:0489","refsource":"REDHAT","url":"http://www.redhat.com/support/errata/RHSA-2010-0489.html"},{"name":"HPSBMA02547","refsource":"HP","url":"http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02273751"},{"name":"http://www.zerodayinitiative.com/advisories/ZDI-10-056","refsource":"MISC","url":"http://www.zerodayinitiative.com/advisories/ZDI-10-056"},{"name":"40211","refsource":"SECUNIA","url":"http://secunia.com/advisories/40211"},{"name":"http://support.apple.com/kb/HT4171","refsource":"CONFIRM","url":"http://support.apple.com/kb/HT4171"},{"name":"oval:org.mitre.oval:def:9974","refsource":"OVAL","url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9974"},{"name":"MDVSA-2010:084","refsource":"MANDRIVA","url":"http://www.mandriva.com/security/advisories?name=MDVSA-2010:084"},{"name":"20110211 VMSA-2011-0003 Third party component updates for VMware vCenter Server, vCenter Update Manager, ESXi and ESX","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/516397/100/0/threaded"},{"name":"ADV-2010-1191","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2010/1191"}]}}}},"cveMetadata":{"assignerOrgId":"43595867-4340-4103-b7a2-9a5208d29a85","assignerShortName":"oracle","cveId":"CVE-2010-0840","datePublished":"2010-04-01T16:00:00.000Z","dateReserved":"2010-03-03T00:00:00.000Z","dateUpdated":"2025-10-22T00:05:52.754Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2010-04-01 16:30:00","lastModifiedDate":"2026-04-21 18:07:32","problem_types":["NVD-CWE-noinfo","n/a","CWE-noinfo Not enough information"],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:jre:1.4.2_25:*:*:*:*:*:*:*","matchCriteriaId":"A4FF2B8F-606B-4721-8DC8-9F3A87E5F6DC"},{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:jre:1.5.0:update23:*:*:*:*:*:*","matchCriteriaId":"708418EA-CFB6-4AFC-9327-E974F99E7323"},{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:jre:1.6.0:update18:*:*:*:*:*:*","matchCriteriaId":"381EFA43-DB73-48EA-A4B1-F451EF60D845"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:opensuse:opensuse:11.0:*:*:*:*:*:*:*","matchCriteriaId":"1B42AB65-443B-4655-BAEA-4EB4A43D9509"},{"vulnerable":true,"criteria":"cpe:2.3:o:opensuse:opensuse:11.1:*:*:*:*:*:*:*","matchCriteriaId":"FBF7B6A8-3DF9-46EC-A90E-6EF68C39F883"},{"vulnerable":true,"criteria":"cpe:2.3:o:opensuse:opensuse:11.2:*:*:*:*:*:*:*","matchCriteriaId":"A01C8B7E-EB19-40EA-B1D2-9AE5EA536C95"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:canonical:ubuntu_linux:8.04:*:*:*:-:*:*:*","matchCriteriaId":"7EBFE35C-E243-43D1-883D-4398D71763CC"},{"vulnerable":true,"criteria":"cpe:2.3:o:canonical:ubuntu_linux:8.10:*:*:*:*:*:*:*","matchCriteriaId":"4747CC68-FAF4-482F-929A-9DA6C24CB663"},{"vulnerable":true,"criteria":"cpe:2.3:o:canonical:ubuntu_linux:9.04:*:*:*:*:*:*:*","matchCriteriaId":"A5D026D0-EF78-438D-BEDD-FC8571F3ACEB"},{"vulnerable":true,"criteria":"cpe:2.3:o:canonical:ubuntu_linux:9.10:*:*:*:*:*:*:*","matchCriteriaId":"A2BCB73E-27BB-4878-AD9C-90C4F20C25A0"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2010","CveId":"840","Ordinal":"1","Title":"CVE-2010-0840","CVE":"CVE-2010-0840","Year":"2010"},"notes":[{"CveYear":"2010","CveId":"840","Ordinal":"1","NoteData":"Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, and 1.4.2_25 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.  NOTE: the previous information was obtained from the March 2010 CPU.  Oracle has not commented on claims from a reliable researcher that this is related to improper checks when executing privileged methods in the Java Runtime Environment (JRE), which allows attackers to execute arbitrary code via (1) an untrusted object that extends the trusted class but has not modified a certain method, or (2) \"a similar trust issue with interfaces,\" aka \"Trusted Methods Chaining Remote Code Execution Vulnerability.\"","Type":"Description","Title":"CVE-2010-0840"},{"CveYear":"2010","CveId":"840","Ordinal":"2","NoteData":"2010-04-01","Type":"Other","Title":"Published"},{"CveYear":"2010","CveId":"840","Ordinal":"3","NoteData":"2018-10-10","Type":"Other","Title":"Modified"}]}}}