{"api_version":"1","generated_at":"2026-07-23T08:47:39+00:00","cve":"CVE-2010-0843","urls":{"html":"https://cve.report/CVE-2010-0843","api":"https://cve.report/api/cve/CVE-2010-0843.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2010-0843","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2010-0843"},"summary":{"title":"CVE-2010-0843","description":"Unspecified vulnerability in the Sound component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, 1.4.2_25, and 1.3.1_27 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.  NOTE: the previous information was obtained from the March 2010 CPU.  Oracle has not commented on claims from a reliable researcher that this is related to XNewPtr and improper handling of an integer parameter when allocating heap memory in the com.sun.media.sound libraries, which allows remote attackers to execute arbitrary code.","state":"PUBLISHED","assigner":"oracle","published_at":"2010-04-01 16:30:00","updated_at":"2026-04-29 01:13:23"},"problem_types":["NVD-CWE-noinfo","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://www.securityfocus.com/archive/1/516397/100/0/threaded","name":"http://www.securityfocus.com/archive/1/516397/100/0/threaded","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2010/1191","name":"http://www.vupen.com/english/advisories/2010/1191","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://osvdb.org/63492","name":"http://osvdb.org/63492","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://www.vupen.com/english/advisories/2010/1454","name":"http://www.vupen.com/english/advisories/2010/1454","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://support.apple.com/kb/HT4170","name":"http://support.apple.com/kb/HT4170","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"About the security content of Java for Mac OS X 10.5 Update 7","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://seclists.org/bugtraq/2010/Apr/41","name":"http://seclists.org/bugtraq/2010/Apr/41","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Bugtraq: ZDI-10-052: Sun Java Runtime Environment XNewPtr Remote Code Execution Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/39083","name":"http://www.securityfocus.com/bid/39083","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Oracle Java SE and Java for Business 'XNewPtr()' Remote Code Execution Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.html","name":"http://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"VMware vCenter Server 4.1 Update 1 Release Notes","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.oracle.com/technetwork/topics/security/cpuoct2010-175626.html","name":"http://www.oracle.com/technetwork/topics/security/cpuoct2010-175626.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Oracle Critical Patch Update Pre-Release Announcement - October 2010","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/39317","name":"http://secunia.com/advisories/39317","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"SUSE Update for Multiple Packages - Advisories - Community","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.zerodayinitiative.com/advisories/ZDI-10-052/","name":"http://www.zerodayinitiative.com/advisories/ZDI-10-052/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Zero Day Initiative","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14092","name":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14092","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Repository  /  Oval Repository","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/39819","name":"http://secunia.com/advisories/39819","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Apple Mac OS X update for Java - Advisories - Community","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://marc.info/?l=bugtraq&m=127557596201693&w=2","name":"http://marc.info/?l=bugtraq&m=127557596201693&w=2","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"'[security bulletin] HPSBUX02524 SSRT100089 rev.1 - HP-UX Running Java, Remote Execution of Arbitrary' - MARC","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vmware.com/security/advisories/VMSA-2011-0003.html","name":"http://www.vmware.com/security/advisories/VMSA-2011-0003.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"VMSA-2011-0003","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.apple.com/archives/security-announce/2010//May/msg00001.html","name":"http://lists.apple.com/archives/security-announce/2010//May/msg00001.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"APPLE-SA-2010-05-18-1 Java for Mac OS X 10.6 Update 2","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/40211","name":"http://secunia.com/advisories/40211","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Red Hat update for java-1.5.0-ibm - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/39659","name":"http://secunia.com/advisories/39659","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Red Hat update for java-1.6.0-ibm - Advisories - Community","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2010/1793","name":"http://www.vupen.com/english/advisories/2010/1793","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.redhat.com/support/errata/RHSA-2010-0489.html","name":"http://www.redhat.com/support/errata/RHSA-2010-0489.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Support | Red Hat","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://marc.info/?l=bugtraq&m=134254866602253&w=2","name":"http://marc.info/?l=bugtraq&m=134254866602253&w=2","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"'[security bulletin] HPSBMU02799 SSRT100867 rev.1 - HP Network Node Manager i (NNMi) v9.0x Running JD' - MARC","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/43308","name":"http://secunia.com/advisories/43308","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"VMware vCenter / ESX Server Update for Oracle (Sun) JRE - Advisories - Community","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.redhat.com/support/errata/RHSA-2010-0383.html","name":"http://www.redhat.com/support/errata/RHSA-2010-0383.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"rhn.redhat.com | Red Hat Support","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.oracle.com/technetwork/topics/security/javacpumar2010-083341.html","name":"http://www.oracle.com/technetwork/topics/security/javacpumar2010-083341.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Oracle Java SE and Java for Business Critical Patch Update Advisory - March 2010","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://support.apple.com/kb/HT4171","name":"http://support.apple.com/kb/HT4171","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"About the security content of Java for Mac OS X 10.6 Update 2","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.redhat.com/support/errata/RHSA-2010-0338.html","name":"http://www.redhat.com/support/errata/RHSA-2010-0338.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Support","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2010-04/msg00001.html","name":"http://lists.opensuse.org/opensuse-security-announce/2010-04/msg00001.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"[security-announce] SUSE Security Summary Report: SUSE-SR:2010:008","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2010/1523","name":"http://www.vupen.com/english/advisories/2010/1523","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/40545","name":"http://secunia.com/advisories/40545","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"HP Systems Insight Manager Multiple Vulnerabilities - Advisories - Community","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2010-09/msg00006.html","name":"http://lists.opensuse.org/opensuse-security-announce/2010-09/msg00006.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"[security-announce] SUSE Security Summary Report: SUSE-SR:2010:017","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.redhat.com/support/errata/RHSA-2010-0471.html","name":"http://www.redhat.com/support/errata/RHSA-2010-0471.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"rhn.redhat.com | Red Hat Support","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.redhat.com/support/errata/RHSA-2010-0337.html","name":"http://www.redhat.com/support/errata/RHSA-2010-0337.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Support","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02273751","name":"http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02273751","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"404"},{"url":"http://lists.apple.com/archives/security-announce/2010//May/msg00002.html","name":"http://lists.apple.com/archives/security-announce/2010//May/msg00002.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"APPLE-SA-2010-05-18-2 Java for Mac OS X 10.5 Update 7","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2010-0843","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2010-0843","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2010","cve_id":"843","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"sun","cpe5":"jdk","cpe6":"1.5.0","cpe7":"update23","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2010","cve_id":"843","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"sun","cpe5":"jdk","cpe6":"1.6.0","cpe7":"update_18","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2010","cve_id":"843","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"sun","cpe5":"jre","cpe6":"1.3.1_27","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2010","cve_id":"843","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"sun","cpe5":"jre","cpe6":"1.4.2_25","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2010","cve_id":"843","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"sun","cpe5":"jre","cpe6":"1.5.0","cpe7":"update23","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2010","cve_id":"843","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"sun","cpe5":"jre","cpe6":"1.6.0","cpe7":"update_18","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2010","cve_id":"843","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"sun","cpe5":"sdk","cpe6":"1.3.1_27","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2010","cve_id":"843","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"sun","cpe5":"sdk","cpe6":"1.4.2_25","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T00:59:39.359Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"APPLE-SA-2010-05-18-1","tags":["vendor-advisory","x_refsource_APPLE","x_transferred"],"url":"http://lists.apple.com/archives/security-announce/2010//May/msg00001.html"},{"name":"HPSBMU02799","tags":["vendor-advisory","x_refsource_HP","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=134254866602253&w=2"},{"name":"39317","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/39317"},{"name":"RHSA-2010:0383","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://www.redhat.com/support/errata/RHSA-2010-0383.html"},{"name":"40545","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/40545"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.zerodayinitiative.com/advisories/ZDI-10-052/"},{"name":"ADV-2010-1454","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2010/1454"},{"name":"39819","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/39819"},{"name":"39083","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/39083"},{"name":"RHSA-2010:0338","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://www.redhat.com/support/errata/RHSA-2010-0338.html"},{"name":"ADV-2010-1793","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2010/1793"},{"name":"APPLE-SA-2010-05-18-2","tags":["vendor-advisory","x_refsource_APPLE","x_transferred"],"url":"http://lists.apple.com/archives/security-announce/2010//May/msg00002.html"},{"name":"63492","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://osvdb.org/63492"},{"name":"43308","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/43308"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.oracle.com/technetwork/topics/security/cpuoct2010-175626.html"},{"name":"SSRT100179","tags":["vendor-advisory","x_refsource_HP","x_transferred"],"url":"http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02273751"},{"name":"SSRT100089","tags":["vendor-advisory","x_refsource_HP","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=127557596201693&w=2"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.oracle.com/technetwork/topics/security/javacpumar2010-083341.html"},{"name":"HPSBUX02524","tags":["vendor-advisory","x_refsource_HP","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=127557596201693&w=2"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://support.apple.com/kb/HT4170"},{"name":"ADV-2010-1523","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2010/1523"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.html"},{"name":"SUSE-SR:2010:008","tags":["vendor-advisory","x_refsource_SUSE","x_transferred"],"url":"http://lists.opensuse.org/opensuse-security-announce/2010-04/msg00001.html"},{"name":"39659","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/39659"},{"name":"oval:org.mitre.oval:def:14092","tags":["vdb-entry","signature","x_refsource_OVAL","x_transferred"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14092"},{"name":"RHSA-2010:0471","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://www.redhat.com/support/errata/RHSA-2010-0471.html"},{"name":"SUSE-SR:2010:017","tags":["vendor-advisory","x_refsource_SUSE","x_transferred"],"url":"http://lists.opensuse.org/opensuse-security-announce/2010-09/msg00006.html"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.vmware.com/security/advisories/VMSA-2011-0003.html"},{"name":"RHSA-2010:0337","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://www.redhat.com/support/errata/RHSA-2010-0337.html"},{"name":"RHSA-2010:0489","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://www.redhat.com/support/errata/RHSA-2010-0489.html"},{"name":"HPSBMA02547","tags":["vendor-advisory","x_refsource_HP","x_transferred"],"url":"http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02273751"},{"name":"40211","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/40211"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://support.apple.com/kb/HT4171"},{"name":"20100405 ZDI-10-052: Sun Java Runtime Environment XNewPtr Remote Code Execution Vulnerability","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://seclists.org/bugtraq/2010/Apr/41"},{"name":"20110211 VMSA-2011-0003 Third party component updates for VMware vCenter Server, vCenter Update Manager, ESXi and ESX","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.securityfocus.com/archive/1/516397/100/0/threaded"},{"name":"ADV-2010-1191","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2010/1191"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2010-03-30T00:00:00.000Z","descriptions":[{"lang":"en","value":"Unspecified vulnerability in the Sound component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, 1.4.2_25, and 1.3.1_27 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.  NOTE: the previous information was obtained from the March 2010 CPU.  Oracle has not commented on claims from a reliable researcher that this is related to XNewPtr and improper handling of an integer parameter when allocating heap memory in the com.sun.media.sound libraries, which allows remote attackers to execute arbitrary code."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2018-10-10T18:57:01.000Z","orgId":"43595867-4340-4103-b7a2-9a5208d29a85","shortName":"oracle"},"references":[{"name":"APPLE-SA-2010-05-18-1","tags":["vendor-advisory","x_refsource_APPLE"],"url":"http://lists.apple.com/archives/security-announce/2010//May/msg00001.html"},{"name":"HPSBMU02799","tags":["vendor-advisory","x_refsource_HP"],"url":"http://marc.info/?l=bugtraq&m=134254866602253&w=2"},{"name":"39317","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/39317"},{"name":"RHSA-2010:0383","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://www.redhat.com/support/errata/RHSA-2010-0383.html"},{"name":"40545","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/40545"},{"tags":["x_refsource_MISC"],"url":"http://www.zerodayinitiative.com/advisories/ZDI-10-052/"},{"name":"ADV-2010-1454","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2010/1454"},{"name":"39819","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/39819"},{"name":"39083","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/39083"},{"name":"RHSA-2010:0338","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://www.redhat.com/support/errata/RHSA-2010-0338.html"},{"name":"ADV-2010-1793","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2010/1793"},{"name":"APPLE-SA-2010-05-18-2","tags":["vendor-advisory","x_refsource_APPLE"],"url":"http://lists.apple.com/archives/security-announce/2010//May/msg00002.html"},{"name":"63492","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://osvdb.org/63492"},{"name":"43308","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/43308"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.oracle.com/technetwork/topics/security/cpuoct2010-175626.html"},{"name":"SSRT100179","tags":["vendor-advisory","x_refsource_HP"],"url":"http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02273751"},{"name":"SSRT100089","tags":["vendor-advisory","x_refsource_HP"],"url":"http://marc.info/?l=bugtraq&m=127557596201693&w=2"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.oracle.com/technetwork/topics/security/javacpumar2010-083341.html"},{"name":"HPSBUX02524","tags":["vendor-advisory","x_refsource_HP"],"url":"http://marc.info/?l=bugtraq&m=127557596201693&w=2"},{"tags":["x_refsource_CONFIRM"],"url":"http://support.apple.com/kb/HT4170"},{"name":"ADV-2010-1523","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2010/1523"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.html"},{"name":"SUSE-SR:2010:008","tags":["vendor-advisory","x_refsource_SUSE"],"url":"http://lists.opensuse.org/opensuse-security-announce/2010-04/msg00001.html"},{"name":"39659","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/39659"},{"name":"oval:org.mitre.oval:def:14092","tags":["vdb-entry","signature","x_refsource_OVAL"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14092"},{"name":"RHSA-2010:0471","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://www.redhat.com/support/errata/RHSA-2010-0471.html"},{"name":"SUSE-SR:2010:017","tags":["vendor-advisory","x_refsource_SUSE"],"url":"http://lists.opensuse.org/opensuse-security-announce/2010-09/msg00006.html"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.vmware.com/security/advisories/VMSA-2011-0003.html"},{"name":"RHSA-2010:0337","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://www.redhat.com/support/errata/RHSA-2010-0337.html"},{"name":"RHSA-2010:0489","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://www.redhat.com/support/errata/RHSA-2010-0489.html"},{"name":"HPSBMA02547","tags":["vendor-advisory","x_refsource_HP"],"url":"http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02273751"},{"name":"40211","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/40211"},{"tags":["x_refsource_CONFIRM"],"url":"http://support.apple.com/kb/HT4171"},{"name":"20100405 ZDI-10-052: Sun Java Runtime Environment XNewPtr Remote Code Execution Vulnerability","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://seclists.org/bugtraq/2010/Apr/41"},{"name":"20110211 VMSA-2011-0003 Third party component updates for VMware vCenter Server, vCenter Update Manager, ESXi and ESX","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.securityfocus.com/archive/1/516397/100/0/threaded"},{"name":"ADV-2010-1191","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2010/1191"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"secalert_us@oracle.com","ID":"CVE-2010-0843","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Unspecified vulnerability in the Sound component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, 1.4.2_25, and 1.3.1_27 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.  NOTE: the previous information was obtained from the March 2010 CPU.  Oracle has not commented on claims from a reliable researcher that this is related to XNewPtr and improper handling of an integer parameter when allocating heap memory in the com.sun.media.sound libraries, which allows remote attackers to execute arbitrary code."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"APPLE-SA-2010-05-18-1","refsource":"APPLE","url":"http://lists.apple.com/archives/security-announce/2010//May/msg00001.html"},{"name":"HPSBMU02799","refsource":"HP","url":"http://marc.info/?l=bugtraq&m=134254866602253&w=2"},{"name":"39317","refsource":"SECUNIA","url":"http://secunia.com/advisories/39317"},{"name":"RHSA-2010:0383","refsource":"REDHAT","url":"http://www.redhat.com/support/errata/RHSA-2010-0383.html"},{"name":"40545","refsource":"SECUNIA","url":"http://secunia.com/advisories/40545"},{"name":"http://www.zerodayinitiative.com/advisories/ZDI-10-052/","refsource":"MISC","url":"http://www.zerodayinitiative.com/advisories/ZDI-10-052/"},{"name":"ADV-2010-1454","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2010/1454"},{"name":"39819","refsource":"SECUNIA","url":"http://secunia.com/advisories/39819"},{"name":"39083","refsource":"BID","url":"http://www.securityfocus.com/bid/39083"},{"name":"RHSA-2010:0338","refsource":"REDHAT","url":"http://www.redhat.com/support/errata/RHSA-2010-0338.html"},{"name":"ADV-2010-1793","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2010/1793"},{"name":"APPLE-SA-2010-05-18-2","refsource":"APPLE","url":"http://lists.apple.com/archives/security-announce/2010//May/msg00002.html"},{"name":"63492","refsource":"OSVDB","url":"http://osvdb.org/63492"},{"name":"43308","refsource":"SECUNIA","url":"http://secunia.com/advisories/43308"},{"name":"http://www.oracle.com/technetwork/topics/security/cpuoct2010-175626.html","refsource":"CONFIRM","url":"http://www.oracle.com/technetwork/topics/security/cpuoct2010-175626.html"},{"name":"SSRT100179","refsource":"HP","url":"http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02273751"},{"name":"SSRT100089","refsource":"HP","url":"http://marc.info/?l=bugtraq&m=127557596201693&w=2"},{"name":"http://www.oracle.com/technetwork/topics/security/javacpumar2010-083341.html","refsource":"CONFIRM","url":"http://www.oracle.com/technetwork/topics/security/javacpumar2010-083341.html"},{"name":"HPSBUX02524","refsource":"HP","url":"http://marc.info/?l=bugtraq&m=127557596201693&w=2"},{"name":"http://support.apple.com/kb/HT4170","refsource":"CONFIRM","url":"http://support.apple.com/kb/HT4170"},{"name":"ADV-2010-1523","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2010/1523"},{"name":"http://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.html","refsource":"CONFIRM","url":"http://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.html"},{"name":"SUSE-SR:2010:008","refsource":"SUSE","url":"http://lists.opensuse.org/opensuse-security-announce/2010-04/msg00001.html"},{"name":"39659","refsource":"SECUNIA","url":"http://secunia.com/advisories/39659"},{"name":"oval:org.mitre.oval:def:14092","refsource":"OVAL","url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14092"},{"name":"RHSA-2010:0471","refsource":"REDHAT","url":"http://www.redhat.com/support/errata/RHSA-2010-0471.html"},{"name":"SUSE-SR:2010:017","refsource":"SUSE","url":"http://lists.opensuse.org/opensuse-security-announce/2010-09/msg00006.html"},{"name":"http://www.vmware.com/security/advisories/VMSA-2011-0003.html","refsource":"CONFIRM","url":"http://www.vmware.com/security/advisories/VMSA-2011-0003.html"},{"name":"RHSA-2010:0337","refsource":"REDHAT","url":"http://www.redhat.com/support/errata/RHSA-2010-0337.html"},{"name":"RHSA-2010:0489","refsource":"REDHAT","url":"http://www.redhat.com/support/errata/RHSA-2010-0489.html"},{"name":"HPSBMA02547","refsource":"HP","url":"http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02273751"},{"name":"40211","refsource":"SECUNIA","url":"http://secunia.com/advisories/40211"},{"name":"http://support.apple.com/kb/HT4171","refsource":"CONFIRM","url":"http://support.apple.com/kb/HT4171"},{"name":"20100405 ZDI-10-052: Sun Java Runtime Environment XNewPtr Remote Code Execution Vulnerability","refsource":"BUGTRAQ","url":"http://seclists.org/bugtraq/2010/Apr/41"},{"name":"20110211 VMSA-2011-0003 Third party component updates for VMware vCenter Server, vCenter Update Manager, ESXi and ESX","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/516397/100/0/threaded"},{"name":"ADV-2010-1191","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2010/1191"}]}}}},"cveMetadata":{"assignerOrgId":"43595867-4340-4103-b7a2-9a5208d29a85","assignerShortName":"oracle","cveId":"CVE-2010-0843","datePublished":"2010-04-01T16:00:00.000Z","dateReserved":"2010-03-03T00:00:00.000Z","dateUpdated":"2024-08-07T00:59:39.359Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2010-04-01 16:30:00","lastModifiedDate":"2026-04-29 01:13:23","problem_types":["NVD-CWE-noinfo","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:sun:jdk:1.5.0:update23:*:*:*:*:*:*","matchCriteriaId":"EB3A0C49-3FF9-4CB7-9E01-F771D4925103"},{"vulnerable":true,"criteria":"cpe:2.3:a:sun:jdk:1.6.0:update_18:*:*:*:*:*:*","matchCriteriaId":"C367B418-659E-4627-B1F1-1B1216C99055"},{"vulnerable":true,"criteria":"cpe:2.3:a:sun:jre:1.3.1_27:*:*:*:*:*:*:*","matchCriteriaId":"D671CFAE-B8C5-449E-9F08-189657A18B26"},{"vulnerable":true,"criteria":"cpe:2.3:a:sun:jre:1.4.2_25:*:*:*:*:*:*:*","matchCriteriaId":"076444F1-543E-4061-9D39-415A1A889F5E"},{"vulnerable":true,"criteria":"cpe:2.3:a:sun:jre:1.5.0:update23:*:*:*:*:*:*","matchCriteriaId":"DE949EBF-2BC0-4355-8B28-B494023D45FE"},{"vulnerable":true,"criteria":"cpe:2.3:a:sun:jre:1.6.0:update_18:*:*:*:*:*:*","matchCriteriaId":"C4FDE9EB-08FE-436E-A265-30E83B15DB23"},{"vulnerable":true,"criteria":"cpe:2.3:a:sun:sdk:1.3.1_27:*:*:*:*:*:*:*","matchCriteriaId":"DA78C21D-2669-4107-A07B-0AA2C7B1EC16"},{"vulnerable":true,"criteria":"cpe:2.3:a:sun:sdk:1.4.2_25:*:*:*:*:*:*:*","matchCriteriaId":"E79C04F7-E3A1-4DF5-94E9-E96A6FC61FC9"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2010","CveId":"843","Ordinal":"1","Title":"CVE-2010-0843","CVE":"CVE-2010-0843","Year":"2010"},"notes":[{"CveYear":"2010","CveId":"843","Ordinal":"1","NoteData":"Unspecified vulnerability in the Sound component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, 1.4.2_25, and 1.3.1_27 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.  NOTE: the previous information was obtained from the March 2010 CPU.  Oracle has not commented on claims from a reliable researcher that this is related to XNewPtr and improper handling of an integer parameter when allocating heap memory in the com.sun.media.sound libraries, which allows remote attackers to execute arbitrary code.","Type":"Description","Title":"CVE-2010-0843"},{"CveYear":"2010","CveId":"843","Ordinal":"2","NoteData":"2010-04-01","Type":"Other","Title":"Published"},{"CveYear":"2010","CveId":"843","Ordinal":"3","NoteData":"2018-10-10","Type":"Other","Title":"Modified"}]}}}