Oracle Java SE and Java for Business CVE-2010-3552 Remote New Java Plug-in Vulnerability

BID:44023

Info

Oracle Java SE and Java for Business CVE-2010-3552 Remote New Java Plug-in Vulnerability

Bugtraq ID: 44023
Class: Boundary Condition Error
CVE: CVE-2010-3552
Remote: Yes
Local: No
Published: Oct 12 2010 12:00AM
Updated: Jan 27 2014 01:04AM
Credit: Stephen Fewer of Harmony Security
Vulnerable: VMWare vCenter 4.1 Update 1
VMWare vCenter 4.1
VMWare ESX 4.1 Update 1
VMWare ESX 4.1
SuSE SUSE Linux Enterprise 11 SP1
SuSE SUSE Linux Enterprise 11
SuSE openSUSE 11.3
Sun JRE (Windows Production Release) 1.6 _17
Sun JRE (Windows Production Release) 1.6 _13
Sun JRE (Windows Production Release) 1.6 _12
Sun JRE (Windows Production Release) 1.6 _10
Sun JRE (Windows Production Release) 1.6 _07
Sun JRE (Windows Production Release) 1.6 _06
Sun JRE (Windows Production Release) 1.6 _05
Sun JRE (Windows Production Release) 1.6 _04
Sun JRE (Windows Production Release) 1.6
Sun JRE (Windows Production Release) 1.6.0_21
Sun JRE (Windows Production Release) 1.6.0_20
Sun JRE (Windows Production Release) 1.6.0_2
Sun JRE (Windows Production Release) 1.6.0_19
Sun JRE (Windows Production Release) 1.6.0_18
Sun JRE (Windows Production Release) 1.6.0_15
Sun JRE (Windows Production Release) 1.6.0_14
Sun JRE (Windows Production Release) 1.6.0_11
Sun JRE (Windows Production Release) 1.6.0_03
Sun JRE (Windows Production Release) 1.6.0_02
Sun JRE (Windows Production Release) 1.6.0_01
Sun JRE (Solaris Production Release) 1.6 _17
Sun JRE (Solaris Production Release) 1.6 _13
Sun JRE (Solaris Production Release) 1.6 _12
Sun JRE (Solaris Production Release) 1.6 _10
Sun JRE (Solaris Production Release) 1.6 _07
Sun JRE (Solaris Production Release) 1.6 _06
Sun JRE (Solaris Production Release) 1.6 _05
Sun JRE (Solaris Production Release) 1.6 _04
Sun JRE (Solaris Production Release) 1.6
Sun JRE (Solaris Production Release) 1.6.0_21
Sun JRE (Solaris Production Release) 1.6.0_2
Sun JRE (Solaris Production Release) 1.6.0_19
Sun JRE (Solaris Production Release) 1.6.0_18
Sun JRE (Solaris Production Release) 1.6.0_15
Sun JRE (Solaris Production Release) 1.6.0_14
Sun JRE (Solaris Production Release) 1.6.0_11
Sun JRE (Solaris Production Release) 1.6.0_03
Sun JRE (Solaris Production Release) 1.6.0_02
Sun JRE (Solaris Production Release) 1.6.0_01
Sun JRE (Linux Production Release) 1.6 _17
Sun JRE (Linux Production Release) 1.6 _13
Sun JRE (Linux Production Release) 1.6 _12
Sun JRE (Linux Production Release) 1.6 _10
Sun JRE (Linux Production Release) 1.6 _07
Sun JRE (Linux Production Release) 1.6 _06
Sun JRE (Linux Production Release) 1.6 _05
Sun JRE (Linux Production Release) 1.6 _04
Sun JRE (Linux Production Release) 1.6
Sun JRE (Linux Production Release) 1.6.0_21
Sun JRE (Linux Production Release) 1.6.0_20
Sun JRE (Linux Production Release) 1.6.0_19
Sun JRE (Linux Production Release) 1.6.0_18
Sun JRE (Linux Production Release) 1.6.0_15
Sun JRE (Linux Production Release) 1.6.0_14
Sun JRE (Linux Production Release) 1.6.0_11
Sun JRE (Linux Production Release) 1.6.0_03
Sun JRE (Linux Production Release) 1.6.0_02
Sun JRE (Linux Production Release) 1.6.0_01
Sun JDK (Windows Production Release) 1.6 _17
Sun JDK (Windows Production Release) 1.6 _14
Sun JDK (Windows Production Release) 1.6 _13
Sun JDK (Windows Production Release) 1.6 _11
Sun JDK (Windows Production Release) 1.6 _10
Sun JDK (Windows Production Release) 1.6 _07
Sun JDK (Windows Production Release) 1.6 _06
Sun JDK (Windows Production Release) 1.6 _05
Sun JDK (Windows Production Release) 1.6 _04
Sun JDK (Windows Production Release) 1.6
Sun JDK (Windows Production Release) 1.6.0_21
Sun JDK (Windows Production Release) 1.6.0_20
Sun JDK (Windows Production Release) 1.6.0_19
Sun JDK (Windows Production Release) 1.6.0_18
Sun JDK (Windows Production Release) 1.6.0_15
Sun JDK (Windows Production Release) 1.6.0_03
Sun JDK (Windows Production Release) 1.6.0_02
Sun JDK (Windows Production Release) 1.6.0_01-b06
Sun JDK (Windows Production Release) 1.6.0_01
Sun JDK (Solaris Production Release) 1.6 _17
Sun JDK (Solaris Production Release) 1.6 _14
Sun JDK (Solaris Production Release) 1.6 _13
Sun JDK (Solaris Production Release) 1.6 _11
Sun JDK (Solaris Production Release) 1.6 _10
Sun JDK (Solaris Production Release) 1.6 _07
Sun JDK (Solaris Production Release) 1.6 _06
Sun JDK (Solaris Production Release) 1.6 _05
Sun JDK (Solaris Production Release) 1.6 _04
Sun JDK (Solaris Production Release) 1.6 _01-b06
Sun JDK (Solaris Production Release) 1.6
Sun JDK (Solaris Production Release) 1.6.0_21
Sun JDK (Solaris Production Release) 1.6.0_20
Sun JDK (Solaris Production Release) 1.6.0_19
Sun JDK (Solaris Production Release) 1.6.0_18
Sun JDK (Solaris Production Release) 1.6.0_15
Sun JDK (Solaris Production Release) 1.6.0_03
Sun JDK (Solaris Production Release) 1.6.0_02
Sun JDK (Solaris Production Release) 1.6.0_01
Sun JDK (Linux Production Release) 1.6 _17
Sun JDK (Linux Production Release) 1.6 _14
Sun JDK (Linux Production Release) 1.6 _13
Sun JDK (Linux Production Release) 1.6 _11
Sun JDK (Linux Production Release) 1.6 _10
Sun JDK (Linux Production Release) 1.6 _07
Sun JDK (Linux Production Release) 1.6 _06
Sun JDK (Linux Production Release) 1.6 _05
Sun JDK (Linux Production Release) 1.6 _04
Sun JDK (Linux Production Release) 1.6 _01-b06
Sun JDK (Linux Production Release) 1.6 _01
Sun JDK (Linux Production Release) 1.6
Sun JDK (Linux Production Release) 1.6.0_21
Sun JDK (Linux Production Release) 1.6.0_20
Sun JDK (Linux Production Release) 1.6.0_19
Sun JDK (Linux Production Release) 1.6.0_18
Sun JDK (Linux Production Release) 1.6.0_15
Sun JDK (Linux Production Release) 1.6.0_03
Sun JDK (Linux Production Release) 1.6.0_02
S.u.S.E. openSUSE 11.2
S.u.S.E. openSUSE 11.1
RedHat Enterprise Linux Extras 4.8.z
RedHat Enterprise Linux Extras 4
Red Hat Enterprise Linux Supplementary 5 server
Red Hat Enterprise Linux Desktop Supplementary 5 client
HP HP-UX B.11.31
HP HP-UX B.11.31
HP HP-UX B.11.23
HP HP-UX B.11.23
HP HP-UX B.11.11
HP HP-UX B.11.11
Gentoo Linux
Avaya Proactive Contact 3.0.3
Avaya Proactive Contact 3.0.2
Avaya Proactive Contact 3.0
Avaya Aura Conferencing 6.0 Standard
Not Vulnerable: VMWare vCenter 4.1 Update 2
Sun SDK (Windows Production Release) 1.4.2_28
Sun SDK (Solaris Production Release) 1.4.2_28
Sun SDK (Linux Production Release) 1.4.2_28
Sun JRE (Windows Production Release) 1.4.2 _28
Sun JRE (Windows Production Release) 1.6.0_22
Sun JRE (Windows Production Release) 1.5.0_26
Sun JRE (Solaris Production Release) 1.6.0_22
Sun JRE (Solaris Production Release) 1.5.0_26
Sun JRE (Solaris Production Release) 1.4.2_28
Sun JRE (Linux Production Release) 1.6.0_22
Sun JRE (Linux Production Release) 1.5.0_26
Sun JRE (Linux Production Release) 1.4.2_28
Sun JDK (Windows Production Release) 1.6.0_22
Sun JDK (Windows Production Release) 1.5.0_26
Sun JDK (Solaris Production Release) 1.6.0_22
Sun JDK (Solaris Production Release) 1.5.0_26
Sun JDK (Linux Production Release) 1.6.0_22
Sun JDK (Linux Production Release) 1.5.0_26

Discussion

Oracle Java SE and Java for Business CVE-2010-3552 Remote New Java Plug-in Vulnerability

Oracle Java SE and Java for Business are prone to a remote vulnerability in the Java plug-in for Internet Explorer.

An attacker can exploit this vulnerability by using a malicious webpage. Due to a buffer overflow, it is possible for an attacker to execute arbitrary code in the context of the currently logged-in user.

This vulnerability affects version 6 Update 21.

Exploit / POC

Oracle Java SE and Java for Business CVE-2010-3552 Remote New Java Plug-in Vulnerability

The issue is being actively exploited in the wild.

The following exploit code is available:

Solution / Fix

Oracle Java SE and Java for Business CVE-2010-3552 Remote New Java Plug-in Vulnerability

Solution:
Vendor updates are available. Please contact the vendor for more information.

References

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report