CVE-2004-2540
published 2004-12-31CVE-2004-2540: readObject in (1) Java Runtime Environment (JRE) and (2) Software Development Kit (SDK) 1.4.0 through 1.4.2_05 allows remote attackers to cause a denial of…
PriorityP416medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
2.49%
82.8th percentile
readObject in (1) Java Runtime Environment (JRE) and (2) Software Development Kit (SDK) 1.4.0 through 1.4.2_05 allows remote attackers to cause a denial of service (JVM unresponsive) via crafted serialized data.
Affected
96 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| sun | jdk | <= 1.5.0 | — |
| sun | jdk | — | — |
| sun | jdk | — | — |
| sun | jdk | — | — |
| sun | jdk | — | — |
| sun | jdk | — | — |
| sun | jdk | — | — |
| sun | jdk | — | — |
| sun | jdk | — | — |
| sun | jdk | — | — |
| sun | jdk | — | — |
| sun | jdk | — | — |
| sun | jdk | — | — |
| sun | jdk | — | — |
| sun | jdk | — | — |
| sun | jdk | — | — |
| sun | jdk | — | — |
| sun | jdk | — | — |
| sun | jdk | — | — |
| sun | jdk | — | — |
| sun | jdk | — | — |
| sun | jdk | — | — |
| sun | jdk | — | — |
| sun | jdk | — | — |
| sun | jdk | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
ghsa5.0MEDIUM
osv5.0MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
Spring Framework Remote Denial of Service vulnerability
vendor_redhat·2009-04-22·CVSS 5.0
CVE-2009-1190 [MEDIUM] Spring Framework Remote Denial of Service vulnerability
Spring Framework Remote Denial of Service vulnerability
Algorithmic complexity vulnerability in the java.util.regex.Pattern.compile method in Sun Java Development Kit (JDK) before 1.6, when used with spring.jar in SpringSource Spring Framework 1.1.0 through 2.5.6 and 3.0.0.M1 through 3.0.0.M2 and dm Server 1.0.0 through 1.0.2, allows remote attackers to cause a denial of service (CPU consumption) via serializable data with a long regex string containing multiple optional groups, a related issue to CVE-2004-2540.
Statement: This flaw affected JBoss Enterprise BRMS Platform 5.1.0 when run on Sun JDK 1.5.x. It was resolved in JBoss Enterprise BRMS Platform 5.2.0, both by updating spring and by dropping support for Sun JDK 1.5.x.
GHSA
Spring Framework Inefficient Regular Expression Complexity
ghsa·2022-05-02·CVSS 5.0
CVE-2009-1190 [MEDIUM] CWE-1333 Spring Framework Inefficient Regular Expression Complexity
Spring Framework Inefficient Regular Expression Complexity
Algorithmic complexity vulnerability in the java.util.regex.Pattern.compile method in Sun Java Development Kit (JDK) before 1.6, when used with spring.jar in SpringSource Spring Framework 1.1.0 through 2.5.6 and 3.0.0.M1 through 3.0.0.M2 and dm Server 1.0.0 through 1.0.2, allows remote attackers to cause a denial of service (CPU consumption) via serializable data with a long regex string containing multiple optional groups, a related issue to CVE-2004-2540.
OSV
Spring Framework Inefficient Regular Expression Complexity
osv·2022-05-02·CVSS 5.0
CVE-2009-1190 [MEDIUM] Spring Framework Inefficient Regular Expression Complexity
Spring Framework Inefficient Regular Expression Complexity
Algorithmic complexity vulnerability in the java.util.regex.Pattern.compile method in Sun Java Development Kit (JDK) before 1.6, when used with spring.jar in SpringSource Spring Framework 1.1.0 through 2.5.6 and 3.0.0.M1 through 3.0.0.M2 and dm Server 1.0.0 through 1.0.2, allows remote attackers to cause a denial of service (CPU consumption) via serializable data with a long regex string containing multiple optional groups, a related issue to CVE-2004-2540.
GHSA
GHSA-h2mv-7266-r4gv: readObject in (1) Java Runtime Environment (JRE) and (2) Software Development Kit (SDK) 1
ghsa_unreviewed·2022-04-29
CVE-2004-2540 [MEDIUM] GHSA-h2mv-7266-r4gv: readObject in (1) Java Runtime Environment (JRE) and (2) Software Development Kit (SDK) 1
readObject in (1) Java Runtime Environment (JRE) and (2) Software Development Kit (SDK) 1.4.0 through 1.4.2_05 allows remote attackers to cause a denial of service (JVM unresponsive) via crafted serialized data.
No detection rules found.
No public exploits indexed.
http://archives.neohapsis.com/archives/bugtraq/2005-04/0113.htmlhttp://secunia.com/advisories/13271/http://sunsolve.sun.com/searchproxy/document.do?assetkey=1-26-57707-1https://exchange.xforce.ibmcloud.com/vulnerabilities/20027http://archives.neohapsis.com/archives/bugtraq/2005-04/0113.htmlhttp://secunia.com/advisories/13271/http://sunsolve.sun.com/searchproxy/document.do?assetkey=1-26-57707-1https://exchange.xforce.ibmcloud.com/vulnerabilities/20027
2004-12-31
Published