CVE-2006-4302

CWE-2643 documents3 sources
Severity
5.0MEDIUM
EPSS
1.5%
top 18.98%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 23
Latest updateMay 1

Description

The Java Plug-in J2SE 1.3.0_02 through 5.0 Update 5, and Java Web Start 1.0 through 1.2 and J2SE 1.4.2 through 5.0 Update 5, allows remote attackers to exploit vulnerabilities by specifying a JRE version that contain vulnerabilities.

CVSS vector

AV:N/AC:L/C:N/I:P/A:NExploitability: 10.0 | Impact: 2.9

Affected Packages2 packages

NVDsun/java_web_start5 versions+4
NVDsun/j2se5 versions+4

Patches

🔴Vulnerability Details

2
GHSA
GHSA-wpv3-f8fm-837r: The Java Plug-in J2SE 12022-05-01
CVEList
CVE-2006-4302: The Java Plug-in J2SE 12006-08-23