CVE-2010-3565 - CVE House
Back to Database
Status published Critical CVE-2010-3565

Unspecified vulnerability in the 2D component in Oracle Java SE...

Vulnerability Description

Unspecified vulnerability in the 2D component in Oracle Java SE and Java for Business 6 Update 21, 5.0 Update 25, and 1.4.2_27 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the October 2010 CPU. Oracle has not commented on claims from a reliable researcher that this is an integer overflow that triggers memory corruption via large values in a subsample of a JPEG image, related to JPEGImageWriter.writeImage in the imageio API.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2010-3565

Credits & Attribution

No credits recorded in the NVD database.

References

Affected Vendor

Affected Software

jre, jdk, sdk
Vulnerable Versions:
0, 1.6.0, 1.5.0, 1.4.2, 1.4.2_1, 1.4.2_2, 1.4.2_3, 1.4.2_4, 1.4.2_5, 1.4.2_6, 1.4.2_7, 1.4.2_8, 1.4.2_9, 1.4.2_10, 1.4.2_11, 1.4.2_12, 1.4.2_13, 1.4.2_14, 1.4.2_15, 1.4.2_16, 1.4.2_17, 1.4.2_18, 1.4.2_19, 1.4.2_20, 1.4.2_21, 1.4.2_22, 1.4.2_23, 1.4.2_24, 1.4.2_25, 1.4.2_26, 1.4.2_02

Timeline

Official Publish: October 19th, 2010
Last Modified: August 7th, 2024
Added to House: July 19th, 2026

CVSS Vectors

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.