Sun JRE 5.0 before update 14 allows remote attackers to cause a denial of service (Internet Explorer crash) via an object tag with an encoded applet and an undefined name attribute, which triggers a NULL pointer dereference in jpiexp32.dll when the applet is decoded and passed to the JVM.
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Link | Tags |
---|---|
http://www.securityfocus.com/archive/1/485942/100/0/threaded | mailing list |
https://exchange.xforce.ibmcloud.com/vulnerabilities/39549 | vdb entry |
http://www.securityfocus.com/bid/27185 | vdb entry |
http://securityreason.com/securityalert/3527 | third party advisory |