Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The Aqua Look and Feel for Java implementation in Java 1.5 on Mac OS X 10.5 allows remote attackers to execute arbitrary code via a call to the undocumented apple.laf.CColourUIResource constructor with a crafted value in the first argument, which is dereferenced as a pointer.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Sun Java运行时环境Aqua Look and Feel界面包权限提升漏洞
Vulnerability Description
Solaris系统的Java运行时环境(JRE)为JAVA应用程序提供可靠的运行环境。 Java实现的Aqua Look and Feel界面包中没有正确地验证对apple.laf.CColourUIResource(long, int, int ,int, int)构建器所传送的参数,如果向第一个参数传送了超长的整数值,该值会被解释为到Objective-C对象的指针。通过创建特殊的内存结构并向第一个参数传送指针,攻击者就可以执行任意代码 。
CVSS Information
N/A
Vulnerability Type
N/A