vendor:
Unknown
by:
Unknown
7.5
CVSS
HIGH
Use-after-free
416
CWE
Product Name: Unknown
Affected Version From: Unknown
Affected Version To: Unknown
Patch Exists: NO
Related CWE: Unknown
CPE: Unknown
Platforms Tested: Unknown
Unknown
Use-after-free in URLStream.readObject
There is a use-after-free vulnerability in URLStream.readObject. If the object read is a registered class, the constructor will be invoked to create the object. If the constructor calls URLStream.close, the URLStream will be freed, and the deserialization function will continue to write to it.
Mitigation:
Unknown