Draft in the CWE catalog · 2 CVEs mapped
When a Java application uses the Java Native Interface (JNI) to call code written in another programming language, it can expose the application to weaknesses in that code, even if those weaknesses cannot occur in Java.
⚠️ A missing null check in Eclipse OpenJ9's JIT compiler could lead to unexpected behavior during execution! Don’t let this oversight slip through the cracks! Think of it like a restaurant kitchen that skips checking if a pot is empty before trying to serve from it. If that pot is indeed empty, chaos ensues when the dish is served, just like unexpected errors in your application when the null check is omitted. If an attacker exploits this oversight, it could lead to erratic application behavior or crashes. While the exact malicious outcomes are unclear given the severity is tagged as unknown, any instability can result in a less reliable user experience or data inconsistency, which is absolutely devastating in production environments!
A vulnerability in SIEMENS SIMATIC WinCC (All versions < SIMATIC WinCC V7.2) and SIEMENS SIMATIC PCS 7 (All versions < SIMATIC PCS 7 V8.0 SP1) could allow a remote attacker to crash an ActiveX component or leak parts of the application memory if a user is tricked into clicking on a malicious link under certain conditions.