CVE-2006-0617JDK vulnerability

5 documents4 sources
Severity
4.0MEDIUMNVD
EPSS
3.7%
top 12.00%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 9
Latest updateMay 1

Description

Multiple unspecified vulnerabilities in Sun Java JDK and JRE 5.0 Update 5 and earlier allow remote attackers to bypass Java sandbox security and obtain privileges via unspecified vectors involving the reflection APIs, aka the "fifth, sixth, and seventh issues."

CVSS vector

AV:N/AC:H/C:P/I:P/A:NExploitability: 4.9 | Impact: 4.9

Affected Packages2 packages

NVDsun/jdk1.5.0
NVDsun/jre1.5.0

Patches

🔴Vulnerability Details

2
GHSA
GHSA-5r52-222q-pvw6: Multiple unspecified vulnerabilities in Sun Java JDK and JRE 52022-05-01
CVEList
CVE-2006-0617: Multiple unspecified vulnerabilities in Sun Java JDK and JRE 52006-02-09

💬Community

2
Bugzilla
CVE-2006-3745 Local SCTP privilege escalation2006-08-10
Bugzilla
CVE-2004-2660 O_DIRECT write sometimes leaks memory2006-05-15
CVE-2006-0617 — SUN JDK vulnerability | cvebase