CVE-2008-0657
published 2008-02-07CVE-2008-0657: Multiple unspecified vulnerabilities in the Java Runtime Environment in Sun JDK and JRE 6 Update 1 and earlier, and 5.0 Update 13 and earlier, allow…
PriorityP342critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
2.84%
85.0th percentile
Multiple unspecified vulnerabilities in the Java Runtime Environment in Sun JDK and JRE 6 Update 1 and earlier, and 5.0 Update 13 and earlier, allow context-dependent attackers to gain privileges via an untrusted (1) application or (2) applet, as demonstrated by an application or applet that grants itself privileges to (a) read local files, (b) write to local files, or (c) execute local programs.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| sun | jdk | <= 5.0_update13 | — |
| sun | jre | <= 1.5.0 | — |
| sun | jre | <= 1.6.0 | — |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vendor_redhat10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-2jgq-w4vv-qrcg: Multiple unspecified vulnerabilities in the Java Runtime Environment in Sun JDK and JRE 6 Update 1 and earlier, and 5
ghsa_unreviewed·2022-05-01
CVE-2008-0657 [HIGH] GHSA-2jgq-w4vv-qrcg: Multiple unspecified vulnerabilities in the Java Runtime Environment in Sun JDK and JRE 6 Update 1 and earlier, and 5
Multiple unspecified vulnerabilities in the Java Runtime Environment in Sun JDK and JRE 6 Update 1 and earlier, and 5.0 Update 13 and earlier, allow context-dependent attackers to gain privileges via an untrusted (1) application or (2) applet, as demonstrated by an application or applet that grants itself privileges to (a) read local files, (b) write to local files, or (c) execute local programs.
Red Hat
java-1.5.0 Privilege escalation via unstrusted applet and application
vendor_redhat·2008-02-05·CVSS 10.0
CVE-2008-0657 [CRITICAL] java-1.5.0 Privilege escalation via unstrusted applet and application
java-1.5.0 Privilege escalation via unstrusted applet and application
Multiple unspecified vulnerabilities in the Java Runtime Environment in Sun JDK and JRE 6 Update 1 and earlier, and 5.0 Update 13 and earlier, allow context-dependent attackers to gain privileges via an untrusted (1) application or (2) applet, as demonstrated by an application or applet that grants itself privileges to (a) read local files, (b) write to local files, or (c) execute local programs.
No detection rules found.
No public exploits indexed.
http://dev2dev.bea.com/pub/advisory/277http://lists.opensuse.org/opensuse-security-announce/2008-04/msg00010.htmlhttp://secunia.com/advisories/28795http://secunia.com/advisories/28888http://secunia.com/advisories/29214http://secunia.com/advisories/29498http://secunia.com/advisories/29841http://secunia.com/advisories/29858http://secunia.com/advisories/29897http://secunia.com/advisories/30676http://secunia.com/advisories/30780http://secunia.com/advisories/31497http://security.gentoo.org/glsa/glsa-200804-28.xmlhttp://sunsolve.sun.com/search/document.do?assetkey=1-26-231261-1http://www.gentoo.org/security/en/glsa/glsa-200804-20.xmlhttp://www.gentoo.org/security/en/glsa/glsa-200806-11.xmlhttp://www.redhat.com/support/errata/RHSA-2008-0123.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0156.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0210.htmlhttp://www.securityfocus.com/bid/27650http://www.securitytracker.com/id?1019308http://www.vmware.com/security/advisories/VMSA-2008-0010.htmlhttp://www.vupen.com/english/advisories/2008/0429http://www.vupen.com/english/advisories/2008/1252http://www.vupen.com/english/advisories/2008/1856/referenceshttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11505http://dev2dev.bea.com/pub/advisory/277http://lists.opensuse.org/opensuse-security-announce/2008-04/msg00010.htmlhttp://secunia.com/advisories/28795http://secunia.com/advisories/28888http://secunia.com/advisories/29214http://secunia.com/advisories/29498http://secunia.com/advisories/29841http://secunia.com/advisories/29858http://secunia.com/advisories/29897http://secunia.com/advisories/30676http://secunia.com/advisories/30780http://secunia.com/advisories/31497http://security.gentoo.org/glsa/glsa-200804-28.xmlhttp://sunsolve.sun.com/search/document.do?assetkey=1-26-231261-1http://www.gentoo.org/security/en/glsa/glsa-200804-20.xmlhttp://www.gentoo.org/security/en/glsa/glsa-200806-11.xmlhttp://www.redhat.com/support/errata/RHSA-2008-0123.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0156.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0210.htmlhttp://www.securityfocus.com/bid/27650http://www.securitytracker.com/id?1019308http://www.vmware.com/security/advisories/VMSA-2008-0010.htmlhttp://www.vupen.com/english/advisories/2008/0429http://www.vupen.com/english/advisories/2008/1252http://www.vupen.com/english/advisories/2008/1856/referenceshttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11505
2008-02-07
Published