cbcvebase.
CVE-2008-1193
published 2008-03-06

CVE-2008-1193: Unspecified vulnerability in Java Runtime Environment Image Parsing Library in Sun JDK and JRE 6 Update 4 and earlier, and 5.0 Update 14 and earlier, allows…

PriorityP355critical9.3CVSS 2.0
AVNACMAuNCCICAC
EXPLOIT
EPSS
12.50%
95.8th percentile
Unspecified vulnerability in Java Runtime Environment Image Parsing Library in Sun JDK and JRE 6 Update 4 and earlier, and 5.0 Update 14 and earlier, allows remote attackers to gain privileges via an untrusted application.

Affected

4 ranges
VendorProductVersion rangeFixed in
sunjdk
sunjdk
sunjre
sunjre

Detection & IOCsextracted from sources · hover to see the quote

urlhttps://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/31343.jpg
  • Exploit delivery via malicious image file (JPEG/image format) triggering heap buffer overflow in JRE Image Parsing Library — monitor for untrusted applets or applications loading crafted image files
  • Privilege escalation vector is an untrusted application or applet downloaded from a website — monitor for Java applet execution granting unexpected file read/write or process execution permissions
  • ·Vulnerability is unspecified/undisclosed in technical detail by the vendor; no patch-level configuration or specific trigger mechanism is publicly documented beyond image parsing in JRE
  • ·Affected version scope is broader than the CVE title implies — also covers SDK/JRE 1.4.2 prior to _17 and SDK/JRE 1.3.1 prior to _22, not only JDK/JRE 5.0 and 6

CVSS provenance

nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_redhat9.3CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.