CVE-2008-1195Ubuntu Linux vulnerability

CWE-2546 documents6 sources
Severity
9.3CRITICALNVD
EPSS
14.4%
top 5.56%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 6
Latest updateMay 1

Description

Unspecified vulnerability in Sun JDK and Java Runtime Environment (JRE) 6 Update 4 and earlier and 5.0 Update 14 and earlier; and SDK and JRE 1.4.2_16 and earlier; allows remote attackers to access arbitrary network services on the local host via unspecified vectors related to JavaScript and Java APIs.

CVSS vector

AV:N/AC:M/C:C/I:C/A:CExploitability: 8.6 | Impact: 10.0

Affected Packages3 packages

NVDsun/jdk1.5.0, 1.6.0+1
NVDsun/jre19 versions+18
NVDsun/sdk17 versions+16

Also affects: Ubuntu Linux 6.06, 6.10, 7.04, 7.10

🔴Vulnerability Details

2
GHSA
GHSA-hqpc-pj99-85gx: Unspecified vulnerability in Sun JDK and Java Runtime Environment (JRE) 6 Update 4 and earlier and 52022-05-01
CVEList
CVE-2008-1195: Unspecified vulnerability in Sun JDK and Java Runtime Environment (JRE) 6 Update 4 and earlier and 52008-03-06

📋Vendor Advisories

2
Ubuntu
Firefox vulnerabilities2008-03-26
Red Hat
Java-API calls in untrusted Javascript allow network privilege escalation2008-03-06

💬Community

1
Bugzilla
CVE-2008-1195 Java-API calls in untrusted Javascript allow network privilege escalation2008-03-06
CVE-2008-1195 — Canonical Ubuntu Linux vulnerability | cvebase