CVE-2008-3110
published 2008-07-09CVE-2008-3110: Unspecified vulnerability in scripting language support in Sun Java Runtime Environment (JRE) in JDK and JRE 6 Update 6 and earlier allows remote attackers to…
PriorityP419medium4.3CVSS 2.0
AVNACMAuNCPINAN
EPSS
3.34%
87.2th percentile
Unspecified vulnerability in scripting language support in Sun Java Runtime Environment (JRE) in JDK and JRE 6 Update 6 and earlier allows remote attackers to obtain sensitive information by using an applet to read information from another applet.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| sun | jdk | <= 6 | — |
| sun | jdk | — | — |
| sun | jre | <= 6 | — |
| sun | jre | — | — |
| vmware | vmware_esxi | — | — |
| vmware | vmware_workstation | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VMware
VMware Hosted products, VirtualCenter Update 3 and patches for ESX and ESXi resolve multiple security issues
vendor_vmware·2008-10-03·CVSS 6.8
CVE-2008-3103 [MEDIUM] VMware Hosted products, VirtualCenter Update 3 and patches for ESX and ESXi resolve multiple security issues
VMSA-2008-0016: VMware Hosted products, VirtualCenter Update 3 and patches for ESX and ESXi resolve multiple security issues
a. Privilege escalation on 64-bit guest operating systems VMware products emulate hardware functions, like CPU, Memory, and IO. A flaw in VMware's CPU hardware emulation could allow the virtual CPU to jump to an incorrect memory address. Exploitation of this issue on the guest operating system does not lead to a compromise of the host system but could lead to a privilege escalation on guest operating system. An attacker would need to have a user account on the guest operating system. Affected 64-bit Windows and 64-bit FreeBSD guest operating systems and possibly other 64-bit operating systems. The issue does not affect the 64-bit versions of Linux guest operating sy
Red Hat
security flaw
vendor_redhat·2008-07-08·CVSS 4.3
CVE-2008-3110 [MEDIUM] security flaw
security flaw
Unspecified vulnerability in scripting language support in Sun Java Runtime Environment (JRE) in JDK and JRE 6 Update 6 and earlier allows remote attackers to obtain sensitive information by using an applet to read information from another applet.
GHSA
GHSA-p45x-6rjm-x9qf: Unspecified vulnerability in scripting language support in Sun Java Runtime Environment (JRE) in JDK and JRE 6 Update 6 and earlier allows remote atta
ghsa_unreviewed·2022-05-01
CVE-2008-3110 [MEDIUM] GHSA-p45x-6rjm-x9qf: Unspecified vulnerability in scripting language support in Sun Java Runtime Environment (JRE) in JDK and JRE 6 Update 6 and earlier allows remote atta
Unspecified vulnerability in scripting language support in Sun Java Runtime Environment (JRE) in JDK and JRE 6 Update 6 and earlier allows remote attackers to obtain sensitive information by using an applet to read information from another applet.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2008-3110 security flaw
bugzilla·2018-08-16·CVSS 4.3
CVE-2008-3110 [MEDIUM] CVE-2008-3110 security flaw
CVE-2008-3110 security flaw
Flaw bug created to hold information about an old flaw we knew something about. For more details see the MITRE CVE description.
Discussion:
MITRE description:
Unspecified vulnerability in scripting language support in Sun Java Runtime Environment (JRE) in JDK and JRE 6 Update 6 and earlier allows remote attackers to obtain sensitive information by using an applet to read information from another applet.
Bugzilla
CVE-2008-3109 CVE-2008-3110 Security Vulnerabilities in the Java Runtime Environment Scripting Language Support (6529568, 6529579)
bugzilla·2008-07-09·CVSS 7.5
CVE-2008-3109 [HIGH] CVE-2008-3109 CVE-2008-3110 Security Vulnerabilities in the Java Runtime Environment Scripting Language Support (6529568, 6529579)
CVE-2008-3109 CVE-2008-3110 Security Vulnerabilities in the Java Runtime Environment Scripting Language Support (6529568, 6529579)
A vulnerability in the Java Runtime Environment relating to scripting language
support may allow an untrusted applet or application to elevate its privileges.
For example, an untrusted applet may grant itself permissions to read and write
local files or execute local applications that are accessible to the user
running the untrusted applet.
A second vulnerability in the Java Runtime Environment relating to scripting
language support may allow an untrusted applet to access information from
another applet.
Discussion:
This issue has been addressed via:
RHEL Supplementary version 5 (RHSA-2008:0594 (java-1.6.0-sun) and RHSA-2008:0906 (java-1.6.0-ibm))
Red Hat
http://lists.apple.com/archives/security-announce//2008/Sep/msg00007.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-08/msg00005.htmlhttp://marc.info/?l=bugtraq&m=122331139823057&w=2http://secunia.com/advisories/31010http://secunia.com/advisories/31600http://secunia.com/advisories/32018http://secunia.com/advisories/32179http://secunia.com/advisories/32180http://secunia.com/advisories/32436http://secunia.com/advisories/33238http://secunia.com/advisories/37386http://security.gentoo.org/glsa/glsa-200911-02.xmlhttp://sunsolve.sun.com/search/document.do?assetkey=1-66-238687-1http://support.apple.com/kb/HT3179http://support.avaya.com/elmodocs2/security/ASA-2008-428.htmhttp://support.avaya.com/elmodocs2/security/ASA-2008-509.htmhttp://www.redhat.com/support/errata/RHSA-2008-0594.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0906.htmlhttp://www.redhat.com/support/errata/RHSA-2008-1045.htmlhttp://www.securityfocus.com/archive/1/497041/100/0/threadedhttp://www.securityfocus.com/bid/30144http://www.securitytracker.com/id?1020456http://www.us-cert.gov/cas/techalerts/TA08-193A.htmlhttp://www.vmware.com/security/advisories/VMSA-2008-0016.htmlhttp://www.vupen.com/english/advisories/2008/2056/referenceshttp://www.vupen.com/english/advisories/2008/2740https://exchange.xforce.ibmcloud.com/vulnerabilities/43661https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10734http://lists.apple.com/archives/security-announce//2008/Sep/msg00007.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-08/msg00005.htmlhttp://marc.info/?l=bugtraq&m=122331139823057&w=2http://secunia.com/advisories/31010http://secunia.com/advisories/31600http://secunia.com/advisories/32018http://secunia.com/advisories/32179http://secunia.com/advisories/32180http://secunia.com/advisories/32436http://secunia.com/advisories/33238http://secunia.com/advisories/37386http://security.gentoo.org/glsa/glsa-200911-02.xmlhttp://sunsolve.sun.com/search/document.do?assetkey=1-66-238687-1http://support.apple.com/kb/HT3179http://support.avaya.com/elmodocs2/security/ASA-2008-428.htmhttp://support.avaya.com/elmodocs2/security/ASA-2008-509.htmhttp://www.redhat.com/support/errata/RHSA-2008-0594.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0906.htmlhttp://www.redhat.com/support/errata/RHSA-2008-1045.htmlhttp://www.securityfocus.com/archive/1/497041/100/0/threadedhttp://www.securityfocus.com/bid/30144http://www.securitytracker.com/id?1020456http://www.us-cert.gov/cas/techalerts/TA08-193A.htmlhttp://www.vmware.com/security/advisories/VMSA-2008-0016.htmlhttp://www.vupen.com/english/advisories/2008/2056/referenceshttp://www.vupen.com/english/advisories/2008/2740https://exchange.xforce.ibmcloud.com/vulnerabilities/43661https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10734
2008-07-09
Published