cbcvebase.
CVE-2008-4368
published 2008-10-01

CVE-2008-4368: The default configuration of Java 1.5 on Apple Mac OS X 10.5.4 and 10.5.5 contains a jurisdiction policy that limits Java Cryptography Extension (JCE) key…

PriorityP418medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
1.39%
69.5th percentile
The default configuration of Java 1.5 on Apple Mac OS X 10.5.4 and 10.5.5 contains a jurisdiction policy that limits Java Cryptography Extension (JCE) key sizes to 128 bits, which makes it easier for attackers to decrypt ciphertext produced by JCE.

Affected

2 ranges
VendorProductVersion rangeFixed in
applemac_os_x
applemac_os_x
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.