CVE-2008-5347
published 2008-12-05CVE-2008-5347: Multiple unspecified vulnerabilities in Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier allow untrusted applets and applications to…
PriorityP339high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
3.43%
87.5th percentile
Multiple unspecified vulnerabilities in Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier allow untrusted applets and applications to gain privileges via vectors related to access to inner classes in the (1) JAX-WS and (2) JAXB packages.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| sun | jdk | <= 6 | — |
| sun | jdk | — | — |
| sun | jre | <= 6 | — |
| sun | jre | — | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
openjdk-6 vulnerabilities
vendor_ubuntu·2009-01-27·CVSS 7.5
CVE-2008-5352 [HIGH] openjdk-6 vulnerabilities
Title: openjdk-6 vulnerabilities
Summary: openjdk-6 vulnerabilities
It was discovered that Java did not correctly handle untrusted applets.
If a user were tricked into running a malicious applet, a remote attacker
could gain user privileges, or list directory contents. (CVE-2008-5347,
CVE-2008-5350)
It was discovered that Kerberos authentication and RSA public key
processing were not correctly handled in Java. A remote attacker
could exploit these flaws to cause a denial of service. (CVE-2008-5348,
CVE-2008-5349)
It was discovered that Java accepted UTF-8 encodings that might be
handled incorrectly by certain applications. A remote attacker could
bypass string filters, possible leading to other exploits. (CVE-2008-5351)
Overflows were discovered in Java JAR processing. If a user or
au
Red Hat
OpenJDK applet privilege escalation via JAX package access (6592792)
vendor_redhat·2008-12-03·CVSS 7.5
CVE-2008-5347 [HIGH] OpenJDK applet privilege escalation via JAX package access (6592792)
OpenJDK applet privilege escalation via JAX package access (6592792)
Multiple unspecified vulnerabilities in Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier allow untrusted applets and applications to gain privileges via vectors related to access to inner classes in the (1) JAX-WS and (2) JAXB packages.
GHSA
GHSA-982w-2wqp-q964: Multiple unspecified vulnerabilities in Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier allow untrusted applets and applica
ghsa_unreviewed·2022-05-17
CVE-2008-5347 [HIGH] GHSA-982w-2wqp-q964: Multiple unspecified vulnerabilities in Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier allow untrusted applets and applica
Multiple unspecified vulnerabilities in Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier allow untrusted applets and applications to gain privileges via vectors related to access to inner classes in the (1) JAX-WS and (2) JAXB packages.
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-security-announce/2009-03/msg00001.htmlhttp://marc.info/?l=bugtraq&m=123678756409861&w=2http://marc.info/?l=bugtraq&m=126583436323697&w=2http://osvdb.org/50506http://rhn.redhat.com/errata/RHSA-2008-1018.htmlhttp://secunia.com/advisories/32991http://secunia.com/advisories/33015http://secunia.com/advisories/33528http://secunia.com/advisories/33709http://secunia.com/advisories/34233http://secunia.com/advisories/34259http://secunia.com/advisories/37386http://secunia.com/advisories/38539http://security.gentoo.org/glsa/glsa-200911-02.xmlhttp://sunsolve.sun.com/search/document.do?assetkey=1-26-246366-1http://sunsolve.sun.com/search/document.do?assetkey=1-77-1019798.1-1http://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&DocumentOID=829914&poid=http://www.redhat.com/support/errata/RHSA-2009-0015.htmlhttp://www.securityfocus.com/bid/32608http://www.securitytracker.com/id?1021307http://www.us-cert.gov/cas/techalerts/TA08-340A.htmlhttp://www.vupen.com/english/advisories/2008/3339http://www.vupen.com/english/advisories/2009/0672http://www116.nortel.com/pub/repository/CLARIFY/DOCUMENT/2009/03/024431-01.pdfhttps://exchange.xforce.ibmcloud.com/vulnerabilities/47068https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5633http://lists.opensuse.org/opensuse-security-announce/2009-03/msg00001.htmlhttp://marc.info/?l=bugtraq&m=123678756409861&w=2http://marc.info/?l=bugtraq&m=126583436323697&w=2http://osvdb.org/50506http://rhn.redhat.com/errata/RHSA-2008-1018.htmlhttp://secunia.com/advisories/32991http://secunia.com/advisories/33015http://secunia.com/advisories/33528http://secunia.com/advisories/33709http://secunia.com/advisories/34233http://secunia.com/advisories/34259http://secunia.com/advisories/37386http://secunia.com/advisories/38539http://security.gentoo.org/glsa/glsa-200911-02.xmlhttp://sunsolve.sun.com/search/document.do?assetkey=1-26-246366-1http://sunsolve.sun.com/search/document.do?assetkey=1-77-1019798.1-1http://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&DocumentOID=829914&poid=http://www.redhat.com/support/errata/RHSA-2009-0015.htmlhttp://www.securityfocus.com/bid/32608http://www.securitytracker.com/id?1021307http://www.us-cert.gov/cas/techalerts/TA08-340A.htmlhttp://www.vupen.com/english/advisories/2008/3339http://www.vupen.com/english/advisories/2009/0672http://www116.nortel.com/pub/repository/CLARIFY/DOCUMENT/2009/03/024431-01.pdfhttps://exchange.xforce.ibmcloud.com/vulnerabilities/47068https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5633
2008-12-05
Published