CVE-2006-0614

critical

Description

Unspecified vulnerability in Sun Java JDK and JRE 5.0 Update 3 and earlier, SDK and JRE 1.3.x through 1.3.1_16 and 1.4.x through 1.4.2_08 allows remote attackers to bypass Java sandbox security and obtain privileges via unspecified vectors involving the reflection APIs, aka the "first issue."

References

https://exchange.xforce.ibmcloud.com/vulnerabilities/24561

http://www.vupen.com/english/advisories/2006/1398

http://www.vupen.com/english/advisories/2006/0828

http://www.vupen.com/english/advisories/2006/0467

http://www.kb.cert.org/vuls/id/759996

http://www.gentoo.org/security/en/glsa/glsa-200602-07.xml

http://securitytracker.com/id?1015596

http://secunia.com/advisories/18884

http://secunia.com/advisories/18760

http://docs.info.apple.com/article.html?artnum=303658

Details

Source: Mitre, NVD

Published: 2006-02-09

Updated: 2018-10-04

Risk Information

CVSS v2

Base Score: 6.4

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:N

Severity: Medium

CVSS v3

Base Score: 9.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Severity: Critical