CVE-2006-0615

critical

Description

Multiple unspecified vulnerabilities in Sun Java JDK and JRE 5.0 Update 4 and earlier, SDK and JRE 1.4.x through 1.4.2_09 allow remote attackers to bypass Java sandbox security and obtain privileges via unspecified vectors involving the reflection APIs, aka the "second and third issues."

References

https://exchange.xforce.ibmcloud.com/vulnerabilities/24561

http://www.vupen.com/english/advisories/2006/1398

http://www.vupen.com/english/advisories/2006/0828

http://www.vupen.com/english/advisories/2006/0467

http://www.kb.cert.org/vuls/id/759996

http://www.gentoo.org/security/en/glsa/glsa-200602-07.xml

http://securitytracker.com/id?1015596

http://secunia.com/advisories/18884

http://secunia.com/advisories/18760

Details

Source: Mitre, NVD

Published: 2006-02-09

Updated: 2019-07-31

Risk Information

CVSS v2

Base Score: 4

Vector: CVSS2#AV:N/AC:H/Au:N/C:P/I:P/A:N

Severity: Medium

CVSS v3

Base Score: 9.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Severity: Critical