CVE-2008-3106

medium
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

Unspecified vulnerability in Sun Java Runtime Environment (JRE) in JDK and JRE 6 Update 6 and earlier and JDK and JRE 5.0 Update 15 and earlier allows remote attackers to access URLs via unknown vectors involving processing of XML data by an untrusted (1) application or (2) applet, a different vulnerability than CVE-2008-3105.

References

http://lists.apple.com/archives/security-announce//2008/Sep/msg00007.html

http://lists.opensuse.org/opensuse-security-announce/2008-08/msg00005.html

http://lists.opensuse.org/opensuse-security-announce/2008-09/msg00000.html

http://lists.opensuse.org/opensuse-security-announce/2008-09/msg00002.html

http://marc.info/?l=bugtraq&m=122331139823057&w=2

http://secunia.com/advisories/31010

http://secunia.com/advisories/31320

http://secunia.com/advisories/31497

http://secunia.com/advisories/31600

http://secunia.com/advisories/31736

http://secunia.com/advisories/32018

http://secunia.com/advisories/32179

http://secunia.com/advisories/32180

http://secunia.com/advisories/32436

http://secunia.com/advisories/33237

http://secunia.com/advisories/33238

http://secunia.com/advisories/37386

http://security.gentoo.org/glsa/glsa-200911-02.xml

http://sunsolve.sun.com/search/document.do?assetkey=1-66-238628-1

http://support.apple.com/kb/HT3179

http://support.avaya.com/elmodocs2/security/ASA-2008-299.htm

http://support.avaya.com/elmodocs2/security/ASA-2008-428.htm

http://support.avaya.com/elmodocs2/security/ASA-2008-507.htm

http://support.avaya.com/elmodocs2/security/ASA-2008-509.htm

http://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&id=751014

http://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&id=756717

http://www.redhat.com/support/errata/RHSA-2008-0594.html

http://www.redhat.com/support/errata/RHSA-2008-0790.html

http://www.redhat.com/support/errata/RHSA-2008-0906.html

http://www.redhat.com/support/errata/RHSA-2008-1044.html

http://www.redhat.com/support/errata/RHSA-2008-1045.html

http://www.securityfocus.com/archive/1/497041/100/0/threaded

http://www.securityfocus.com/bid/30143

http://www.securitytracker.com/id?1020457

http://www.us-cert.gov/cas/techalerts/TA08-193A.html

http://www.vmware.com/security/advisories/VMSA-2008-0016.html

http://www.vupen.com/english/advisories/2008/2056/references

http://www.vupen.com/english/advisories/2008/2740

https://exchange.xforce.ibmcloud.com/vulnerabilities/43658

https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10866

Details

Source: MITRE

Published: 2008-07-09

Updated: 2018-10-11

Type: CWE-264

Risk Information

CVSS v2

Base Score: 4.3

Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N

Impact Score: 2.9

Exploitability Score: 8.6

Severity: MEDIUM

Vulnerable Software

Configuration 1

OR

cpe:2.3:a:sun:jdk:5.0:update_1:*:*:*:*:*:*

cpe:2.3:a:sun:jdk:5.0:update_10:*:*:*:*:*:*

cpe:2.3:a:sun:jdk:5.0:update_11:*:*:*:*:*:*

cpe:2.3:a:sun:jdk:5.0:update_12:*:*:*:*:*:*

cpe:2.3:a:sun:jdk:5.0:update_13:*:*:*:*:*:*

cpe:2.3:a:sun:jdk:5.0:update_14:*:*:*:*:*:*

cpe:2.3:a:sun:jdk:*:update_15:*:*:*:*:*:* versions up to 5.0 (inclusive)

cpe:2.3:a:sun:jdk:5.0:update_2:*:*:*:*:*:*

cpe:2.3:a:sun:jdk:5.0:update_3:*:*:*:*:*:*

cpe:2.3:a:sun:jdk:5.0:update_4:*:*:*:*:*:*

cpe:2.3:a:sun:jdk:5.0:update_5:*:*:*:*:*:*

cpe:2.3:a:sun:jdk:5.0:update_6:*:*:*:*:*:*

cpe:2.3:a:sun:jdk:5.0:update_7:*:*:*:*:*:*

cpe:2.3:a:sun:jdk:5.0:update_8:*:*:*:*:*:*

cpe:2.3:a:sun:jdk:5.0:update_9:*:*:*:*:*:*

cpe:2.3:a:sun:jdk:6:update_1:*:*:*:*:*:*

cpe:2.3:a:sun:jdk:6:update_2:*:*:*:*:*:*

cpe:2.3:a:sun:jdk:6:update_3:*:*:*:*:*:*

cpe:2.3:a:sun:jdk:6:update_4:*:*:*:*:*:*

cpe:2.3:a:sun:jdk:6:update_5:*:*:*:*:*:*

cpe:2.3:a:sun:jdk:*:update_6:*:*:*:*:*:* versions up to 6 (inclusive)

cpe:2.3:a:sun:jre:5.0:update_1:*:*:*:*:*:*

cpe:2.3:a:sun:jre:5.0:update_10:*:*:*:*:*:*

cpe:2.3:a:sun:jre:5.0:update_11:*:*:*:*:*:*

cpe:2.3:a:sun:jre:5.0:update_12:*:*:*:*:*:*

cpe:2.3:a:sun:jre:5.0:update_13:*:*:*:*:*:*

cpe:2.3:a:sun:jre:5.0:update_14:*:*:*:*:*:*

cpe:2.3:a:sun:jre:*:update_15:*:*:*:*:*:* versions up to 5.0 (inclusive)

cpe:2.3:a:sun:jre:5.0:update_2:*:*:*:*:*:*

cpe:2.3:a:sun:jre:5.0:update_3:*:*:*:*:*:*

cpe:2.3:a:sun:jre:5.0:update_4:*:*:*:*:*:*

cpe:2.3:a:sun:jre:5.0:update_5:*:*:*:*:*:*

cpe:2.3:a:sun:jre:5.0:update_6:*:*:*:*:*:*

cpe:2.3:a:sun:jre:5.0:update_7:*:*:*:*:*:*

cpe:2.3:a:sun:jre:5.0:update_8:*:*:*:*:*:*

cpe:2.3:a:sun:jre:5.0:update_9:*:*:*:*:*:*

cpe:2.3:a:sun:jre:6:update_1:*:*:*:*:*:*

cpe:2.3:a:sun:jre:6:update_2:*:*:*:*:*:*

cpe:2.3:a:sun:jre:6:update_3:*:*:*:*:*:*

cpe:2.3:a:sun:jre:6:update_4:*:*:*:*:*:*

cpe:2.3:a:sun:jre:6:update_5:*:*:*:*:*:*

cpe:2.3:a:sun:jre:*:update_6:*:*:*:*:*:* versions up to 6 (inclusive)

Tenable Plugins

View all (20 total)

IDNameProductFamilySeverity
69874Juniper NSM Servers Multiple Java JDK/JRE Vulnerabilities (PSN-2012-08-689)NessusMisc.
critical
64833Sun Java JDK/JRE 6 < Update 7 Multiple Vulnerabilities (Unix)NessusMisc.
critical
64832Sun Java JDK/JRE 5 < Update 16 Multiple Vulnerabilities (Unix)NessusMisc.
critical
63858RHEL 5 : java-1.6.0-sun (RHSA-2008:0594)NessusRed Hat Local Security Checks
critical
42834GLSA-200911-02 : Sun JDK/JRE: Multiple vulnerabilitiesNessusGentoo Local Security Checks
critical
40735RHEL 4 / 5 : java-1.6.0-bea (RHSA-2008:1045)NessusRed Hat Local Security Checks
high
40734RHEL 4 / 5 : java-1.5.0-bea (RHSA-2008:1044)NessusRed Hat Local Security Checks
critical
40728RHEL 4 / 5 : java-1.6.0-ibm (RHSA-2008:0906)NessusRed Hat Local Security Checks
critical
40725RHEL 4 / 5 : java-1.5.0-ibm (RHSA-2008:0790)NessusRed Hat Local Security Checks
critical
40383VMSA-2008-0016 : VMware Hosted products, VirtualCenter Update 3 and patches for ESX and ESXi resolve multiple security issuesNessusVMware ESX Local Security Checks
critical
40001openSUSE Security Update : java-1_6_0-sun (java-1_6_0-sun-97)NessusSuSE Local Security Checks
critical
39996openSUSE Security Update : java-1_5_0-sun (java-1_5_0-sun-96)NessusSuSE Local Security Checks
critical
34291Mac OS X : Java for Mac OS X 10.4 Release 7NessusMacOS X Local Security Checks
high
34290Mac OS X : Java for Mac OS X 10.5 Update 2NessusMacOS X Local Security Checks
high
34200SuSE 10 Security Update : IBM Java 1.5 (ZYPP Patch Number 5591)NessusSuSE Local Security Checks
critical
34072SuSE 10 Security Update : IBM Java 1.5.0 (ZYPP Patch Number 5557)NessusSuSE Local Security Checks
critical
34038openSUSE 10 Security Update : java-1_6_0-sun (java-1_6_0-sun-5435)NessusSuSE Local Security Checks
critical
34037openSUSE 10 Security Update : java-1_5_0-sun (java-1_5_0-sun-5434)NessusSuSE Local Security Checks
critical
33488Sun Java JDK/JRE 6 < Update 7 Multiple VulnerabilitiesNessusWindows
high
33487Sun Java JDK/JRE 5 < Update 16 Multiple VulnerabilitiesNessusWindows
high