CVE-2008-3110

MEDIUM
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

Unspecified vulnerability in scripting language support in Sun Java Runtime Environment (JRE) in JDK and JRE 6 Update 6 and earlier allows remote attackers to obtain sensitive information by using an applet to read information from another applet.

References

http://lists.apple.com/archives/security-announce//2008/Sep/msg00007.html

http://lists.opensuse.org/opensuse-security-announce/2008-08/msg00005.html

http://marc.info/?l=bugtraq&m=122331139823057&w=2

http://secunia.com/advisories/31010

http://secunia.com/advisories/31600

http://secunia.com/advisories/32018

http://secunia.com/advisories/32179

http://secunia.com/advisories/32180

http://secunia.com/advisories/32436

http://secunia.com/advisories/33238

http://secunia.com/advisories/37386

http://security.gentoo.org/glsa/glsa-200911-02.xml

http://sunsolve.sun.com/search/document.do?assetkey=1-66-238687-1

http://support.apple.com/kb/HT3179

http://support.avaya.com/elmodocs2/security/ASA-2008-428.htm

http://support.avaya.com/elmodocs2/security/ASA-2008-509.htm

http://www.redhat.com/support/errata/RHSA-2008-0594.html

http://www.redhat.com/support/errata/RHSA-2008-0906.html

http://www.redhat.com/support/errata/RHSA-2008-1045.html

http://www.securityfocus.com/archive/1/497041/100/0/threaded

http://www.securityfocus.com/bid/30144

http://www.securitytracker.com/id?1020456

http://www.us-cert.gov/cas/techalerts/TA08-193A.html

http://www.vmware.com/security/advisories/VMSA-2008-0016.html

http://www.vupen.com/english/advisories/2008/2056/references

http://www.vupen.com/english/advisories/2008/2740

https://exchange.xforce.ibmcloud.com/vulnerabilities/43661

https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10734

Details

Source: MITRE

Published: 2008-07-09

Updated: 2018-10-11

Type: CWE-264

Risk Information

CVSS v2

Base Score: 4.3

Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N

Impact Score: 2.9

Exploitability Score: 8.6

Severity: MEDIUM

Tenable Plugins

View all (12 total)

IDNameProductFamilySeverity
69874Juniper NSM Servers Multiple Java JDK/JRE Vulnerabilities (PSN-2012-08-689)NessusMisc.
critical
64833Sun Java JDK/JRE 6 < Update 7 Multiple Vulnerabilities (Unix)NessusMisc.
critical
63858RHEL 5 : java-1.6.0-sun (RHSA-2008:0594)NessusRed Hat Local Security Checks
critical
42834GLSA-200911-02 : Sun JDK/JRE: Multiple vulnerabilitiesNessusGentoo Local Security Checks
critical
40735RHEL 4 / 5 : java-1.6.0-bea (RHSA-2008:1045)NessusRed Hat Local Security Checks
high
40728RHEL 4 / 5 : java-1.6.0-ibm (RHSA-2008:0906)NessusRed Hat Local Security Checks
critical
40383VMSA-2008-0016 : VMware Hosted products, VirtualCenter Update 3 and patches for ESX and ESXi resolve multiple security issuesNessusVMware ESX Local Security Checks
critical
40001openSUSE Security Update : java-1_6_0-sun (java-1_6_0-sun-97)NessusSuSE Local Security Checks
critical
34291Mac OS X : Java for Mac OS X 10.4 Release 7NessusMacOS X Local Security Checks
high
34290Mac OS X : Java for Mac OS X 10.5 Update 2NessusMacOS X Local Security Checks
high
34038openSUSE 10 Security Update : java-1_6_0-sun (java-1_6_0-sun-5435)NessusSuSE Local Security Checks
critical
33488Sun Java JDK/JRE 6 < Update 7 Multiple VulnerabilitiesNessusWindows
high