CVE-2008-3113

high
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

Unspecified vulnerability in Sun Java Web Start in JDK and JRE 5.0 before Update 16 and SDK and JRE 1.4.x before 1.4.2_18 allows remote attackers to create or delete arbitrary files via an untrusted application, aka CR 6704077.

References

http://lists.apple.com/archives/security-announce//2008/Sep/msg00008.html

http://lists.opensuse.org/opensuse-security-announce/2008-08/msg00005.html

http://lists.opensuse.org/opensuse-security-announce/2008-09/msg00000.html

http://lists.opensuse.org/opensuse-security-announce/2008-09/msg00002.html

http://lists.opensuse.org/opensuse-security-announce/2008-12/msg00003.html

http://lists.opensuse.org/opensuse-security-announce/2009-05/msg00000.html

http://marc.info/?l=bugtraq&m=122331139823057&w=2

http://rhn.redhat.com/errata/RHSA-2008-0955.html

http://secunia.com/advisories/31010

http://secunia.com/advisories/31055

http://secunia.com/advisories/31320

http://secunia.com/advisories/31497

http://secunia.com/advisories/31600

http://secunia.com/advisories/31736

http://secunia.com/advisories/32018

http://secunia.com/advisories/32179

http://secunia.com/advisories/32180

http://secunia.com/advisories/32826

http://secunia.com/advisories/33194

http://secunia.com/advisories/35065

http://secunia.com/advisories/37386

http://security.gentoo.org/glsa/glsa-200911-02.xml

http://sunsolve.sun.com/search/document.do?assetkey=1-66-238905-1

http://support.apple.com/kb/HT3178

http://support.apple.com/kb/HT3179

http://www.redhat.com/support/errata/RHSA-2008-0595.html

http://www.redhat.com/support/errata/RHSA-2008-0790.html

http://www.securityfocus.com/archive/1/497041/100/0/threaded

http://www.securityfocus.com/bid/30148

http://www.securitytracker.com/id?1020452

http://www.us-cert.gov/cas/techalerts/TA08-193A.html

http://www.vmware.com/security/advisories/VMSA-2008-0016.html

http://www.vupen.com/english/advisories/2008/2056/references

http://www.vupen.com/english/advisories/2008/2740

https://exchange.xforce.ibmcloud.com/vulnerabilities/43667

https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10454

Details

Source: MITRE

Published: 2008-07-09

Updated: 2018-10-30

Type: CWE-264

Risk Information

CVSS v2

Base Score: 10

Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Impact Score: 10

Exploitability Score: 10

Severity: HIGH

Vulnerable Software

Configuration 1

OR

cpe:2.3:a:sun:jdk:5.0:update_1:*:*:*:*:*:*

cpe:2.3:a:sun:jdk:5.0:update_10:*:*:*:*:*:*

cpe:2.3:a:sun:jdk:5.0:update_11:*:*:*:*:*:*

cpe:2.3:a:sun:jdk:5.0:update_12:*:*:*:*:*:*

cpe:2.3:a:sun:jdk:5.0:update_13:*:*:*:*:*:*

cpe:2.3:a:sun:jdk:5.0:update_14:*:*:*:*:*:*

cpe:2.3:a:sun:jdk:*:update_15:*:*:*:*:*:* versions up to 5.0 (inclusive)

cpe:2.3:a:sun:jdk:5.0:update_2:*:*:*:*:*:*

cpe:2.3:a:sun:jdk:5.0:update_3:*:*:*:*:*:*

cpe:2.3:a:sun:jdk:5.0:update_4:*:*:*:*:*:*

cpe:2.3:a:sun:jdk:5.0:update_5:*:*:*:*:*:*

cpe:2.3:a:sun:jdk:5.0:update_6:*:*:*:*:*:*

cpe:2.3:a:sun:jdk:5.0:update_7:*:*:*:*:*:*

cpe:2.3:a:sun:jdk:5.0:update_8:*:*:*:*:*:*

cpe:2.3:a:sun:jdk:5.0:update_9:*:*:*:*:*:*

cpe:2.3:a:sun:jre:1.4.2:*:*:*:*:*:*:*

cpe:2.3:a:sun:jre:1.4.2_01:*:*:*:*:*:*:*

cpe:2.3:a:sun:jre:1.4.2_02:*:*:*:*:*:*:*

cpe:2.3:a:sun:jre:1.4.2_03:*:*:*:*:*:*:*

cpe:2.3:a:sun:jre:1.4.2_04:*:*:*:*:*:*:*

cpe:2.3:a:sun:jre:1.4.2_05:*:*:*:*:*:*:*

cpe:2.3:a:sun:jre:1.4.2_06:*:*:*:*:*:*:*

cpe:2.3:a:sun:jre:1.4.2_07:*:*:*:*:*:*:*

cpe:2.3:a:sun:jre:1.4.2_8:*:*:*:*:*:*:*

cpe:2.3:a:sun:jre:1.4.2_9:*:*:*:*:*:*:*

cpe:2.3:a:sun:jre:1.4.2_10:*:*:*:*:*:*:*

cpe:2.3:a:sun:jre:1.4.2_11:*:*:*:*:*:*:*

cpe:2.3:a:sun:jre:1.4.2_12:*:*:*:*:*:*:*

cpe:2.3:a:sun:jre:1.4.2_13:*:*:*:*:*:*:*

cpe:2.3:a:sun:jre:1.4.2_14:*:*:*:*:*:*:*

cpe:2.3:a:sun:jre:1.4.2_15:*:*:*:*:*:*:*

cpe:2.3:a:sun:jre:1.4.2_16:*:*:*:*:*:*:*

cpe:2.3:a:sun:jre:*:*:*:*:*:*:*:* versions up to 1.4.2_17 (inclusive)

cpe:2.3:a:sun:jre:5.0:update_1:*:*:*:*:*:*

cpe:2.3:a:sun:jre:5.0:update_10:*:*:*:*:*:*

cpe:2.3:a:sun:jre:5.0:update_11:*:*:*:*:*:*

cpe:2.3:a:sun:jre:5.0:update_12:*:*:*:*:*:*

cpe:2.3:a:sun:jre:5.0:update_13:*:*:*:*:*:*

cpe:2.3:a:sun:jre:5.0:update_14:*:*:*:*:*:*

cpe:2.3:a:sun:jre:*:update_15:*:*:*:*:*:* versions up to 5.0 (inclusive)

cpe:2.3:a:sun:jre:5.0:update_2:*:*:*:*:*:*

cpe:2.3:a:sun:jre:5.0:update_3:*:*:*:*:*:*

cpe:2.3:a:sun:jre:5.0:update_4:*:*:*:*:*:*

cpe:2.3:a:sun:jre:5.0:update_5:*:*:*:*:*:*

cpe:2.3:a:sun:jre:5.0:update_6:*:*:*:*:*:*

cpe:2.3:a:sun:jre:5.0:update_7:*:*:*:*:*:*

cpe:2.3:a:sun:jre:5.0:update_8:*:*:*:*:*:*

cpe:2.3:a:sun:jre:5.0:update_9:*:*:*:*:*:*

cpe:2.3:a:sun:sdk:1.4.2:*:*:*:*:*:*:*

cpe:2.3:a:sun:sdk:1.4.2_01:*:*:*:*:*:*:*

cpe:2.3:a:sun:sdk:1.4.2_02:*:*:*:*:*:*:*

cpe:2.3:a:sun:sdk:1.4.2_03:*:*:*:*:*:*:*

cpe:2.3:a:sun:sdk:1.4.2_04:*:*:*:*:*:*:*

cpe:2.3:a:sun:sdk:1.4.2_05:*:*:*:*:*:*:*

cpe:2.3:a:sun:sdk:1.4.2_06:*:*:*:*:*:*:*

cpe:2.3:a:sun:sdk:1.4.2_07:*:*:*:*:*:*:*

cpe:2.3:a:sun:sdk:1.4.2_08:*:*:*:*:*:*:*

cpe:2.3:a:sun:sdk:1.4.2_09:*:*:*:*:*:*:*

cpe:2.3:a:sun:sdk:1.4.2_10:*:*:*:*:*:*:*

cpe:2.3:a:sun:sdk:1.4.2_11:*:*:*:*:*:*:*

cpe:2.3:a:sun:sdk:1.4.2_12:*:*:*:*:*:*:*

cpe:2.3:a:sun:sdk:1.4.2_13:*:*:*:*:*:*:*

cpe:2.3:a:sun:sdk:1.4.2_14:*:*:*:*:*:*:*

cpe:2.3:a:sun:sdk:1.4.2_15:*:*:*:*:*:*:*

cpe:2.3:a:sun:sdk:1.4.2_16:*:*:*:*:*:*:*

cpe:2.3:a:sun:sdk:1.4.2_17:*:*:*:*:*:*:*

Tenable Plugins

View all (24 total)

IDNameProductFamilySeverity
69874Juniper NSM Servers Multiple Java JDK/JRE Vulnerabilities (PSN-2012-08-689)NessusMisc.
critical
64833Sun Java JDK/JRE 6 < Update 7 Multiple Vulnerabilities (Unix)NessusMisc.
critical
64832Sun Java JDK/JRE 5 < Update 16 Multiple Vulnerabilities (Unix)NessusMisc.
critical
64817Sun Java J2SE 1.4.2 < Update 18 Multiple Vulnerabilities (Unix)NessusMisc.
critical
60440Scientific Linux Security Update : java (jdk 1.5.0) on SL4.x, SL5.x i386/x86_64NessusScientific Linux Local Security Checks
critical
43841RHEL 4 : Sun Java Runtime in Satellite Server (RHSA-2008:0636)NessusRed Hat Local Security Checks
critical
42834GLSA-200911-02 : Sun JDK/JRE: Multiple vulnerabilitiesNessusGentoo Local Security Checks
critical
41524SuSE 10 Security Update : IBM Java (ZYPP Patch Number 5846)NessusSuSE Local Security Checks
critical
41258SuSE9 Security Update : IBM Java2 JRE and SDK (YOU Patch Number 12313)NessusSuSE Local Security Checks
critical
41224SuSE9 Security Update : Java2 (YOU Patch Number 12206)NessusSuSE Local Security Checks
critical
40729RHEL 3 / 4 / 5 : java-1.4.2-ibm (RHSA-2008:0955)NessusRed Hat Local Security Checks
critical
40725RHEL 4 / 5 : java-1.5.0-ibm (RHSA-2008:0790)NessusRed Hat Local Security Checks
critical
40723RHEL 4 / 5 : java-1.5.0-sun (RHSA-2008:0595)NessusRed Hat Local Security Checks
critical
40383VMSA-2008-0016 : VMware Hosted products, VirtualCenter Update 3 and patches for ESX and ESXi resolve multiple security issuesNessusVMware ESX Local Security Checks
critical
39996openSUSE Security Update : java-1_5_0-sun (java-1_5_0-sun-96)NessusSuSE Local Security Checks
critical
34291Mac OS X : Java for Mac OS X 10.4 Release 7NessusMacOS X Local Security Checks
high
34290Mac OS X : Java for Mac OS X 10.5 Update 2NessusMacOS X Local Security Checks
high
34200SuSE 10 Security Update : IBM Java 1.5 (ZYPP Patch Number 5591)NessusSuSE Local Security Checks
critical
34072SuSE 10 Security Update : IBM Java 1.5.0 (ZYPP Patch Number 5557)NessusSuSE Local Security Checks
critical
34037openSUSE 10 Security Update : java-1_5_0-sun (java-1_5_0-sun-5434)NessusSuSE Local Security Checks
critical
34036SuSE 10 Security Update : Java 1.4.2 (ZYPP Patch Number 5431)NessusSuSE Local Security Checks
critical
34035openSUSE 10 Security Update : java-1_4_2-sun (java-1_4_2-sun-5430)NessusSuSE Local Security Checks
critical
33487Sun Java JDK/JRE 5 < Update 16 Multiple VulnerabilitiesNessusWindows
high
33486Sun Java J2SE 1.4.2 < Update 18 Multiple VulnerabilitiesNessusWindows
high