9.3

CVE-2008-1188

Multiple buffer overflows in the useEncodingDecl function in Java Web Start in Sun JDK and JRE 6 Update 4 and earlier, and 5.0 Update 14 and earlier, allow remote attackers to execute arbitrary code via a JNLP file with (1) a long key name in the xml header or (2) a long charset value, different issues than CVE-2008-1189, aka "The first two issues."
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Sun ≫ Jdk Version 1.5.0 Update -
Sun ≫ Jdk Version 1.5.0 Update update1
Sun ≫ Jdk Version 1.5.0 Update update10
Sun ≫ Jdk Version 1.5.0 Update update11
Sun ≫ Jdk Version 1.5.0 Update update12
Sun ≫ Jdk Version 1.5.0 Update update13
Sun ≫ Jdk Version 1.5.0 Update update14
Sun ≫ Jdk Version 1.5.0 Update update2
Sun ≫ Jdk Version 1.5.0 Update update3
Sun ≫ Jdk Version 1.5.0 Update update4
Sun ≫ Jdk Version 1.5.0 Update update5
Sun ≫ Jdk Version 1.5.0 Update update6
Sun ≫ Jdk Version 1.5.0 Update update7
Sun ≫ Jdk Version 1.5.0 Update update8
Sun ≫ Jdk Version 1.5.0 Update update9
Sun ≫ Jdk Version 1.6.0 Update -
Sun ≫ Jdk Version 1.6.0 Update update_3
Sun ≫ Jdk Version 1.6.0 Update update_4
Sun ≫ Jre Version 1.5.0 Update -
Sun ≫ Jre Version 1.5.0 Update update1
Sun ≫ Jre Version 1.5.0 Update update10
Sun ≫ Jre Version 1.5.0 Update update11
Sun ≫ Jre Version 1.5.0 Update update12
Sun ≫ Jre Version 1.5.0 Update update13
Sun ≫ Jre Version 1.5.0 Update update14
Sun ≫ Jre Version 1.5.0 Update update2
Sun ≫ Jre Version 1.5.0 Update update3
Sun ≫ Jre Version 1.5.0 Update update4
Sun ≫ Jre Version 1.5.0 Update update5
Sun ≫ Jre Version 1.5.0 Update update6
Sun ≫ Jre Version 1.5.0 Update update7
Sun ≫ Jre Version 1.5.0 Update update8
Sun ≫ Jre Version 1.5.0 Update update9
Sun ≫ Jre Version 1.6.0 Update -
Sun ≫ Jre Version 1.6.0 Update update_1
Sun ≫ Jre Version 1.6.0 Update update_2
Sun ≫ Jre Version 1.6.0 Update update_3
Sun ≫ Jre Version 1.6.0 Update update_4
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 12.48% 0.957
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.3 8.6 10
AV:N/AC:M/Au:N/C:C/I:C/A:C
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

http://secunia.com/advisories/29858
Third Party Advisory
http://secunia.com/advisories/30780
Third Party Advisory
http://security.gentoo.org/glsa/glsa-200804-28.xml
Third Party Advisory
http://www.gentoo.org/security/en/glsa/glsa-200804-20.xml
Third Party Advisory
http://www.gentoo.org/security/en/glsa/glsa-200806-11.xml
Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2008-04/msg00010.html
Third Party Advisory
Mailing List
http://secunia.com/advisories/29897
Third Party Advisory
http://secunia.com/advisories/30676
Third Party Advisory
http://www.vmware.com/security/advisories/VMSA-2008-0010.html
Third Party Advisory
http://www.vupen.com/english/advisories/2008/1856/references
Third Party Advisory
http://secunia.com/advisories/29498
Third Party Advisory
http://secunia.com/advisories/31497
Third Party Advisory
http://www.redhat.com/support/errata/RHSA-2008-0210.html
Third Party Advisory
http://lists.apple.com/archives/security-announce//2008/Sep/msg00008.html
Third Party Advisory
Mailing List
http://lists.opensuse.org/opensuse-security-announce/2008-04/msg00000.html
Third Party Advisory
Mailing List
http://secunia.com/advisories/29239
Third Party Advisory
http://secunia.com/advisories/29273
Third Party Advisory
http://secunia.com/advisories/29582
Third Party Advisory
http://secunia.com/advisories/32018
Third Party Advisory
http://support.apple.com/kb/HT3178
Third Party Advisory
http://support.apple.com/kb/HT3179
Third Party Advisory
http://www.redhat.com/support/errata/RHSA-2008-0186.html
Third Party Advisory
http://www.us-cert.gov/cas/techalerts/TA08-066A.html
Third Party Advisory
US Government Resource
http://www.vupen.com/english/advisories/2008/0770/references
Third Party Advisory
http://www.redhat.com/support/errata/RHSA-2008-0267.html
Third Party Advisory
http://sunsolve.sun.com/search/document.do?assetkey=1-26-233323-1
Patch
Third Party Advisory
http://www.securitytracker.com/id?1019549
Third Party Advisory
VDB Entry
http://www.zerodayinitiative.com/advisories/ZDI-08-009/
Third Party Advisory
VDB Entry
http://www.zerodayinitiative.com/advisories/ZDI-08-010/
Third Party Advisory
VDB Entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/41029
Third Party Advisory
VDB Entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/41133
Third Party Advisory
VDB Entry
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11209
Third Party Advisory