9.3

CVE-2008-5352

Integer overflow in the JAR unpacking utility (unpack200) in the unpack library (unpack.dll) in Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier, and JDK and JRE 5.0 Update 16 and earlier, allows untrusted applications and applets to gain privileges via a Pack200 compressed JAR file that triggers a heap-based buffer overflow.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SunJdk Updateupdate_16 Version <= 5.0
SunJdk Updateupdate_10 Version <= 6
SunJdk Version5.0 Updateupdate_1
SunJdk Version5.0 Updateupdate_10
SunJdk Version5.0 Updateupdate_11
SunJdk Version5.0 Updateupdate_12
SunJdk Version5.0 Updateupdate_13
SunJdk Version5.0 Updateupdate_14
SunJdk Version5.0 Updateupdate_15
SunJdk Version5.0 Updateupdate_2
SunJdk Version5.0 Updateupdate_3
SunJdk Version6
SunJdk Version6 Updateupdate_1
SunJdk Version6 Updateupdate_2
SunJdk Version6 Updateupdate_3
SunJdk Version6 Updateupdate_4
SunJdk Version6 Updateupdate_5
SunJdk Version6 Updateupdate_6
SunJdk Version6 Updateupdate_7
SunJdk Version6 Updateupdate_8
SunJre Updateupdate_16 Version <= 5.0
SunJre Updateupdate_10 Version <= 6
SunJre Version5.0
SunJre Version5.0 Updateupdate_1
SunJre Version5.0 Updateupdate_10
SunJre Version5.0 Updateupdate_11
SunJre Version5.0 Updateupdate_12
SunJre Version5.0 Updateupdate_13
SunJre Version5.0 Updateupdate_14
SunJre Version5.0 Updateupdate_15
SunJre Version5.0 Updateupdate_2
SunJre Version6
SunJre Version6 Updateupdate_1
SunJre Version6 Updateupdate_2
SunJre Version6 Updateupdate_3
SunJre Version6 Updateupdate_4
SunJre Version6 Updateupdate_5
SunJre Version6 Updateupdate_6
SunJre Version6 Updateupdate_7
SunJre Version6 Updateupdate_8
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 8.5% 0.92
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.3 8.6 10
AV:N/AC:M/Au:N/C:C/I:C/A:C