9.3

CVE-2008-5359

Buffer overflow in Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; SDK and JRE 1.4.2_18 and earlier; and SDK and JRE 1.3.1_23 and earlier might allow remote attackers to execute arbitrary code, related to a ConvolveOp operation in the Java AWT library.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Sun ≫ Jre Version 1.3.1
Sun ≫ Jre Version 1.3.1_2
Sun ≫ Jre Version 1.3.1_03
Sun ≫ Jre Version 1.3.1_04
Sun ≫ Jre Version 1.3.1_05
Sun ≫ Jre Version 1.3.1_06
Sun ≫ Jre Version 1.3.1_07
Sun ≫ Jre Version 1.3.1_08
Sun ≫ Jre Version 1.3.1_09
Sun ≫ Jre Version 1.3.1_10
Sun ≫ Jre Version 1.3.1_11
Sun ≫ Jre Version 1.3.1_12
Sun ≫ Jre Version 1.3.1_13
Sun ≫ Jre Version 1.3.1_14
Sun ≫ Jre Version 1.3.1_15
Sun ≫ Jre Version 1.3.1_16
Sun ≫ Jre Version 1.3.1_17
Sun ≫ Jre Version 1.3.1_18
Sun ≫ Jre Version 1.3.1_19
Sun ≫ Jre Version 1.3.1_20
Sun ≫ Jre Version 1.3.1_21
Sun ≫ Jre Version 1.3.1_22
Sun ≫ Jre Version 1.3.1_23
Sun ≫ Jre Version 1.4.2
Sun ≫ Jre Version 1.4.2_1
Sun ≫ Jre Version 1.4.2_2
Sun ≫ Jre Version 1.4.2_3
Sun ≫ Jre Version 1.4.2_4
Sun ≫ Jre Version 1.4.2_5
Sun ≫ Jre Version 1.4.2_6
Sun ≫ Jre Version 1.4.2_7
Sun ≫ Jre Version 1.4.2_8
Sun ≫ Jre Version 1.4.2_9
Sun ≫ Jre Version 1.4.2_10
Sun ≫ Jre Version 1.4.2_11
Sun ≫ Jre Version 1.4.2_12
Sun ≫ Jre Version 1.4.2_13
Sun ≫ Jre Version 1.4.2_14
Sun ≫ Jre Version 1.4.2_15
Sun ≫ Jre Version 1.4.2_16
Sun ≫ Jre Version 1.4.2_17
Sun ≫ Jre Version 1.4.2_18
Sun ≫ Jre Version 1.5.0
Sun ≫ Jre Version 1.5.0 Update update1
Sun ≫ Jre Version 1.5.0 Update update10
Sun ≫ Jre Version 1.5.0 Update update11
Sun ≫ Jre Version 1.5.0 Update update12
Sun ≫ Jre Version 1.5.0 Update update13
Sun ≫ Jre Version 1.5.0 Update update14
Sun ≫ Jre Version 1.5.0 Update update15
Sun ≫ Jre Version 1.5.0 Update update16
Sun ≫ Jre Version 1.5.0 Update update2
Sun ≫ Jre Version 1.6.0
Sun ≫ Jre Version 1.6.0 Update update_1
Sun ≫ Jre Version 1.6.0 Update update_10
Sun ≫ Jre Version 1.6.0 Update update_2
Sun ≫ Jre Version 1.6.0 Update update_3
Sun ≫ Jre Version 1.6.0 Update update_4
Sun ≫ Jre Version 1.6.0 Update update_5
Sun ≫ Jre Version 1.6.0 Update update_6
Sun ≫ Jdk Version 1.5.0
Sun ≫ Jdk Version 1.5.0 Update update1
Sun ≫ Jdk Version 1.5.0 Update update10
Sun ≫ Jdk Version 1.5.0 Update update2
Sun ≫ Jdk Version 1.5.0 Update update3
Sun ≫ Jdk Version 1.5.0 Update update4
Sun ≫ Jdk Version 1.5.0 Update update5
Sun ≫ Jdk Version 1.5.0 Update update6
Sun ≫ Jdk Version 1.5.0 Update update7
Sun ≫ Jdk Version 1.5.0 Update update7_b03
Sun ≫ Jdk Version 1.5.0 Update update8
Sun ≫ Jdk Version 1.5.0 Update update9
Sun ≫ Jdk Version 1.6.0
Sun ≫ Jdk Version 1.6.0 Update update_10
Sun ≫ Jdk Version 1.6.0 Update update_3
Sun ≫ Jdk Version 1.6.0 Update update_4
Sun ≫ Jdk Version 1.6.0 Update update_5
Sun ≫ Jdk Version 1.6.0 Update update_6
Sun ≫ Jdk Version 1.6.0 Update update_7
Sun ≫ Sdk Version 1.3.1
Sun ≫ Sdk Version 1.3.1_01
Sun ≫ Sdk Version 1.3.1_01a
Sun ≫ Sdk Version 1.3.1_02
Sun ≫ Sdk Version 1.3.1_03
Sun ≫ Sdk Version 1.3.1_04
Sun ≫ Sdk Version 1.3.1_05
Sun ≫ Sdk Version 1.3.1_06
Sun ≫ Sdk Version 1.3.1_07
Sun ≫ Sdk Version 1.3.1_08
Sun ≫ Sdk Version 1.3.1_09
Sun ≫ Sdk Version 1.3.1_10
Sun ≫ Sdk Version 1.3.1_11
Sun ≫ Sdk Version 1.3.1_12
Sun ≫ Sdk Version 1.3.1_13
Sun ≫ Sdk Version 1.3.1_14
Sun ≫ Sdk Version 1.3.1_15
Sun ≫ Sdk Version 1.3.1_16
Sun ≫ Sdk Version 1.3.1_17
Sun ≫ Sdk Version 1.3.1_18
Sun ≫ Sdk Version 1.3.1_19
Sun ≫ Sdk Version 1.3.1_20
Sun ≫ Sdk Version 1.3.1_21
Sun ≫ Sdk Version 1.3.1_22
Sun ≫ Sdk Version 1.3.1_23
Sun ≫ Sdk Version 1.4.2
Sun ≫ Sdk Version 1.4.2_1
Sun ≫ Sdk Version 1.4.2_2
Sun ≫ Sdk Version 1.4.2_02
Sun ≫ Sdk Version 1.4.2_03
Sun ≫ Sdk Version 1.4.2_3
Sun ≫ Sdk Version 1.4.2_04
Sun ≫ Sdk Version 1.4.2_4
Sun ≫ Sdk Version 1.4.2_5
Sun ≫ Sdk Version 1.4.2_6
Sun ≫ Sdk Version 1.4.2_7
Sun ≫ Sdk Version 1.4.2_8
Sun ≫ Sdk Version 1.4.2_08
Sun ≫ Sdk Version 1.4.2_09
Sun ≫ Sdk Version 1.4.2_9
Sun ≫ Sdk Version 1.4.2_10
Sun ≫ Sdk Version 1.4.2_11
Sun ≫ Sdk Version 1.4.2_12
Sun ≫ Sdk Version 1.4.2_13
Sun ≫ Sdk Version 1.4.2_14
Sun ≫ Sdk Version 1.4.2_15
Sun ≫ Sdk Version 1.4.2_16
Sun ≫ Sdk Version 1.4.2_17
Sun ≫ Sdk Version 1.4.2_18
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 10.78% 0.953
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.3 8.6 10
AV:N/AC:M/Au:N/C:C/I:C/A:C
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

http://lists.opensuse.org/opensuse-security-announce/2009-03/msg00001.html
Third Party Advisory
Mailing List
http://secunia.com/advisories/34259
Third Party Advisory
http://secunia.com/advisories/34972
Third Party Advisory
http://secunia.com/advisories/37386
Third Party Advisory
http://security.gentoo.org/glsa/glsa-200911-02.xml
Third Party Advisory
https://rhn.redhat.com/errata/RHSA-2009-0466.html
Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2009-05/msg00000.html
Third Party Advisory
Mailing List
http://secunia.com/advisories/35065
Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2009-01/msg00009.html
Third Party Advisory
Mailing List
http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00004.html
Third Party Advisory
Mailing List
http://marc.info/?l=bugtraq&m=123678756409861&w=2
Third Party Advisory
Mailing List
http://marc.info/?l=bugtraq&m=126583436323697&w=2
Third Party Advisory
Mailing List
http://rhn.redhat.com/errata/RHSA-2008-1025.html
Third Party Advisory
http://secunia.com/advisories/32991
Third Party Advisory
http://secunia.com/advisories/33015
Third Party Advisory
http://secunia.com/advisories/33528
Third Party Advisory
http://secunia.com/advisories/33710
Third Party Advisory
http://secunia.com/advisories/34233
Third Party Advisory
http://secunia.com/advisories/34605
Third Party Advisory
http://secunia.com/advisories/34889
Third Party Advisory
http://secunia.com/advisories/38539
Third Party Advisory
http://support.avaya.com/elmodocs2/security/ASA-2009-012.htm
Third Party Advisory
http://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&DocumentOID=829914&poid=
Third Party Advisory
http://www.redhat.com/support/errata/RHSA-2009-0015.html
Third Party Advisory
http://www.redhat.com/support/errata/RHSA-2009-0016.html
Third Party Advisory
http://www.redhat.com/support/errata/RHSA-2009-0445.html
Third Party Advisory
http://www.us-cert.gov/cas/techalerts/TA08-340A.html
Third Party Advisory
US Government Resource
http://www.vupen.com/english/advisories/2009/0672
Third Party Advisory
http://www116.nortel.com/pub/repository/CLARIFY/DOCUMENT/2009/03/024431-01.pdf
Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2008-1018.html
Third Party Advisory
http://www.vupen.com/english/advisories/2008/3339
Third Party Advisory
http://secunia.com/advisories/33709
Third Party Advisory
http://www.securityfocus.com/bid/32608
Third Party Advisory
VDB Entry
http://secunia.com/advisories/33187
Third Party Advisory
http://sunsolve.sun.com/search/document.do?assetkey=1-26-244987-1
Patch
Vendor Advisory
http://support.avaya.com/elmodocs2/security/ASA-2008-485.htm
Third Party Advisory
http://www.zerodayinitiative.com/advisories/ZDI-08-080/
Third Party Advisory
VDB Entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/47048
Third Party Advisory
VDB Entry
Mailing List
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5841
Third Party Advisory