← Back

CVE-2008-3111

nvd nist
Published: Jul 9, 2008Modified: Apr 23, 2026

JSON object

Loading...
10.0
Vector
AV:N/AC:L/Au:N/C:C/I:C/A:C
Exploitability: 10.0 / Impact: 10.0
Source: NVD

Description

Multiple buffer overflows in Sun Java Web Start in JDK and JRE 6 before Update 4, JDK and JRE 5.0 before Update 16, and SDK and JRE 1.4.x before 1.4.2_18 allow context-dependent attackers to gain privileges via an untrusted application, as demonstrated by (a) an application that grants itself privileges to (1) read local files, (2) write to local files, or (3) execute local programs; and as demonstrated by (b) a long value associated with a java-vm-args attribute in a j2se tag in a JNLP file, which triggers a stack-based buffer overflow in the GetVMArgsOption function; aka CR 6557220.

Affected (73)

Products: Sun: Jdk, Jre, Sdk
3 products
Jdk
Jre
Sdk
Configuration A
73 vulnerable
Vulnerable SoftwareAffected Versions
Sun
Version 5.0 update_10
Version 5.0 update_11
Version 5.0 update_12
Version 5.0 update_13
Version 5.0 update_14
Version 5.0 update_15
Version 5.0 update_1
Version 5.0 update_2
Version 5.0 update_3
Version 5.0 update_4
Version 5.0 update_5
Version 5.0 update_6
Version 5.0 update_7
Version 5.0 update_8
Version 5.0 update_9
Version 6 update_1
Version 6 update_2
Version 6 update_3
Sun
Version 1.4.2_01
Version 1.4.2_02
Version 1.4.2_03
Version 1.4.2_04
Version 1.4.2_05
Version 1.4.2_06
Version 1.4.2_07
Version 1.4.2_10
Version 1.4.2_11
Version 1.4.2_12
Version 1.4.2_13
Version 1.4.2_14
Version 1.4.2_15
Version 1.4.2_16
Version 1.4.2_17
Version 1.4.2_8
Version 1.4.2_9
Version 1.4
Version 5.0 update_10
Version 5.0 update_11
Version 5.0 update_12
Version 5.0 update_13
Version 5.0 update_14
Version 5.0 update_15
Version 5.0 update_1
Version 5.0 update_2
Version 5.0 update_3
Version 5.0 update_4
Version 5.0 update_5
Version 5.0 update_6
Version 5.0 update_7
Version 5.0 update_8
Version 5.0 update_9
Version 6 update_1
Version 6 update_2
Version 6 update_3
Sun
Version 1.4.2
Version 1.4.2_01
Version 1.4.2_02
Version 1.4.2_03
Version 1.4.2_04
Version 1.4.2_05
Version 1.4.2_06
Version 1.4.2_07
Version 1.4.2_08
Version 1.4.2_09
Version 1.4.2_10
Version 1.4.2_11
Version 1.4.2_12
Version 1.4.2_13
Version 1.4.2_14
Version 1.4.2_15
Version 1.4.2_16
Version 1.4.2_17
Version 1.4

References (64)

Source: cve@mitre.org
Vendor Advisory
Source: cve@mitre.org
Vendor Advisory
Source: cve@mitre.org
Vendor Advisory
Source: cve@mitre.org
Vendor Advisory
Source: cve@mitre.org
Vendor Advisory
Source: cve@mitre.org
Vendor Advisory
Source: cve@mitre.org
Vendor Advisory
Source: cve@mitre.org
Vendor Advisory
Source: cve@mitre.org
Vendor Advisory
Source: cve@mitre.org
US Government Resource
Source: cve@mitre.org
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
US Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.