← All CVEs

CVE-2008-1188

high · 9.3

Multiple buffer overflows in the useEncodingDecl function in Java Web Start in Sun JDK and JRE 6 Update 4 and earlier, and 5.0 Update 14 and earlier, allow remote attackers to execute arbitrary code via a JNLP file with (1) a long key name in the xml header or (2) a long charset value, different issues than CVE-2008-1189, aka "The first two issues."

9.3
CVSS
12.5%
EPSS (exploit prob.)
96th
EPSS percentile
2008-03-06
Published

AV:N/AC:M/Au:N/C:C/I:C/A:C

Weaknesses

CWE-119

Affected products

VendorProductAffected versions
sunjdk1.5.0
sunjdk1.5.0
sunjdk1.5.0
sunjdk1.5.0
sunjdk1.5.0
sunjdk1.5.0
sunjdk1.5.0
sunjdk1.5.0
sunjdk1.5.0
sunjdk1.5.0
sunjdk1.5.0
sunjdk1.5.0
sunjdk1.5.0
sunjdk1.5.0
sunjdk1.5.0
sunjdk1.6.0
sunjdk1.6.0
sunjdk1.6.0
sunjre1.5.0
sunjre1.5.0
sunjre1.5.0
sunjre1.5.0
sunjre1.5.0
sunjre1.5.0
sunjre1.5.0
sunjre1.5.0
sunjre1.5.0
sunjre1.5.0
sunjre1.5.0
sunjre1.5.0
sunjre1.5.0
sunjre1.5.0
sunjre1.5.0
sunjre1.6.0
sunjre1.6.0
sunjre1.6.0
sunjre1.6.0
sunjre1.6.0

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2008-1188