CVE-2008-1190
high · 9.3Unspecified vulnerability in Java Web Start in Sun JDK and JRE 6 Update 4 and earlier, 5.0 Update 14 and earlier, and SDK/JRE 1.4.2_16 and earlier allows remote attackers to gain privileges via an untrusted application, a different issue than CVE-2008-1191, aka the "fourth" issue.
9.3
CVSS
16.9%
EPSS (exploit prob.)
97th
EPSS percentile
2008-03-06
Published
AV:N/AC:M/Au:N/C:C/I:C/A:C
Weaknesses
CWE-264
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| sun | jdk | 1.5.0 |
| sun | jdk | 1.5.0 |
| sun | jdk | 1.5.0 |
| sun | jdk | 1.5.0 |
| sun | jdk | 1.5.0 |
| sun | jdk | 1.5.0 |
| sun | jdk | 1.5.0 |
| sun | jdk | 1.5.0 |
| sun | jdk | 1.5.0 |
| sun | jdk | 1.5.0 |
| sun | jdk | 1.5.0 |
| sun | jdk | 1.5.0 |
| sun | jdk | 1.5.0 |
| sun | jdk | 1.5.0 |
| sun | jdk | 1.5.0 |
| sun | jdk | 1.6.0 |
| sun | jdk | 1.6.0 |
| sun | jdk | 1.6.0 |
| sun | jre | 1.4.2 |
| sun | jre | 1.4.2_1 |
| sun | jre | 1.4.2_2 |
| sun | jre | 1.4.2_3 |
| sun | jre | 1.4.2_4 |
| sun | jre | 1.4.2_5 |
| sun | jre | 1.4.2_6 |
| sun | jre | 1.4.2_7 |
| sun | jre | 1.4.2_8 |
| sun | jre | 1.4.2_9 |
| sun | jre | 1.4.2_10 |
| sun | jre | 1.4.2_11 |
| sun | jre | 1.4.2_12 |
| sun | jre | 1.4.2_13 |
| sun | jre | 1.4.2_14 |
| sun | jre | 1.4.2_15 |
| sun | jre | 1.4.2_16 |
| sun | jre | 1.5.0 |
| sun | jre | 1.5.0 |
| sun | jre | 1.5.0 |
| sun | jre | 1.5.0 |
| sun | jre | 1.5.0 |
Check a specific version with /api/v1/cve/match.
References
- http://lists.apple.com/archives/security-announce//2008/Sep/msg00008.html
- http://lists.opensuse.org/opensuse-security-announce/2008-04/msg00000.html
- http://lists.opensuse.org/opensuse-security-announce/2008-04/msg00010.html
- http://secunia.com/advisories/29239
- http://secunia.com/advisories/29273
- http://secunia.com/advisories/29498
- http://secunia.com/advisories/29582
- http://secunia.com/advisories/29858
- http://secunia.com/advisories/29897
- http://secunia.com/advisories/30676
- http://secunia.com/advisories/30780
- http://secunia.com/advisories/31497
- http://secunia.com/advisories/32018
- http://security.gentoo.org/glsa/glsa-200804-28.xml
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-233323-1
- http://support.apple.com/kb/HT3178
- http://support.apple.com/kb/HT3179
- http://www.gentoo.org/security/en/glsa/glsa-200804-20.xml
- http://www.gentoo.org/security/en/glsa/glsa-200806-11.xml
- http://www.redhat.com/support/errata/RHSA-2008-0186.html
- http://www.redhat.com/support/errata/RHSA-2008-0210.html
- http://www.redhat.com/support/errata/RHSA-2008-0267.html
- http://www.securitytracker.com/id?1019549
- http://www.us-cert.gov/cas/techalerts/TA08-066A.html
- http://www.vmware.com/security/advisories/VMSA-2008-0010.html
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2008-1190