← All CVEs

CVE-2008-5353

high · 10

The Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier does not properly enforce context of ZoneInfo objects during deserialization, which allows remote attackers to run untrusted applets and applications in a privileged context, as demonstrated by "deserializing Calendar objects".

10
CVSS
85.8%
EPSS (exploit prob.)
100th
EPSS percentile
2008-12-05
Published

AV:N/AC:L/Au:N/C:C/I:C/A:C

Affected products

VendorProductAffected versions
sunjdk<= 5.0
sunjdk<= 6
sunjdk5.0
sunjdk5.0
sunjdk5.0
sunjdk5.0
sunjdk5.0
sunjdk5.0
sunjdk5.0
sunjdk5.0
sunjdk5.0
sunjdk5.0
sunjdk5.0
sunjdk5.0
sunjdk5.0
sunjdk5.0
sunjdk5.0
sunjdk6
sunjdk6
sunjdk6
sunjdk6
sunjdk6
sunjdk6
sunjdk6
sunjdk6
sunjdk6
sunjdk6
sunjre<= 1.4.2_18
sunjre<= 5.0
sunjre<= 6
sunjre1.4.2_1
sunjre1.4.2_2
sunjre1.4.2_3
sunjre1.4.2_4
sunjre1.4.2_5
sunjre1.4.2_6
sunjre1.4.2_7
sunjre1.4.2_8
sunjre1.4.2_9
sunjre1.4.2_10

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2008-5353