CVE-2008-3440
Sun Java <1.6.0_03 - Code Injection
Title source: llmDescription
Sun Java 1.6.0_03 and earlier versions, and possibly later versions, does not properly verify the authenticity of updates, which allows man-in-the-middle attackers to execute arbitrary code via a Trojan horse update, as demonstrated by evilgrade and DNS cache poisoning.
References (4)
Scores
EPSS
0.0070
EPSS Percentile
71.7%
Classification
CWE
CWE-94
Status
draft
Affected Products (4)
sun/java
< 1.6.0
sun/java
sun/java
sun/java
Timeline
Published
Aug 01, 2008
Tracked Since
Feb 18, 2026