CVE-2008-5342

Java Web Start/JDK/JRE - Info Disclosure

Title source: llm
STIX 2.1

Description

Unspecified vulnerability in the BasicService for Java Web Start (JWS) and Java Plug-in with Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier allows untrusted downloaded applications to cause local files to be displayed in the browser of the user of the untrusted application via unknown vectors, aka 6767668.

References (33)

Core 33
Core References
Vendor Advisory vendor-advisory x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2009-0369.html
Vendor Advisory vendor-advisory x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2009-0445.html
Vendor Advisory vendor-advisory x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2009-0016.html
US Government Resource third-party-advisory x_refsource_cert
http://www.us-cert.gov/cas/techalerts/TA08-340A.html
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6359
Patch, Vendor Advisory vendor-advisory x_refsource_sunalert
http://sunsolve.sun.com/search/document.do?assetkey=1-26-244988-1
Mailing List vendor-advisory x_refsource_hp
http://marc.info/?l=bugtraq&m=126583436323697&w=2
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2009/0672
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/50514
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/34447
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2008-1018.html
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/33015
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/34889
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/34233
Third Party Advisory vendor-advisory x_refsource_gentoo
http://security.gentoo.org/glsa/glsa-200911-02.xml
Mailing List vendor-advisory x_refsource_hp
http://marc.info/?l=bugtraq&m=123678756409861&w=2
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/38539
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/35065
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2009/0424
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2008-1025.html
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2008/3339
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/34605
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/32991
Mailing List vendor-advisory x_refsource_apple
http://lists.apple.com/archives/security-announce/2009/Feb/msg00003.html
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/37386
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/33710

Scores

EPSS 0.0113
EPSS Percentile 78.6%

Details

CWE
CWE-200
Status published
Products (22)
sun/jdk 5.0 update_1 (15 CPE variants)
sun/jdk 6 (10 CPE variants)
sun/jdk < 5.0
sun/jdk < 6
sun/jre 1.4.2_1
sun/jre 1.4.2_2
sun/jre 1.4.2_3
sun/jre 1.4.2_4
sun/jre 1.4.2_5
sun/jre 1.4.2_6
... and 12 more
Published Dec 05, 2008
Tracked Since Feb 18, 2026