CVE-2008-5355

Java Runtime Environment <6 - RCE

Title source: llm

Description

The "Java Update" feature for Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier does not verify the signature of the JRE that is downloaded, which allows remote attackers to execute arbitrary code via DNS man-in-the-middle attacks.

Scores

EPSS 0.1592
EPSS Percentile 94.6%

Classification

CWE
CWE-287
Status draft

Affected Products (50)

sun/jdk < 5.0
sun/jdk < 6
sun/jdk
sun/jdk
sun/jdk
sun/jdk
sun/jdk
sun/jdk
sun/jdk
sun/jdk
sun/jdk
sun/jdk
sun/jdk
sun/jdk
sun/jdk
... and 35 more

Timeline

Published Dec 05, 2008
Tracked Since Feb 18, 2026