CVE-2008-5355
Java Runtime Environment <6 - RCE
Title source: llmDescription
The "Java Update" feature for Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier does not verify the signature of the JRE that is downloaded, which allows remote attackers to execute arbitrary code via DNS man-in-the-middle attacks.
References (10)
Scores
EPSS
0.1592
EPSS Percentile
94.6%
Classification
CWE
CWE-287
Status
draft
Affected Products (50)
sun/jdk
< 5.0
sun/jdk
< 6
sun/jdk
sun/jdk
sun/jdk
sun/jdk
sun/jdk
sun/jdk
sun/jdk
sun/jdk
sun/jdk
sun/jdk
sun/jdk
sun/jdk
sun/jdk
... and 35 more
Timeline
Published
Dec 05, 2008
Tracked Since
Feb 18, 2026