Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2008-5352

Integer overflow in the JAR unpacking utility (unpack200) in the unpack library (unpack.dll) in Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier, and JDK and JRE 5.0 Update 16 and earlier, allows untrusted applications and applets to gain privileges via a Pack200 compressed JAR file that triggers a heap-based buffer overflow.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.085
EPSS Ranking 92.0%
CVSS Severity
CVSS v2 Score 9.3
References
Products affected by CVE-2008-5352
  • Sun » Jdk » Version: 1.6.0
    cpe:2.3:a:sun:jdk:1.6.0
  • Sun » Jdk » Version: 5.0
    cpe:2.3:a:sun:jdk:5.0
  • Sun » Jdk » Version: 6
    cpe:2.3:a:sun:jdk:6
  • Sun » Jre » Version: 1.6.0
    cpe:2.3:a:sun:jre:1.6.0
  • Sun » Jre » Version: 5.0
    cpe:2.3:a:sun:jre:5.0
  • Sun » Jre » Version: 6
    cpe:2.3:a:sun:jre:6


Contact Us

Shodan ® - All rights reserved