CVE-2008-5339
Unspecified vulnerability in Java Web Start (JWS) and Java Plug-in with Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier allows untrusted JWS applications to perform network connections to unauthorized hosts via unknown vectors, aka CR 6727079.
- Affected products
- Hp-Ux, Java Development Kit, Java Platform, Java Plug-In, Java Runtime Environment, Java Web Start
- Sun Jdk
- ≤ 5.0, 6
- Sun Jre
- ≤ 1.4.2_18, 5.0, 6, 1.4.2_1, 1.4.2_2, 1.4.2_3, 1.4.2_4, 1.4.2_5, 1.4.2_6, 1.4.2_7, 1.4.2_8, 1.4.2_9, 1.4.2_10, 1.4.2_11, 1.4.2_12, 1.4.2_13, 1.4.2_14, 1.4.2_15, 1.4.2_16, 1.4.2_17
- Sun Sdk
- ≤ 1.4.2_18, 1.4.2_1, 1.4.2_2, 1.4.2_3, 1.4.2_4, 1.4.2_5, 1.4.2_6, 1.4.2_7, 1.4.2_8, 1.4.2_9, 1.4.2_10, 1.4.2_11, 1.4.2_12, 1.4.2_13, 1.4.2_14, 1.4.2_15, 1.4.2_16, 1.4.2_17
- Fix
- Available
- CVSS 2.0
- 5.0 MEDIUM
- EPSS
- 3.5% (88th percentile)
- NVD status
- Modified
- Published
- 2008-12-05
CVE-2008-5339 at NVD
1 known exploit for CVE-2008-5339
Proof-of-concept code and exploit modules indexed by Sploitus