CVE-2008-5353
The Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier does not properly enforce context of ZoneInfo objects during deserialization, which allows remote attackers to run untrusted applets and applications in a privileged context, as demonstrated by "deserializing Calendar objects".
- Affected products
- Hp-Ux, Jdk, Java Platform, Java Runtime Environment, Sdk
- Sun Jdk
- ≤ 5.0, 6
- Sun Jre
- ≤ 1.4.2_18, 5.0, 6, 1.4.2_1, 1.4.2_2, 1.4.2_3, 1.4.2_4, 1.4.2_5, 1.4.2_6, 1.4.2_7, 1.4.2_8, 1.4.2_9, 1.4.2_10, 1.4.2_11, 1.4.2_12, 1.4.2_13, 1.4.2_14, 1.4.2_15, 1.4.2_16, 1.4.2_17
- Sun Sdk
- ≤ 1.4.2_18, 1.4.2_1, 1.4.2_2, 1.4.2_3, 1.4.2_4, 1.4.2_5, 1.4.2_6, 1.4.2_7, 1.4.2_8, 1.4.2_9, 1.4.2_10, 1.4.2_11, 1.4.2_12, 1.4.2_13, 1.4.2_14, 1.4.2_15, 1.4.2_16, 1.4.2_17
- Fix
- Available
- CVSS 2.0
- 10.0 HIGH
- EPSS
- 85.8% (100th percentile)
- NVD status
- Modified
- Published
- 2008-12-05
CVE-2008-5353 at NVD
19 known exploits for CVE-2008-5353
Proof-of-concept code and exploit modules indexed by Sploitus
Mac OS X - Java applet Remote Deserialization Remote PoC (updated)
Sun Java Runtime and Development Kit <= 6 Update 10 - Calendar Deserialization Exploit
Signed Applet Social Engineering - Code Execuction
Sun Java Calendar Deserialization Exploit
Signed Applet Social Engineering - Code Execution (Metasploit)
Sun Java - Calendar Deserialization (Metasploit)
Signed Applet Social Engineering Code Exec
Sun Java Calendar Deserialization Privilege Escalation
Sun Java Calendar Deserialization
Mac OS X Java applet Remote Deserialization Remote PoC (updated)
Apple Mac OSX - Java applet Remote Deserialization Remote (2)
Apple Mac OSX - Java applet Remote Deserialization Remote (2)
Mac OS X Java applet Remote Deserialization Remote PoC
Sun Java JDK/JRE安全更新修复多个漏洞
Immunity Canvas: JAVA_DESERIALIZE
Immunity Canvas: JAVA_DESERIALIZE_WIN32
Sun Java Runtime and Development Kit 6 Update 10 - Calendar Deserialization (Metasploit)
Sun Java Runtime and Development Kit <= 6 update 10 Calendar Deserialization Exploit
Sun Java Runtime and Development Kit 6 Update 10 - Calendar Deserialization (Metasploit)