CVE-2008-5357
Integer overflow in Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; SDK and JRE 1.4.2_18 and earlier; and SDK and JRE 1.3.1_23 and earlier might allow remote attackers to execute arbitrary code via a crafted TrueType font file, which triggers a heap-based buffer overflow.
- Affected products
- Hp-Ux, Java Platform, Java Runtime Environment
- Sun Jre
- = 1.3.1, 1.3.1_2, 1.3.1_03, 1.3.1_04, 1.3.1_05, 1.3.1_06, 1.3.1_07, 1.3.1_08, 1.3.1_09, 1.3.1_10, 1.3.1_11, 1.3.1_12, 1.3.1_13, 1.3.1_14, 1.3.1_15, 1.3.1_16, 1.3.1_17, 1.3.1_18, 1.3.1_19, 1.3.1_20, 1.3.1_21, 1.3.1_22, 1.3.1_23, 1.4.2, 1.4.2_1, 1.4.2_2, 1.4.2_3, 1.4.2_4, 1.4.2_5, 1.4.2_6, 1.4.2_7, 1.4.2_8, 1.4.2_9, 1.4.2_10, 1.4.2_11, 1.4.2_12, 1.4.2_13, 1.4.2_14, 1.4.2_15, 1.4.2_16
- Fix
- Available
- CVSS 2.0
- 9.3 HIGH
- EPSS
- 10.0% (95th percentile)
- Weakness
- CWE-189
- NVD status
- Modified
- Published
- 2008-12-05
CVE-2008-5357 at NVD
1 known exploit for CVE-2008-5357
Proof-of-concept code and exploit modules indexed by Sploitus