CVE-2008-3109

Unspecified vulnerability in scripting language support in Sun Java Runtime Environment (JRE) in JDK and JRE 6 Update 6 and earlier allows context-dependent attackers to gain privileges via an untrusted (1) application or (2) applet, as demonstrated by an application or applet that grants itself privileges to (a) read local files, (b) write to local files, or (c) execute local programs.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:P/I:P/A:P
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 90%
VendorProductVersion
sunjdk
𝑥
≤ 6
sunjre
𝑥
≤ 6
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
sun-java5
karmic
dne
jaunty
not-affected
intrepid
not-affected
hardy
not-affected
gutsy
not-affected
feisty
not-affected
dapper
not-affected
sun-java6
karmic
not-affected
jaunty
not-affected
intrepid
not-affected
hardy
Fixed 6-17-0ubuntu1.8.04
released
gutsy
ignored
feisty
ignored
dapper
dne
Common Weakness Enumeration
References