CVE-2008-5342

UnknownEPSS 3.01%

Last modified

CVE-2008-5342 is a vulnerability of currently unknown severity. Unspecified vulnerability in the BasicService for Java Web Start (JWS) and Java Plug-in with Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier allows untrusted downloaded applications to cause local files to be displayed in the browser of the user of the untrusted application via unknown vectors, aka 6767668.. EPSS estimates a 3.01% chance of exploitation in the next 30 days.

Description

Unspecified vulnerability in the BasicService for Java Web Start (JWS) and Java Plug-in with Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier allows untrusted downloaded applications to cause local files to be displayed in the browser of the user of the untrusted application via unknown vectors, aka 6767668.

Metrics

EPSS Probability
3.01%

85.7th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersionsUpdate
SunJdk<= 5.0Update 16
SunJdk<= 6Update 10
SunJdk5.0Update 1
SunJdk6
SunJre<= 1.4.2_18
SunJre<= 5.0Update 16
SunJre<= 6Update 10
SunJre1.4.2_1
SunJre1.4.2_2
SunJre1.4.2_3
SunJre1.4.2_4
SunJre1.4.2_5
SunJre1.4.2_6
SunJre1.4.2_7
SunJre1.4.2_8
SunJre1.4.2_9
SunJre1.4.2_10
SunJre1.4.2_11
SunJre1.4.2_12
SunJre1.4.2_13
SunJre1.4.2_14
SunJre1.4.2_15
SunJre1.4.2_16
SunJre1.4.2_17
SunJre5.0
SunJre6
SunSdk<= 1.4.2_18
SunSdk1.4.2_1
SunSdk1.4.2_2
SunSdk1.4.2_3
SunSdk1.4.2_4
SunSdk1.4.2_5
SunSdk1.4.2_6
SunSdk1.4.2_7
SunSdk1.4.2_8
SunSdk1.4.2_9
SunSdk1.4.2_10
SunSdk1.4.2_11
SunSdk1.4.2_12
SunSdk1.4.2_13
SunSdk1.4.2_14
SunSdk1.4.2_15
SunSdk1.4.2_16
SunSdk1.4.2_17

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2008-5342?
Unspecified vulnerability in the BasicService for Java Web Start (JWS) and Java Plug-in with Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier allows untrusted downloaded applications to cause local files to be displayed in the browser of the user of the untrusted application via unknown vectors, aka 6767668.
How severe is CVE-2008-5342?
Severity scoring for CVE-2008-5342 is pending analysis. The EPSS model estimates a 3.01% probability of exploitation in the next 30 days.
How do I fix CVE-2008-5342?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2008-5342?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST