CVE-2008-5342
Last modified
CVE-2008-5342 is a vulnerability of currently unknown severity. Unspecified vulnerability in the BasicService for Java Web Start (JWS) and Java Plug-in with Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier allows untrusted downloaded applications to cause local files to be displayed in the browser of the user of the untrusted application via unknown vectors, aka 6767668.. EPSS estimates a 3.01% chance of exploitation in the next 30 days.
Description
Unspecified vulnerability in the BasicService for Java Web Start (JWS) and Java Plug-in with Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier allows untrusted downloaded applications to cause local files to be displayed in the browser of the user of the untrusted application via unknown vectors, aka 6767668.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Sun | Jdk | <= 5.0 | Update 16 |
| Sun | Jdk | <= 6 | Update 10 |
| Sun | Jdk | 5.0 | Update 1 |
| Sun | Jdk | 6 | — |
| Sun | Jre | <= 1.4.2_18 | — |
| Sun | Jre | <= 5.0 | Update 16 |
| Sun | Jre | <= 6 | Update 10 |
| Sun | Jre | 1.4.2_1 | — |
| Sun | Jre | 1.4.2_2 | — |
| Sun | Jre | 1.4.2_3 | — |
| Sun | Jre | 1.4.2_4 | — |
| Sun | Jre | 1.4.2_5 | — |
| Sun | Jre | 1.4.2_6 | — |
| Sun | Jre | 1.4.2_7 | — |
| Sun | Jre | 1.4.2_8 | — |
| Sun | Jre | 1.4.2_9 | — |
| Sun | Jre | 1.4.2_10 | — |
| Sun | Jre | 1.4.2_11 | — |
| Sun | Jre | 1.4.2_12 | — |
| Sun | Jre | 1.4.2_13 | — |
| Sun | Jre | 1.4.2_14 | — |
| Sun | Jre | 1.4.2_15 | — |
| Sun | Jre | 1.4.2_16 | — |
| Sun | Jre | 1.4.2_17 | — |
| Sun | Jre | 5.0 | — |
| Sun | Jre | 6 | — |
| Sun | Sdk | <= 1.4.2_18 | — |
| Sun | Sdk | 1.4.2_1 | — |
| Sun | Sdk | 1.4.2_2 | — |
| Sun | Sdk | 1.4.2_3 | — |
| Sun | Sdk | 1.4.2_4 | — |
| Sun | Sdk | 1.4.2_5 | — |
| Sun | Sdk | 1.4.2_6 | — |
| Sun | Sdk | 1.4.2_7 | — |
| Sun | Sdk | 1.4.2_8 | — |
| Sun | Sdk | 1.4.2_9 | — |
| Sun | Sdk | 1.4.2_10 | — |
| Sun | Sdk | 1.4.2_11 | — |
| Sun | Sdk | 1.4.2_12 | — |
| Sun | Sdk | 1.4.2_13 | — |
| Sun | Sdk | 1.4.2_14 | — |
| Sun | Sdk | 1.4.2_15 | — |
| Sun | Sdk | 1.4.2_16 | — |
| Sun | Sdk | 1.4.2_17 | — |
References
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-244988-1Patch, Vendor Advisory
- http://www.us-cert.gov/cas/techalerts/TA08-340A.htmlUS Government Resource
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-244988-1Patch, Vendor Advisory
- http://www.us-cert.gov/cas/techalerts/TA08-340A.htmlUS Government Resource
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2008-5342?
How severe is CVE-2008-5342?
How do I fix CVE-2008-5342?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2008
- CVE-2008-5336SQL injection vulnerability in index.php in WebStudio CMS al…
- CVE-2008-5337SQL injection vulnerability in lyrics.php in Bandwebsite (ak…
- CVE-2008-5338Cross-site scripting (XSS) vulnerability in info.php in Band…
- CVE-2008-5339Unspecified vulnerability in Java Web Start (JWS) and Java P…
- CVE-2008-5340Unspecified vulnerability in Java Web Start (JWS) and Java P…
- CVE-2008-5341Unspecified vulnerability in Java Web Start (JWS) and Java P…
- CVE-2008-5343Java Web Start (JWS) and Java Plug-in with Sun JDK and JRE 6…
- CVE-2008-5344Unspecified vulnerability in Java Web Start (JWS) and Java P…
- CVE-2008-5345Unspecified vulnerability in Java Runtime Environment (JRE) …
- CVE-2008-5346Unspecified vulnerability in Java Runtime Environment (JRE) …
- CVE-2008-5347Multiple unspecified vulnerabilities in Java Runtime Environ…
- CVE-2008-5348Unspecified vulnerability in Java Runtime Environment (JRE) …
Are you affected by CVE-2008-5342?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
