CVE-2008-3106

critical

Description

Unspecified vulnerability in Sun Java Runtime Environment (JRE) in JDK and JRE 6 Update 6 and earlier and JDK and JRE 5.0 Update 15 and earlier allows remote attackers to access URLs via unknown vectors involving processing of XML data by an untrusted (1) application or (2) applet, a different vulnerability than CVE-2008-3105.

References

https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10866

https://exchange.xforce.ibmcloud.com/vulnerabilities/43658

http://www.vupen.com/english/advisories/2008/2740

http://www.vupen.com/english/advisories/2008/2056/references

http://www.vmware.com/security/advisories/VMSA-2008-0016.html

http://www.us-cert.gov/cas/techalerts/TA08-193A.html

http://www.securitytracker.com/id?1020457

http://www.securityfocus.com/bid/30143

http://www.securityfocus.com/archive/1/497041/100/0/threaded

http://www.redhat.com/support/errata/RHSA-2008-1045.html

http://www.redhat.com/support/errata/RHSA-2008-1044.html

http://www.redhat.com/support/errata/RHSA-2008-0906.html

http://www.redhat.com/support/errata/RHSA-2008-0790.html

http://www.redhat.com/support/errata/RHSA-2008-0594.html

http://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&id=756717

http://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&id=751014

http://support.avaya.com/elmodocs2/security/ASA-2008-509.htm

http://support.avaya.com/elmodocs2/security/ASA-2008-507.htm

http://support.avaya.com/elmodocs2/security/ASA-2008-428.htm

http://support.avaya.com/elmodocs2/security/ASA-2008-299.htm

http://support.apple.com/kb/HT3179

http://sunsolve.sun.com/search/document.do?assetkey=1-66-238628-1

http://security.gentoo.org/glsa/glsa-200911-02.xml

http://secunia.com/advisories/37386

http://secunia.com/advisories/33238

http://secunia.com/advisories/33237

http://secunia.com/advisories/32436

http://secunia.com/advisories/32180

http://secunia.com/advisories/32179

http://secunia.com/advisories/32018

http://secunia.com/advisories/31736

http://secunia.com/advisories/31600

http://secunia.com/advisories/31497

http://secunia.com/advisories/31320

http://secunia.com/advisories/31010

http://marc.info/?l=bugtraq&m=122331139823057&w=2

http://lists.opensuse.org/opensuse-security-announce/2008-09/msg00002.html

http://lists.opensuse.org/opensuse-security-announce/2008-09/msg00000.html

http://lists.opensuse.org/opensuse-security-announce/2008-08/msg00005.html

http://lists.apple.com/archives/security-announce//2008/Sep/msg00007.html

Details

Source: Mitre, NVD

Published: 2008-07-09

Updated: 2018-10-11

Risk Information

CVSS v2

Base Score: 4.3

Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:N/A:N

Severity: Medium

CVSS v3

Base Score: 9.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Severity: Critical