5
CVSSv2

CVE-2005-1080

Published: 02/05/2005 Updated: 03/01/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

Directory traversal vulnerability in the Java Archive Tool (Jar) utility in J2SE SDK 1.4.2 and 1.5, and OpenJDK, allows remote malicious users to create or overwrite arbitrary files via a .. (dot dot) in filenames in a .jar file.

Vulnerable Product Search on Vulmon Subscribe to Product

sun sdk 1.4.2

sun sdk 1.5

Vendor Advisories

Debian Bug report logs - #774953 jar(1): directory traversal Package: openjdk-7-jdk; Maintainer for openjdk-7-jdk is OpenJDK Team <openjdk@listslaunchpadnet>; Source for openjdk-7-jdk is src:openjdk-7 (PTS, buildd, popcon) Reported by: Alexander Cherepanov <cherepan@mccmeru> Date: Fri, 9 Jan 2015 12:27:01 UTC Se ...
An off-by-one flaw, leading to a buffer overflow, was found in the font parsing code in the 2D component in OpenJDK A specially crafted font file could possibly cause the Java Virtual Machine to execute arbitrary code, allowing an untrusted Java application or applet to bypass Java sandbox restrictions (CVE-2015-0469) A flaw was found in the way ...
An off-by-one flaw, leading to a buffer overflow, was found in the font parsing code in the 2D component in OpenJDK A specially crafted font file could possibly cause the Java Virtual Machine to execute arbitrary code, allowing an untrusted Java application or applet to bypass Java sandbox restrictions (CVE-2015-0469) A flaw was found in the way ...
An off-by-one flaw, leading to a buffer overflow, was found in the font parsing code in the 2D component in OpenJDK A specially crafted font file could possibly cause the Java Virtual Machine to execute arbitrary code, allowing an untrusted Java application or applet to bypass Java sandbox restrictions (CVE-2015-0469) A flaw was found in the way ...