10
CVSSv2

CVE-2008-3108

Published: 09/07/2008 Updated: 31/07/2019
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 890
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Buffer overflow in Sun Java Runtime Environment (JRE) in JDK and JRE 5.0 before Update 10, SDK and JRE 1.4.x prior to 1.4.2_18, and SDK and JRE 1.3.x prior to 1.3.1_23 allows context-dependent malicious users to gain privileges via unspecified vectors related to font processing.

Vulnerable Product Search on Vulmon Subscribe to Product

sun jre 1.4.2 7

sun jre 1.4.2 16

sun jre 1.3.1

sun jre 1.3.1 10

sun jre 1.3.1 06

sun jre 1.4.2 4

sun jre 1.4.2 2

sun jre 1.3.1 20

sun jre 1.3.1 22

sun jre 1.5.0

sun jre 1.3.1 2

sun jre 1.4.2 15

sun jre 1.4.2 13

sun jre 1.4.2 1

sun jre 1.4.2 8

sun jre 1.3.1 16

sun jre 1.3.1 19

sun jre 1.3.1 11

sun jre 1.3.1 17

sun jre 1.4.2 12

sun jre 1.3.1 12

sun jre 1.3.1 03

sun jre 1.3.1 14

sun jre 1.3.1 08

sun jre 1.4.2 18

sun jre 1.4.2 14

sun jre 1.3.1 07

sun jre 1.3.1 05

sun jre 1.4.2 10

sun jre 1.4.2 17

sun jre 1.4.2 9

sun jre 1.4.2

sun jre 1.3.1 13

sun jre 1.3.1 04

sun jre 1.3.1 09

sun jre 1.4.2 11

sun jre 1.3.1 18

sun jre 1.3.1 23

sun jre 1.3.1 15

sun jre 1.4.2 3

sun jre 1.4.2 5

sun jre 1.3.1 21

sun jre 1.4.2 6

sun jdk 1.5.0

sun sdk 1.3.1 03

sun sdk 1.3.1 23

sun sdk 1.4.2

sun sdk 1.3.1 19

sun sdk 1.3.1

sun sdk 1.3.1 08

sun sdk 1.4.2 10

sun sdk 1.4.2 12

sun sdk 1.3.1 15

sun sdk 1.4.2 17

sun sdk 1.4.2 14

sun sdk 1.4.2 04

sun sdk 1.4.2 13

sun sdk 1.4.2 6

sun sdk 1.3.1 07

sun sdk 1.4.2 2

sun sdk 1.3.1 10

sun sdk 1.4.2 5

sun sdk 1.3.1 06

sun sdk 1.4.2 1

sun sdk 1.4.2 18

sun sdk 1.3.1 12

sun sdk 1.4.2 4

sun sdk 1.3.1 20

sun sdk 1.3.1 17

sun sdk 1.3.1 02

sun sdk 1.3.1 18

sun sdk 1.3.1 01

sun sdk 1.3.1 16

sun sdk 1.3.1 01a

sun sdk 1.3.1 22

sun sdk 1.3.1 14

sun sdk 1.4.2 7

sun sdk 1.3.1 13

sun sdk 1.4.2 09

sun sdk 1.4.2 8

sun sdk 1.4.2 02

sun sdk 1.4.2 16

sun sdk 1.4.2 11

sun sdk 1.3.1 09

sun sdk 1.4.2 9

sun sdk 1.3.1 04

sun sdk 1.3.1 21

sun sdk 1.4.2 08

sun sdk 1.3.1 05

sun sdk 1.4.2 03

sun sdk 1.4.2 3

sun sdk 1.3.1 11

sun sdk 1.4.2 15

Vendor Advisories

Synopsis Important: java-150-bea security update Type/Severity Security Advisory: Important Topic java-150-bea as shipped in Red Hat Enterprise Linux 4 Extras and Red HatEnterprise Linux 5 Supplementary, contains security flaws and should not beusedThis update has been rated as having important securit ...
Synopsis Important: java-142-bea security update Type/Severity Security Advisory: Important Topic java-142-bea as shipped in Red Hat Enterprise Linux 3 Extras, Red HatEnterprise Linux 4 Extras, and Red Hat Enterprise Linux 5 Supplementary,contains security flaws and should not be usedThis update has be ...

References

CWE-119http://sunsolve.sun.com/search/document.do?assetkey=1-66-238666-1http://www.securityfocus.com/bid/30147http://secunia.com/advisories/31010http://www.redhat.com/support/errata/RHSA-2008-0790.htmlhttp://secunia.com/advisories/31320http://lists.opensuse.org/opensuse-security-announce/2008-08/msg00005.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-09/msg00000.htmlhttp://secunia.com/advisories/31497http://secunia.com/advisories/31600http://www.us-cert.gov/cas/techalerts/TA08-193A.htmlhttp://support.apple.com/kb/HT3178http://secunia.com/advisories/32018http://lists.apple.com/archives/security-announce//2008/Sep/msg00008.htmlhttp://support.apple.com/kb/HT3179http://lists.opensuse.org/opensuse-security-announce/2008-09/msg00002.htmlhttp://secunia.com/advisories/32180http://www.vmware.com/security/advisories/VMSA-2008-0016.htmlhttp://marc.info/?l=bugtraq&m=122331139823057&w=2http://secunia.com/advisories/32179http://www.securitytracker.com/id?1020461http://www.redhat.com/support/errata/RHSA-2008-1044.htmlhttp://www.redhat.com/support/errata/RHSA-2008-1043.htmlhttp://secunia.com/advisories/33237http://secunia.com/advisories/33236http://support.avaya.com/elmodocs2/security/ASA-2008-507.htmhttp://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&id=756717http://support.avaya.com/elmodocs2/security/ASA-2008-300.htmhttp://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&id=751014http://security.gentoo.org/glsa/glsa-200911-02.xmlhttp://secunia.com/advisories/37386http://www.vupen.com/english/advisories/2008/2056/referenceshttp://www.vupen.com/english/advisories/2008/2740http://secunia.com/advisories/31736https://exchange.xforce.ibmcloud.com/vulnerabilities/43656http://www.securityfocus.com/archive/1/497041/100/0/threadedhttps://access.redhat.com/errata/RHSA-2008:1044https://nvd.nist.gov