// For flags

CVE-2008-5353

Signed Applet Social Engineering - Code Execution

Severity Score

10.0
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

4
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

The Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier does not properly enforce context of ZoneInfo objects during deserialization, which allows remote attackers to run untrusted applets and applications in a privileged context, as demonstrated by "deserializing Calendar objects".

Vulnerabilidad no especificada en Java Runtime Environment (JRE) en Sun JDK y JRE v6 Update 10 y anteriores; JDK y JRE v5.0 Update 16 y anteriores; y en SDK y JRE v1.4.2_18 y anteriores permite a applets y aplicaciones no confiables obtener privilegios mediante vectores desconocidos relacionados con la "segregaciĆ³n informaciĆ³n de objetos de calendario".

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2008-12-03 First Exploit
  • 2008-12-04 CVE Reserved
  • 2008-12-05 CVE Published
  • 2024-08-07 CVE Updated
  • 2024-08-26 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
CAPEC
References (48)
URL Tag Source
http://blog.cr0.org/2009/05/write-once-own-everyone.html X_refsource_misc
http://landonf.bikemonkey.org/code/macosx/CVE-2008-5353.20090519.html X_refsource_misc
http://osvdb.org/50500 Vdb Entry
http://secunia.com/advisories/32991 Third Party Advisory
http://secunia.com/advisories/33015 Third Party Advisory
http://secunia.com/advisories/33528 Third Party Advisory
http://secunia.com/advisories/33709 Third Party Advisory
http://secunia.com/advisories/33710 Third Party Advisory
http://secunia.com/advisories/34233 Third Party Advisory
http://secunia.com/advisories/34259 Third Party Advisory
http://secunia.com/advisories/34605 Third Party Advisory
http://secunia.com/advisories/34889 Third Party Advisory
http://secunia.com/advisories/34972 Third Party Advisory
http://secunia.com/advisories/35065 Third Party Advisory
http://secunia.com/advisories/35118 Third Party Advisory
http://secunia.com/advisories/37386 Third Party Advisory
http://secunia.com/advisories/38539 Third Party Advisory
http://support.avaya.com/elmodocs2/security/ASA-2009-012.htm X_refsource_confirm
http://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&DocumentOID=829914&poid= X_refsource_confirm
http://www.securityfocus.com/archive/1/503797/100/0/threaded Mailing List
http://www.securityfocus.com/bid/32608 Vdb Entry
http://www.securitytracker.com/id?1021313 Vdb Entry
http://www.us-cert.gov/cas/techalerts/TA08-340A.html Third Party Advisory
http://www.vupen.com/english/advisories/2008/3339 Vdb Entry
http://www.vupen.com/english/advisories/2009/0672 Vdb Entry
http://www.vupen.com/english/advisories/2009/1391 Vdb Entry
http://www116.nortel.com/pub/repository/CLARIFY/DOCUMENT/2009/03/024431-01.pdf X_refsource_confirm
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6511 Signature
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Sun
Search vendor "Sun"
Jdk
Search vendor "Sun" for product "Jdk"
<= 5.0
Search vendor "Sun" for product "Jdk" and version " <= 5.0"
update_16
Affected
Sun
Search vendor "Sun"
Jdk
Search vendor "Sun" for product "Jdk"
<= 6
Search vendor "Sun" for product "Jdk" and version " <= 6"
update_10
Affected
Sun
Search vendor "Sun"
Jdk
Search vendor "Sun" for product "Jdk"
5.0
Search vendor "Sun" for product "Jdk" and version "5.0"
update_1
Affected
Sun
Search vendor "Sun"
Jdk
Search vendor "Sun" for product "Jdk"
5.0
Search vendor "Sun" for product "Jdk" and version "5.0"
update_10
Affected
Sun
Search vendor "Sun"
Jdk
Search vendor "Sun" for product "Jdk"
5.0
Search vendor "Sun" for product "Jdk" and version "5.0"
update_11
Affected
Sun
Search vendor "Sun"
Jdk
Search vendor "Sun" for product "Jdk"
5.0
Search vendor "Sun" for product "Jdk" and version "5.0"
update_12
Affected
Sun
Search vendor "Sun"
Jdk
Search vendor "Sun" for product "Jdk"
5.0
Search vendor "Sun" for product "Jdk" and version "5.0"
update_13
Affected
Sun
Search vendor "Sun"
Jdk
Search vendor "Sun" for product "Jdk"
5.0
Search vendor "Sun" for product "Jdk" and version "5.0"
update_14
Affected
Sun
Search vendor "Sun"
Jdk
Search vendor "Sun" for product "Jdk"
5.0
Search vendor "Sun" for product "Jdk" and version "5.0"
update_15
Affected
Sun
Search vendor "Sun"
Jdk
Search vendor "Sun" for product "Jdk"
5.0
Search vendor "Sun" for product "Jdk" and version "5.0"
update_2
Affected
Sun
Search vendor "Sun"
Jdk
Search vendor "Sun" for product "Jdk"
5.0
Search vendor "Sun" for product "Jdk" and version "5.0"
update_3
Affected
Sun
Search vendor "Sun"
Jdk
Search vendor "Sun" for product "Jdk"
5.0
Search vendor "Sun" for product "Jdk" and version "5.0"
update_4
Affected
Sun
Search vendor "Sun"
Jdk
Search vendor "Sun" for product "Jdk"
5.0
Search vendor "Sun" for product "Jdk" and version "5.0"
update_5
Affected
Sun
Search vendor "Sun"
Jdk
Search vendor "Sun" for product "Jdk"
5.0
Search vendor "Sun" for product "Jdk" and version "5.0"
update_6
Affected
Sun
Search vendor "Sun"
Jdk
Search vendor "Sun" for product "Jdk"
5.0
Search vendor "Sun" for product "Jdk" and version "5.0"
update_7
Affected
Sun
Search vendor "Sun"
Jdk
Search vendor "Sun" for product "Jdk"
5.0
Search vendor "Sun" for product "Jdk" and version "5.0"
update_8
Affected
Sun
Search vendor "Sun"
Jdk
Search vendor "Sun" for product "Jdk"
5.0
Search vendor "Sun" for product "Jdk" and version "5.0"
update_9
Affected
Sun
Search vendor "Sun"
Jdk
Search vendor "Sun" for product "Jdk"
6
Search vendor "Sun" for product "Jdk" and version "6"
-
Affected
Sun
Search vendor "Sun"
Jdk
Search vendor "Sun" for product "Jdk"
6
Search vendor "Sun" for product "Jdk" and version "6"
update_1
Affected
Sun
Search vendor "Sun"
Jdk
Search vendor "Sun" for product "Jdk"
6
Search vendor "Sun" for product "Jdk" and version "6"
update_2
Affected
Sun
Search vendor "Sun"
Jdk
Search vendor "Sun" for product "Jdk"
6
Search vendor "Sun" for product "Jdk" and version "6"
update_3
Affected
Sun
Search vendor "Sun"
Jdk
Search vendor "Sun" for product "Jdk"
6
Search vendor "Sun" for product "Jdk" and version "6"
update_4
Affected
Sun
Search vendor "Sun"
Jdk
Search vendor "Sun" for product "Jdk"
6
Search vendor "Sun" for product "Jdk" and version "6"
update_5
Affected
Sun
Search vendor "Sun"
Jdk
Search vendor "Sun" for product "Jdk"
6
Search vendor "Sun" for product "Jdk" and version "6"
update_6
Affected
Sun
Search vendor "Sun"
Jdk
Search vendor "Sun" for product "Jdk"
6
Search vendor "Sun" for product "Jdk" and version "6"
update_7
Affected
Sun
Search vendor "Sun"
Jdk
Search vendor "Sun" for product "Jdk"
6
Search vendor "Sun" for product "Jdk" and version "6"
update_8
Affected
Sun
Search vendor "Sun"
Jdk
Search vendor "Sun" for product "Jdk"
6
Search vendor "Sun" for product "Jdk" and version "6"
update_9
Affected
Sun
Search vendor "Sun"
Jre
Search vendor "Sun" for product "Jre"
<= 1.4.2_18
Search vendor "Sun" for product "Jre" and version " <= 1.4.2_18"
-
Affected
Sun
Search vendor "Sun"
Jre
Search vendor "Sun" for product "Jre"
<= 5.0
Search vendor "Sun" for product "Jre" and version " <= 5.0"
update_16
Affected
Sun
Search vendor "Sun"
Jre
Search vendor "Sun" for product "Jre"
<= 6
Search vendor "Sun" for product "Jre" and version " <= 6"
update_10
Affected
Sun
Search vendor "Sun"
Jre
Search vendor "Sun" for product "Jre"
1.4.2_1
Search vendor "Sun" for product "Jre" and version "1.4.2_1"
-
Affected
Sun
Search vendor "Sun"
Jre
Search vendor "Sun" for product "Jre"
1.4.2_2
Search vendor "Sun" for product "Jre" and version "1.4.2_2"
-
Affected
Sun
Search vendor "Sun"
Jre
Search vendor "Sun" for product "Jre"
1.4.2_3
Search vendor "Sun" for product "Jre" and version "1.4.2_3"
-
Affected
Sun
Search vendor "Sun"
Jre
Search vendor "Sun" for product "Jre"
1.4.2_4
Search vendor "Sun" for product "Jre" and version "1.4.2_4"
-
Affected
Sun
Search vendor "Sun"
Jre
Search vendor "Sun" for product "Jre"
1.4.2_5
Search vendor "Sun" for product "Jre" and version "1.4.2_5"
-
Affected
Sun
Search vendor "Sun"
Jre
Search vendor "Sun" for product "Jre"
1.4.2_6
Search vendor "Sun" for product "Jre" and version "1.4.2_6"
-
Affected
Sun
Search vendor "Sun"
Jre
Search vendor "Sun" for product "Jre"
1.4.2_7
Search vendor "Sun" for product "Jre" and version "1.4.2_7"
-
Affected
Sun
Search vendor "Sun"
Jre
Search vendor "Sun" for product "Jre"
1.4.2_8
Search vendor "Sun" for product "Jre" and version "1.4.2_8"
-
Affected
Sun
Search vendor "Sun"
Jre
Search vendor "Sun" for product "Jre"
1.4.2_9
Search vendor "Sun" for product "Jre" and version "1.4.2_9"
-
Affected
Sun
Search vendor "Sun"
Jre
Search vendor "Sun" for product "Jre"
1.4.2_10
Search vendor "Sun" for product "Jre" and version "1.4.2_10"
-
Affected
Sun
Search vendor "Sun"
Jre
Search vendor "Sun" for product "Jre"
1.4.2_11
Search vendor "Sun" for product "Jre" and version "1.4.2_11"
-
Affected
Sun
Search vendor "Sun"
Jre
Search vendor "Sun" for product "Jre"
1.4.2_12
Search vendor "Sun" for product "Jre" and version "1.4.2_12"
-
Affected
Sun
Search vendor "Sun"
Jre
Search vendor "Sun" for product "Jre"
1.4.2_13
Search vendor "Sun" for product "Jre" and version "1.4.2_13"
-
Affected
Sun
Search vendor "Sun"
Jre
Search vendor "Sun" for product "Jre"
1.4.2_14
Search vendor "Sun" for product "Jre" and version "1.4.2_14"
-
Affected
Sun
Search vendor "Sun"
Jre
Search vendor "Sun" for product "Jre"
1.4.2_15
Search vendor "Sun" for product "Jre" and version "1.4.2_15"
-
Affected
Sun
Search vendor "Sun"
Jre
Search vendor "Sun" for product "Jre"
1.4.2_16
Search vendor "Sun" for product "Jre" and version "1.4.2_16"
-
Affected
Sun
Search vendor "Sun"
Jre
Search vendor "Sun" for product "Jre"
1.4.2_17
Search vendor "Sun" for product "Jre" and version "1.4.2_17"
-
Affected
Sun
Search vendor "Sun"
Jre
Search vendor "Sun" for product "Jre"
5.0
Search vendor "Sun" for product "Jre" and version "5.0"
-
Affected
Sun
Search vendor "Sun"
Jre
Search vendor "Sun" for product "Jre"
5.0
Search vendor "Sun" for product "Jre" and version "5.0"
update_1
Affected
Sun
Search vendor "Sun"
Jre
Search vendor "Sun" for product "Jre"
5.0
Search vendor "Sun" for product "Jre" and version "5.0"
update_10
Affected
Sun
Search vendor "Sun"
Jre
Search vendor "Sun" for product "Jre"
5.0
Search vendor "Sun" for product "Jre" and version "5.0"
update_11
Affected
Sun
Search vendor "Sun"
Jre
Search vendor "Sun" for product "Jre"
5.0
Search vendor "Sun" for product "Jre" and version "5.0"
update_12
Affected
Sun
Search vendor "Sun"
Jre
Search vendor "Sun" for product "Jre"
5.0
Search vendor "Sun" for product "Jre" and version "5.0"
update_13
Affected
Sun
Search vendor "Sun"
Jre
Search vendor "Sun" for product "Jre"
5.0
Search vendor "Sun" for product "Jre" and version "5.0"
update_14
Affected
Sun
Search vendor "Sun"
Jre
Search vendor "Sun" for product "Jre"
5.0
Search vendor "Sun" for product "Jre" and version "5.0"
update_15
Affected
Sun
Search vendor "Sun"
Jre
Search vendor "Sun" for product "Jre"
5.0
Search vendor "Sun" for product "Jre" and version "5.0"
update_2
Affected
Sun
Search vendor "Sun"
Jre
Search vendor "Sun" for product "Jre"
5.0
Search vendor "Sun" for product "Jre" and version "5.0"
update_3
Affected
Sun
Search vendor "Sun"
Jre
Search vendor "Sun" for product "Jre"
5.0
Search vendor "Sun" for product "Jre" and version "5.0"
update_4
Affected
Sun
Search vendor "Sun"
Jre
Search vendor "Sun" for product "Jre"
5.0
Search vendor "Sun" for product "Jre" and version "5.0"
update_5
Affected
Sun
Search vendor "Sun"
Jre
Search vendor "Sun" for product "Jre"
5.0
Search vendor "Sun" for product "Jre" and version "5.0"
update_6
Affected
Sun
Search vendor "Sun"
Jre
Search vendor "Sun" for product "Jre"
5.0
Search vendor "Sun" for product "Jre" and version "5.0"
update_7
Affected
Sun
Search vendor "Sun"
Jre
Search vendor "Sun" for product "Jre"
5.0
Search vendor "Sun" for product "Jre" and version "5.0"
update_8
Affected
Sun
Search vendor "Sun"
Jre
Search vendor "Sun" for product "Jre"
5.0
Search vendor "Sun" for product "Jre" and version "5.0"
update_9
Affected
Sun
Search vendor "Sun"
Jre
Search vendor "Sun" for product "Jre"
6
Search vendor "Sun" for product "Jre" and version "6"
-
Affected
Sun
Search vendor "Sun"
Jre
Search vendor "Sun" for product "Jre"
6
Search vendor "Sun" for product "Jre" and version "6"
update_1
Affected
Sun
Search vendor "Sun"
Jre
Search vendor "Sun" for product "Jre"
6
Search vendor "Sun" for product "Jre" and version "6"
update_2
Affected
Sun
Search vendor "Sun"
Jre
Search vendor "Sun" for product "Jre"
6
Search vendor "Sun" for product "Jre" and version "6"
update_3
Affected
Sun
Search vendor "Sun"
Jre
Search vendor "Sun" for product "Jre"
6
Search vendor "Sun" for product "Jre" and version "6"
update_4
Affected
Sun
Search vendor "Sun"
Jre
Search vendor "Sun" for product "Jre"
6
Search vendor "Sun" for product "Jre" and version "6"
update_5
Affected
Sun
Search vendor "Sun"
Jre
Search vendor "Sun" for product "Jre"
6
Search vendor "Sun" for product "Jre" and version "6"
update_6
Affected
Sun
Search vendor "Sun"
Jre
Search vendor "Sun" for product "Jre"
6
Search vendor "Sun" for product "Jre" and version "6"
update_7
Affected
Sun
Search vendor "Sun"
Jre
Search vendor "Sun" for product "Jre"
6
Search vendor "Sun" for product "Jre" and version "6"
update_8
Affected
Sun
Search vendor "Sun"
Jre
Search vendor "Sun" for product "Jre"
6
Search vendor "Sun" for product "Jre" and version "6"
update_9
Affected
Sun
Search vendor "Sun"
Sdk
Search vendor "Sun" for product "Sdk"
<= 1.4.2_18
Search vendor "Sun" for product "Sdk" and version " <= 1.4.2_18"
-
Affected
Sun
Search vendor "Sun"
Sdk
Search vendor "Sun" for product "Sdk"
1.4.2_1
Search vendor "Sun" for product "Sdk" and version "1.4.2_1"
-
Affected
Sun
Search vendor "Sun"
Sdk
Search vendor "Sun" for product "Sdk"
1.4.2_2
Search vendor "Sun" for product "Sdk" and version "1.4.2_2"
-
Affected
Sun
Search vendor "Sun"
Sdk
Search vendor "Sun" for product "Sdk"
1.4.2_3
Search vendor "Sun" for product "Sdk" and version "1.4.2_3"
-
Affected
Sun
Search vendor "Sun"
Sdk
Search vendor "Sun" for product "Sdk"
1.4.2_4
Search vendor "Sun" for product "Sdk" and version "1.4.2_4"
-
Affected
Sun
Search vendor "Sun"
Sdk
Search vendor "Sun" for product "Sdk"
1.4.2_5
Search vendor "Sun" for product "Sdk" and version "1.4.2_5"
-
Affected
Sun
Search vendor "Sun"
Sdk
Search vendor "Sun" for product "Sdk"
1.4.2_6
Search vendor "Sun" for product "Sdk" and version "1.4.2_6"
-
Affected
Sun
Search vendor "Sun"
Sdk
Search vendor "Sun" for product "Sdk"
1.4.2_7
Search vendor "Sun" for product "Sdk" and version "1.4.2_7"
-
Affected
Sun
Search vendor "Sun"
Sdk
Search vendor "Sun" for product "Sdk"
1.4.2_8
Search vendor "Sun" for product "Sdk" and version "1.4.2_8"
-
Affected
Sun
Search vendor "Sun"
Sdk
Search vendor "Sun" for product "Sdk"
1.4.2_9
Search vendor "Sun" for product "Sdk" and version "1.4.2_9"
-
Affected
Sun
Search vendor "Sun"
Sdk
Search vendor "Sun" for product "Sdk"
1.4.2_10
Search vendor "Sun" for product "Sdk" and version "1.4.2_10"
-
Affected
Sun
Search vendor "Sun"
Sdk
Search vendor "Sun" for product "Sdk"
1.4.2_11
Search vendor "Sun" for product "Sdk" and version "1.4.2_11"
-
Affected
Sun
Search vendor "Sun"
Sdk
Search vendor "Sun" for product "Sdk"
1.4.2_12
Search vendor "Sun" for product "Sdk" and version "1.4.2_12"
-
Affected
Sun
Search vendor "Sun"
Sdk
Search vendor "Sun" for product "Sdk"
1.4.2_13
Search vendor "Sun" for product "Sdk" and version "1.4.2_13"
-
Affected
Sun
Search vendor "Sun"
Sdk
Search vendor "Sun" for product "Sdk"
1.4.2_14
Search vendor "Sun" for product "Sdk" and version "1.4.2_14"
-
Affected
Sun
Search vendor "Sun"
Sdk
Search vendor "Sun" for product "Sdk"
1.4.2_15
Search vendor "Sun" for product "Sdk" and version "1.4.2_15"
-
Affected
Sun
Search vendor "Sun"
Sdk
Search vendor "Sun" for product "Sdk"
1.4.2_16
Search vendor "Sun" for product "Sdk" and version "1.4.2_16"
-
Affected
Sun
Search vendor "Sun"
Sdk
Search vendor "Sun" for product "Sdk"
1.4.2_17
Search vendor "Sun" for product "Sdk" and version "1.4.2_17"
-
Affected