CVE-2008-3110

Advisory lineage Upstream: 0 Downstream: 2
Modified
Published: 09 Jul 2008, 23:00
Last modified:07 Aug 2024, 09:28

Vulnerability Summary

Overall Risk (default)
low
18/100
CVSS Score
4.3 MEDIUM
v2.0 (nvd)
EPSS Score
6.25% LOW
6% probability -0.93%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

09 Jul 2008, 23:00
Published
Vulnerability first disclosed
07 Aug 2024, 09:28
Last Modified
Vulnerability information updated

Description

Unspecified vulnerability in scripting language support in Sun Java Runtime Environment (JRE) in JDK and JRE 6 Update 6 and earlier allows remote attackers to obtain sensitive information by using an applet to read information from another applet.

CVSS Metrics

  • v2.0MEDIUMScore: 4.3AV:N/AC:M/Au:N/C:P/I:N/A:N

EPSS Trends

Current EPSS score: 6.25% Percentile: 91%

Techniques & Countermeasures

  • CWE-264Permissions, Privileges, and Access Controls

    Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.

Affected Systems

  • sunjdk

    ≤ 6 | 6:update_1 | 6:update_2 | 6:update_3 | 6:update_4 | 6:update_5

  • sunjre

    ≤ 6 | 6:update_1 | 6:update_2 | 6:update_3 | 6:update_4 | 6:update_5

References (28)