PT-2008-5011 · Oracle · Java

Billy Rios

+1

·

Published

2008-09-26

·

Updated

2017-08-08

·

CVE-2008-3638

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Java versions on Apple Mac OS X 10.5.4 and 10.5.5
Description The issue allows remote attackers to execute arbitrary programs by accessing file:// URLs through applets, which are not properly restricted.
Recommendations For Java on Apple Mac OS X 10.5.4 and 10.5.5, consider disabling the execution of applets that access file:// URLs until a patch is available. Restrict access to sensitive files and directories to minimize the risk of exploitation.

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-3638

Affected Products

Java