Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2008-5357

Опубликовано: 05 дек. 2008
Источник: ubuntu
Приоритет: low
EPSS Низкий
CVSS2: 9.3

Описание

Integer overflow in Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; SDK and JRE 1.4.2_18 and earlier; and SDK and JRE 1.3.1_23 and earlier might allow remote attackers to execute arbitrary code via a crafted TrueType font file, which triggers a heap-based buffer overflow.

РелизСтатусПримечание
dapper

DNE

devel

not-affected

6b14-0ubuntu4
gutsy

DNE

hardy

not-affected

code not present
intrepid

not-affected

code not present
jaunty

not-affected

6b14-0ubuntu4
karmic

not-affected

6b14-0ubuntu4
upstream

needs-triage

Показывать по

РелизСтатусПримечание
dapper

ignored

end of life
devel

DNE

gutsy

ignored

end of life, was needed
hardy

released

1.5.0-22-0ubuntu0.8.04
intrepid

released

1.5.0-19-0ubuntu0.8.10
jaunty

released

1.5.0-19-0ubuntu0.9.04
karmic

DNE

upstream

needs-triage

Показывать по

РелизСтатусПримечание
dapper

DNE

devel

released

6.19-0ubuntu1
gutsy

ignored

end of life, was needed
hardy

released

6-17-0ubuntu1.8.04
intrepid

released

6-14-0ubuntu1.8.10
jaunty

released

6-16-0ubuntu1.9.04
karmic

released

6-15-1
upstream

needs-triage

Показывать по

Ссылки на источники

EPSS

Процентиль: 92%
0.07609
Низкий

9.3 Critical

CVSS2

Связанные уязвимости

redhat
около 17 лет назад

Integer overflow in Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; SDK and JRE 1.4.2_18 and earlier; and SDK and JRE 1.3.1_23 and earlier might allow remote attackers to execute arbitrary code via a crafted TrueType font file, which triggers a heap-based buffer overflow.

nvd
около 17 лет назад

Integer overflow in Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; SDK and JRE 1.4.2_18 and earlier; and SDK and JRE 1.3.1_23 and earlier might allow remote attackers to execute arbitrary code via a crafted TrueType font file, which triggers a heap-based buffer overflow.

debian
около 17 лет назад

Integer overflow in Java Runtime Environment (JRE) for Sun JDK and JRE ...

github
больше 3 лет назад

Integer overflow in Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; SDK and JRE 1.4.2_18 and earlier; and SDK and JRE 1.3.1_23 and earlier might allow remote attackers to execute arbitrary code via a crafted TrueType font file, which triggers a heap-based buffer overflow.

EPSS

Процентиль: 92%
0.07609
Низкий

9.3 Critical

CVSS2