[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250363

 
 

909

 
 

196124

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2005-3906Date: (C)2005-11-30   (M)2023-12-22


Multiple unspecified vulnerabilities in reflection APIs in Java SDK and JRE 1.4.2_08 and earlier and JDK and JRE 5.0 Update 3 and earlier allow remote attackers to escape the Java sandbox and access arbitrary files or execute arbitrary applications via unknown attack vectors, a different set of vulnerabilities than CVE-2005-3905. NOTE: this is associated with the "second and third issues" identified in SUNALERT:102003.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 7.5
Exploit Score: 10.0
Impact Score: 6.4
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: LOW
Authentication: NONE
Confidentiality: PARTIAL
Integrity: PARTIAL
Availability: PARTIAL
  
Reference:
SECTRACK-1015280
SUNALERT-102003
BID-15615
SECUNIA-17748
SECUNIA-17847
SECUNIA-18092
SECUNIA-18435
SECUNIA-18503
ADV-2005-2636
ADV-2005-2675
ADV-2005-2946
APPLE-SA-2005-11-30
GLSA-200601-10
VU#974188
http://www-1.ibm.com/support/docview.wss?uid=swg21225628
sun-reflection-api-elevate-privileges(23251)

CPE    26
cpe:/a:sun:jre:1.5.0
cpe:/a:sun:jre:1.4.2_8
cpe:/a:sun:jre:1.4.2_7
cpe:/a:sun:jre:1.4.2_6
...

© SecPod Technologies