Unspecified vulnerability in the Virtual Machine for Sun Java Runtime...
Vulnerability Description
Unspecified vulnerability in the Virtual Machine for Sun Java Runtime Environment (JRE) and JDK 5.0 Update 13 and earlier, and SDK/JRE 1.4.2_16 and earlier, allows remote attackers to gain privileges via an untrusted application or applet, a different issue than CVE-2008-1185, aka "the second issue."
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2008-1186
Credits & Attribution
No credits recorded in the NVD database.
References
- http://lists.apple.com/archives/security-announce//2008/Sep/msg00008.html
- http://secunia.com/advisories/30676
- http://securitytracker.com/id?1019555
- http://lists.opensuse.org/opensuse-security-announce/2008-04/msg00000.html
- http://secunia.com/advisories/32018
- https://exchange.xforce.ibmcloud.com/vulnerabilities/41025
- http://security.gentoo.org/glsa/glsa-200804-28.xml
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9585
- http://secunia.com/advisories/29239
- http://secunia.com/advisories/29858
- http://www.us-cert.gov/cas/techalerts/TA08-066A.html
- http://support.apple.com/kb/HT3178
- http://secunia.com/advisories/29582
- http://www.vupen.com/english/advisories/2008/0770/references
- http://secunia.com/advisories/30780
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-233321-1
- http://www.vupen.com/english/advisories/2008/1856/references
- http://www.vmware.com/security/advisories/VMSA-2008-0010.html
- http://www.gentoo.org/security/en/glsa/glsa-200804-20.xml
- http://www.gentoo.org/security/en/glsa/glsa-200806-11.xml
- https://exchange.xforce.ibmcloud.com/vulnerabilities/41138
- http://www.redhat.com/support/errata/RHSA-2008-0186.html
- http://support.apple.com/kb/HT3179
- http://secunia.com/advisories/29273
More from sun
View All →Affected Vendor
Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.