René Helmke 7791f18b51 bootstrap
2023-05-16 16:09:41 +02:00

168 lines
5.3 KiB
JSON

{
"id": "CVE-2008-0657",
"sourceIdentifier": "cve@mitre.org",
"published": "2008-02-07T21:00:00.000",
"lastModified": "2017-09-29T01:30:24.020",
"vulnStatus": "Modified",
"descriptions": [
{
"lang": "en",
"value": "Multiple unspecified vulnerabilities in the Java Runtime Environment in Sun JDK and JRE 6 Update 1 and earlier, and 5.0 Update 13 and earlier, allow context-dependent attackers to gain privileges via an untrusted (1) application or (2) applet, as demonstrated by an application or applet that grants itself privileges to (a) read local files, (b) write to local files, or (c) execute local programs."
},
{
"lang": "es",
"value": "M\u00faltiples vulnerabilidades no especificadas en el Java Runtime Environment en Sun JDK y JRE 6 Update 1 y versiones anteriores y 5.0 Update 13 y versiones anteriores, permite a atacantes seg\u00fan contexto conseguir privilegios a trav\u00e9s de (1) aplicaci\u00f3n o (2) applet no confiables, como se demostr\u00f3 por una aplicaci\u00f3n o applet que garantiza de por s\u00ed privilegios de (a) lectura en archivos locales (b) escritura en archivos locales, o (c) ejecuci\u00f3n de programas locales."
}
],
"metrics": {
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
"accessVector": "NETWORK",
"accessComplexity": "LOW",
"authentication": "NONE",
"confidentialityImpact": "COMPLETE",
"integrityImpact": "COMPLETE",
"availabilityImpact": "COMPLETE",
"baseScore": 10.0
},
"baseSeverity": "HIGH",
"exploitabilityScore": 10.0,
"impactScore": 10.0,
"acInsufInfo": false,
"obtainAllPrivilege": true,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-264"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:sun:jre:*:update13:*:*:*:*:*:*",
"versionEndIncluding": "1.5.0",
"matchCriteriaId": "0284CD7F-4BF7-47EE-A27B-A7A12AD6553D"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:sun:jre:*:update1:*:*:*:*:*:*",
"versionEndIncluding": "1.6.0",
"matchCriteriaId": "2CE4D7F3-A393-40E7-A08D-60527A1658DA"
}
]
}
]
},
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:sun:jdk:*:*:*:*:*:*:*:*",
"versionEndIncluding": "5.0_update13",
"matchCriteriaId": "0346781D-3289-47BB-8D82-D6634F05315F"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:sun:jre:*:update1:*:*:*:*:*:*",
"versionEndIncluding": "1.6.0",
"matchCriteriaId": "2CE4D7F3-A393-40E7-A08D-60527A1658DA"
}
]
}
]
}
],
"references": [
{
"url": "http://dev2dev.bea.com/pub/advisory/277",
"source": "cve@mitre.org"
},
{
"url": "http://lists.opensuse.org/opensuse-security-announce/2008-04/msg00010.html",
"source": "cve@mitre.org"
},
{
"url": "http://security.gentoo.org/glsa/glsa-200804-28.xml",
"source": "cve@mitre.org"
},
{
"url": "http://sunsolve.sun.com/search/document.do?assetkey=1-26-231261-1",
"source": "cve@mitre.org"
},
{
"url": "http://www.gentoo.org/security/en/glsa/glsa-200804-20.xml",
"source": "cve@mitre.org"
},
{
"url": "http://www.gentoo.org/security/en/glsa/glsa-200806-11.xml",
"source": "cve@mitre.org"
},
{
"url": "http://www.redhat.com/support/errata/RHSA-2008-0123.html",
"source": "cve@mitre.org"
},
{
"url": "http://www.redhat.com/support/errata/RHSA-2008-0156.html",
"source": "cve@mitre.org"
},
{
"url": "http://www.redhat.com/support/errata/RHSA-2008-0210.html",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/27650",
"source": "cve@mitre.org"
},
{
"url": "http://www.securitytracker.com/id?1019308",
"source": "cve@mitre.org"
},
{
"url": "http://www.vmware.com/security/advisories/VMSA-2008-0010.html",
"source": "cve@mitre.org"
},
{
"url": "http://www.vupen.com/english/advisories/2008/0429",
"source": "cve@mitre.org"
},
{
"url": "http://www.vupen.com/english/advisories/2008/1252",
"source": "cve@mitre.org"
},
{
"url": "http://www.vupen.com/english/advisories/2008/1856/references",
"source": "cve@mitre.org"
},
{
"url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11505",
"source": "cve@mitre.org"
}
]
}