← back
CVE-2008-5353observed exploitation

CVE-2008-5353

82Vexday Risk Score

Patch now. It exploitation observed by VulnCheck and has a working public exploit.

ssvc Actepss 86%
from disclosure to weapon0 days
Published on NVDDec 5
1st PoCDec 3
metasploitDec 3
VulnCheck+396d
exploitation probability
86%top 1% of all CVEs
observed exploitation
yesVulnCheck
4 public exploit(s)
The Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier does not properly enforce context of ZoneInfo objects during deserialization, which allows remote attackers to run untrusted applets and applications in a privileged context, as demonstrated by "deserializing Calendar objects".
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.