CVE-2008-5351

Description

Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier accepts UTF-8 encodings that are not the shortest form, which makes it easier for attackers to bypass protection mechanisms for other applications that rely on shortest-form UTF-8 encodings.

Risk Information

Base Score
9.1
MODERATE
Vector
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
EPSS Score
Exploitation Probability
3.276

Associated Vulnerability

VulnerabilityOS Platform
Multiple vulnerabilities affected in Java jdk (x64) 6(x64)Windows
Multiple vulnerabilities affected in Java jdk 6Windows
Multiple vulnerabilities affected in Java jre (x64) 6(x64)Windows
Multiple vulnerabilities affected in Java jre 6Windows

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234