Unrated severityNVD Advisory· Published Mar 6, 2008· Updated Apr 23, 2026
CVE-2008-1187
CVE-2008-1187
Description
Unspecified vulnerability in Sun Java Runtime Environment (JRE) and JDK 6 Update 4 and earlier, 5.0 Update 14 and earlier, and SDK/JRE 1.4.2_16 and earlier allows remote attackers to cause a denial of service (JRE crash) and possibly execute arbitrary code via unknown vectors related to XSLT transforms.
Affected products
70cpe:2.3:a:sun:jdk:5.0:update_1:*:*:*:*:*:*+ 18 more
- cpe:2.3:a:sun:jdk:5.0:update_1:*:*:*:*:*:*
- cpe:2.3:a:sun:jdk:5.0:update_10:*:*:*:*:*:*
- cpe:2.3:a:sun:jdk:5.0:update_11:*:*:*:*:*:*
- cpe:2.3:a:sun:jdk:5.0:update_12:*:*:*:*:*:*
- cpe:2.3:a:sun:jdk:5.0:update_13:*:*:*:*:*:*
- cpe:2.3:a:sun:jdk:5.0:update_2:*:*:*:*:*:*
- cpe:2.3:a:sun:jdk:5.0:update_3:*:*:*:*:*:*
- cpe:2.3:a:sun:jdk:5.0:update_4:*:*:*:*:*:*
- cpe:2.3:a:sun:jdk:5.0:update_5:*:*:*:*:*:*
- cpe:2.3:a:sun:jdk:5.0:update_6:*:*:*:*:*:*
- cpe:2.3:a:sun:jdk:5.0:update_7:*:*:*:*:*:*
- cpe:2.3:a:sun:jdk:5.0:update_8:*:*:*:*:*:*
- cpe:2.3:a:sun:jdk:5.0:update_9:*:*:*:*:*:*
- cpe:2.3:a:sun:jdk:6:*:*:*:*:*:*:*
- cpe:2.3:a:sun:jdk:6:update_1:*:*:*:*:*:*
- cpe:2.3:a:sun:jdk:6:update_2:*:*:*:*:*:*
- cpe:2.3:a:sun:jdk:6:update_3:*:*:*:*:*:*
- cpe:2.3:a:sun:jdk:*:update_14:*:*:*:*:*:*range: <=5.0
- cpe:2.3:a:sun:jdk:*:update_4:*:*:*:*:*:*range: <=6
cpe:2.3:a:sun:jre:*:*:*:*:*:*:*:*+ 32 more
- cpe:2.3:a:sun:jre:*:*:*:*:*:*:*:*range: <=1.4.2_14
- cpe:2.3:a:sun:jre:1.4.2_01:*:*:*:*:*:*:*
- cpe:2.3:a:sun:jre:1.4.2_02:*:*:*:*:*:*:*
- cpe:2.3:a:sun:jre:1.4.2_03:*:*:*:*:*:*:*
- cpe:2.3:a:sun:jre:1.4.2_04:*:*:*:*:*:*:*
- cpe:2.3:a:sun:jre:1.4.2_05:*:*:*:*:*:*:*
- cpe:2.3:a:sun:jre:1.4.2_06:*:*:*:*:*:*:*
- cpe:2.3:a:sun:jre:1.4.2_07:*:*:*:*:*:*:*
- cpe:2.3:a:sun:jre:1.4.2_1:*:*:*:*:*:*:*
- cpe:2.3:a:sun:jre:1.4.2_10:*:*:*:*:*:*:*
- cpe:2.3:a:sun:jre:1.4.2_11:*:*:*:*:*:*:*
- cpe:2.3:a:sun:jre:1.4.2_12:*:*:*:*:*:*:*
- cpe:2.3:a:sun:jre:1.4.2_13:*:*:*:*:*:*:*
- cpe:2.3:a:sun:jre:5.0:*:*:*:*:*:*:*
- cpe:2.3:a:sun:jre:5.0:update_1:*:*:*:*:*:*
- cpe:2.3:a:sun:jre:5.0:update_10:*:*:*:*:*:*
- cpe:2.3:a:sun:jre:5.0:update_11:*:*:*:*:*:*
- cpe:2.3:a:sun:jre:5.0:update_12:*:*:*:*:*:*
- cpe:2.3:a:sun:jre:5.0:update_13:*:*:*:*:*:*
- cpe:2.3:a:sun:jre:5.0:update_2:*:*:*:*:*:*
- cpe:2.3:a:sun:jre:5.0:update_3:*:*:*:*:*:*
- cpe:2.3:a:sun:jre:5.0:update_4:*:*:*:*:*:*
- cpe:2.3:a:sun:jre:5.0:update_5:*:*:*:*:*:*
- cpe:2.3:a:sun:jre:5.0:update_6:*:*:*:*:*:*
- cpe:2.3:a:sun:jre:5.0:update_7:*:*:*:*:*:*
- cpe:2.3:a:sun:jre:5.0:update_8:*:*:*:*:*:*
- cpe:2.3:a:sun:jre:5.0:update_9:*:*:*:*:*:*
- cpe:2.3:a:sun:jre:6:*:*:*:*:*:*:*
- cpe:2.3:a:sun:jre:6:update_1:*:*:*:*:*:*
- cpe:2.3:a:sun:jre:6:update_2:*:*:*:*:*:*
- cpe:2.3:a:sun:jre:6:update_3:*:*:*:*:*:*
- cpe:2.3:a:sun:jre:*:update_14:*:*:*:*:*:*range: <=5.0
- cpe:2.3:a:sun:jre:*:update_4:*:*:*:*:*:*range: <=6
cpe:2.3:a:sun:sdk:*:*:*:*:*:*:*:*+ 17 more
- cpe:2.3:a:sun:sdk:*:*:*:*:*:*:*:*range: <=1.4.2_16
- cpe:2.3:a:sun:sdk:1.4.2:*:*:*:*:*:*:*
- cpe:2.3:a:sun:sdk:1.4.2_01:*:*:*:*:*:*:*
- cpe:2.3:a:sun:sdk:1.4.2_02:*:*:*:*:*:*:*
- cpe:2.3:a:sun:sdk:1.4.2_03:*:*:*:*:*:*:*
- cpe:2.3:a:sun:sdk:1.4.2_04:*:*:*:*:*:*:*
- cpe:2.3:a:sun:sdk:1.4.2_05:*:*:*:*:*:*:*
- cpe:2.3:a:sun:sdk:1.4.2_06:*:*:*:*:*:*:*
- cpe:2.3:a:sun:sdk:1.4.2_07:*:*:*:*:*:*:*
- cpe:2.3:a:sun:sdk:1.4.2_08:*:*:*:*:*:*:*
- cpe:2.3:a:sun:sdk:1.4.2_09:*:*:*:*:*:*:*
- cpe:2.3:a:sun:sdk:1.4.2_1:*:*:*:*:*:*:*
- cpe:2.3:a:sun:sdk:1.4.2_10:*:*:*:*:*:*:*
- cpe:2.3:a:sun:sdk:1.4.2_11:*:*:*:*:*:*:*
- cpe:2.3:a:sun:sdk:1.4.2_12:*:*:*:*:*:*:*
- cpe:2.3:a:sun:sdk:1.4.2_13:*:*:*:*:*:*:*
- cpe:2.3:a:sun:sdk:1.4.2_14:*:*:*:*:*:*:*
- cpe:2.3:a:sun:sdk:1.4.2_15:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
45- download.novell.com/DownloadnvdPatch
- sunsolve.sun.com/search/document.donvdPatchVendor Advisory
- www.vmware.com/security/advisories/VMSA-2008-0010.htmlnvdPatch
- secunia.com/advisories/29239nvdVendor Advisory
- secunia.com/advisories/29273nvdVendor Advisory
- secunia.com/advisories/29498nvdVendor Advisory
- secunia.com/advisories/29582nvdVendor Advisory
- secunia.com/advisories/29841nvdVendor Advisory
- secunia.com/advisories/29858nvdVendor Advisory
- secunia.com/advisories/29897nvdVendor Advisory
- secunia.com/advisories/29999nvdVendor Advisory
- secunia.com/advisories/30003nvdVendor Advisory
- secunia.com/advisories/30676nvdVendor Advisory
- secunia.com/advisories/30780nvdVendor Advisory
- secunia.com/advisories/31067nvdVendor Advisory
- secunia.com/advisories/31497nvdVendor Advisory
- secunia.com/advisories/31580nvdVendor Advisory
- secunia.com/advisories/31586nvdVendor Advisory
- secunia.com/advisories/32018nvdVendor Advisory
- www.vupen.com/english/advisories/2008/0770/referencesnvdVendor Advisory
- www.vupen.com/english/advisories/2008/1252nvdVendor Advisory
- www.vupen.com/english/advisories/2008/1856/referencesnvdVendor Advisory
- www.us-cert.gov/cas/techalerts/TA08-066A.htmlnvdUS Government Resource
- dev2dev.bea.com/pub/advisory/277nvd
- jvn.jp/en/jp/JVN04032535/index.htmlnvd
- jvndb.jvn.jp/ja/contents/2008/JVNDB-2008-000016.htmlnvd
- lists.apple.com/archives/security-announce//2008/Sep/msg00008.htmlnvd
- lists.opensuse.org/opensuse-security-announce/2008-04/msg00000.htmlnvd
- lists.opensuse.org/opensuse-security-announce/2008-04/msg00010.htmlnvd
- security.gentoo.org/glsa/glsa-200804-28.xmlnvd
- support.apple.com/kb/HT3178nvd
- support.apple.com/kb/HT3179nvd
- support.novell.com/docs/Readmes/InfoDocument/patchbuilder/readme_5033642.htmlnvd
- www.gentoo.org/security/en/glsa/glsa-200804-20.xmlnvd
- www.gentoo.org/security/en/glsa/glsa-200806-11.xmlnvd
- www.redhat.com/support/errata/RHSA-2008-0186.htmlnvd
- www.redhat.com/support/errata/RHSA-2008-0210.htmlnvd
- www.redhat.com/support/errata/RHSA-2008-0243.htmlnvd
- www.redhat.com/support/errata/RHSA-2008-0244.htmlnvd
- www.redhat.com/support/errata/RHSA-2008-0245.htmlnvd
- www.redhat.com/support/errata/RHSA-2008-0267.htmlnvd
- www.redhat.com/support/errata/RHSA-2008-0555.htmlnvd
- www.securitytracker.com/idnvd
- exchange.xforce.ibmcloud.com/vulnerabilities/41025nvd
- oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10278nvd
News mentions
0No linked articles in our index yet.