Bugsalert.com
Security News about Viruses, Spyware,
Trojans, Malware, XSS attacks.

CVE-2008-0628 (JDK, JRE)

BugsAlert Home > CVE-2008-0628 (JDK, JRE)
 
 

The XML parsing code in Sun Java Runtime Environment JDK and JRE 6 Update 3 and earlier processes external entity references even when the "external general entities" property is false, which allows remote attackers to conduct XML external entity (XXE) attacks and cause a denial of service or access restricted resources.




Original Source: http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-0628

Learn more about CVE-2008-0628 (JDK, JRE)
 
Tags: cve-2008-0628 jdk jre

Related Items

      CVE-2008-1000

      CVE-2008-2652 (smeweb)

      Windows Vista "NoDriveTypeAutoRun" Security Issue

      FrSIRT - freeSSHd SFTP Directory Name Buffer Overflow Vulnerability

      Squid Cache Update Reply Processing Denial of Service Vulnerability

      CVE-2008-3688 (http_antivirus_proxy, havp)

      CVE-2008-1771 (fireflymediaserver)

 

Pixel