PublicDate: 2008-07-09 23:41:00 UTC Candidate: CVE-2008-3104 References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3104 Description: Multiple unspecified vulnerabilities in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 7, JDK and JRE 5.0 before Update 16, SDK and JRE 1.4.x before 1.4.2_18, and SDK and JRE 1.3.x before 1.3.1_23 allow remote attackers to violate the security model for an applet's outbound connections by connecting to localhost services running on the machine that loaded the applet. Ubuntu-Description: Notes: Bugs: Priority: low Discovered-by: Assigned-to: CVSS: Patches_sun-java5: upstream_sun-java5: released (1.5.0-16-1) dapper_sun-java5: ignored (reached end-of-life) feisty_sun-java5: needs-triage (reached end-of-life) gutsy_sun-java5: needs-triage (reached end-of-life) hardy_sun-java5: released (1.5.0-22-0ubuntu0.8.04) intrepid_sun-java5: not-affected (1.5.0-16-2ubuntu1) jaunty_sun-java5: not-affected (1.5.0-16-2ubuntu1) karmic_sun-java5: DNE devel_sun-java5: DNE Patches_sun-java6: upstream_sun-java6: released (6-07-1) dapper_sun-java6: DNE feisty_sun-java6: needs-triage (reached end-of-life) gutsy_sun-java6: needs-triage (reached end-of-life) hardy_sun-java6: released (6-17-0ubuntu1.8.04) intrepid_sun-java6: not-affected (6-07-3ubuntu1) jaunty_sun-java6: not-affected (6-07-3ubuntu1) karmic_sun-java6: not-affected (6-07-3ubuntu1) devel_sun-java6: not-affected (6-07-3ubuntu1)