Back
CVE-2005-3904
Unspecified vulnerability in Java Management Extensions (JMX) in Java JDK and JRE 5.0 Update 3, 1.4.2 and later, 1.3.1 and later allows remote attackers to escape the Java sandbox and access arbitrary files or execute arbitrary application via unknown attack vectors.
Published: Nov 30, 2005
Modified: Jun 16, 2026
CVSS Metrics
Affected Products (29)
| Vendor | Product | Version |
|---|---|---|
| sun | jdk | 1.5.0_03 |
| sun | jdk | 1.5.0_03 |
| sun | jdk | 1.5.0_03 |
| sun | jre | 1.3.0 |
| sun | jre | 1.3.0 |
| sun | jre | 1.3.0 |
| sun | jre | 1.3.0 |
| sun | jre | 1.3.0 |
| sun | jre | 1.3.0 |
| sun | jre | 1.3.1 |
| sun | jre | 1.3.1 |
| sun | jre | 1.3.1 |
| sun | jre | 1.3.1 |
| sun | jre | 1.3.1 |
| sun | jre | 1.3.1 |
| sun | jre | 1.4.1 |
| sun | jre | 1.4.2 |
| sun | jre | 1.4.2_1 |
| sun | jre | 1.4.2_2 |
| sun | jre | 1.4.2_3 |
…and 9 more
GitHub Security Advisory GHSA-r8qg-vjh8-h4m5
Unspecified vulnerability in Java Management Extensions (JMX) in Java JDK and JRE 5.0 Update 3, 1...
References (28)
- http://lists.apple.com/archives/security-announce/2005/Nov/msg00004.html
- http://secunia.com/advisories/17748 Patch, Vendor Advisory
- http://secunia.com/advisories/17847
- http://secunia.com/advisories/18092
- http://secunia.com/advisories/18503
- http://securitytracker.com/id?1015281
- http://sunsolve.sun.com/searchproxy/document.do?assetkey=1-26-102017-1 Vendor Advisory
- http://www-1.ibm.com/support/docview.wss?uid=swg21225628
- http://www.kb.cert.org/vuls/id/931684 US Government Resource
- http://www.securityfocus.com/bid/15615
- http://www.vupen.com/english/advisories/2005/2636
- http://www.vupen.com/english/advisories/2005/2675
- http://www.vupen.com/english/advisories/2005/2946
- https://exchange.xforce.ibmcloud.com/vulnerabilities/23252
- http://lists.apple.com/archives/security-announce/2005/Nov/msg00004.html
Risk Scores
CVSS Score
7.5 / 10
EPSS Score
5.17%
Top 8% most likely to be exploited
Threat Score
31.6 / 100
Data Sources
NVD
EPSS
GitHub