Back
CVE-2005-3905
Unspecified vulnerability in reflection APIs in Java SDK and JRE 1.3.1_15 and earlier, 1.4.2_08 and earlier, and JDK and JRE 5.0 Update 3 and earlier allows remote attackers to escape the Java sandbox and access arbitrary files or execute arbitrary application via unknown attack vectors, a different vulnerability than CVE-2005-3906. NOTE: this is associated with the "first issue" identified in SUNALERT:102003.
Published: Nov 30, 2005
Modified: Jun 16, 2026
NVD-CWE-noinfo
CVSS Metrics
Affected Products (122)
| Vendor | Product | Version |
|---|---|---|
| sun | jdk | 1.3 |
| sun | jdk | 1.3.0_02 |
| sun | jdk | 1.3.0_02 |
| sun | jdk | 1.3.0_02 |
| sun | jdk | 1.3.0_05 |
| sun | jdk | 1.3.0_05 |
| sun | jdk | 1.3.1_01 |
| sun | jdk | 1.3.1_01 |
| sun | jdk | 1.3.1_01a |
| sun | jdk | 1.3.1_02 |
| sun | jdk | 1.3.1_02 |
| sun | jdk | 1.3.1_02 |
| sun | jdk | 1.3.1_03 |
| sun | jdk | 1.3.1_03 |
| sun | jdk | 1.3.1_03 |
| sun | jdk | 1.3.1_04 |
| sun | jdk | 1.3.1_05 |
| sun | jdk | 1.3.1_05 |
| sun | jdk | 1.3.1_05 |
| sun | jdk | 1.3.1_06 |
…and 102 more
GitHub Security Advisory GHSA-wf3m-v872-644c
Unspecified vulnerability in reflection APIs in Java SDK and JRE 1.3.1_15 and earlier, 1.4.2_08...
References (32)
- http://lists.apple.com/archives/security-announce/2005/Nov/msg00004.html
- http://secunia.com/advisories/17748 Patch, Vendor Advisory
- http://secunia.com/advisories/17847 Vendor Advisory
- http://secunia.com/advisories/18092 Vendor Advisory
- http://secunia.com/advisories/18435 Vendor Advisory
- http://secunia.com/advisories/18503 Vendor Advisory
- http://securitytracker.com/id?1015280
- http://sunsolve.sun.com/searchproxy/document.do?assetkey=1-26-102003-1 Patch, Vendor Advisory
- http://www-1.ibm.com/support/docview.wss?uid=swg21225628
- http://www.gentoo.org/security/en/glsa/glsa-200601-10.xml
- http://www.kb.cert.org/vuls/id/974188 US Government Resource
- http://www.securityfocus.com/bid/15615
- http://www.vupen.com/english/advisories/2005/2636 Vendor Advisory
- http://www.vupen.com/english/advisories/2005/2675 Vendor Advisory
- http://www.vupen.com/english/advisories/2005/2946 Vendor Advisory
Risk Scores
CVSS Score
7.5 / 10
EPSS Score
5.17%
Top 8% most likely to be exploited
Threat Score
31.6 / 100
Data Sources
NVD
EPSS
GitHub