Back

CVE-2005-3905

Unspecified vulnerability in reflection APIs in Java SDK and JRE 1.3.1_15 and earlier, 1.4.2_08 and earlier, and JDK and JRE 5.0 Update 3 and earlier allows remote attackers to escape the Java sandbox and access arbitrary files or execute arbitrary application via unknown attack vectors, a different vulnerability than CVE-2005-3906. NOTE: this is associated with the "first issue" identified in SUNALERT:102003.

Published: Nov 30, 2005 Modified: Jun 16, 2026
NVD-CWE-noinfo

CVSS Metrics

Affected Products (122)

Vendor Product Version
sun jdk 1.3
sun jdk 1.3.0_02
sun jdk 1.3.0_02
sun jdk 1.3.0_02
sun jdk 1.3.0_05
sun jdk 1.3.0_05
sun jdk 1.3.1_01
sun jdk 1.3.1_01
sun jdk 1.3.1_01a
sun jdk 1.3.1_02
sun jdk 1.3.1_02
sun jdk 1.3.1_02
sun jdk 1.3.1_03
sun jdk 1.3.1_03
sun jdk 1.3.1_03
sun jdk 1.3.1_04
sun jdk 1.3.1_05
sun jdk 1.3.1_05
sun jdk 1.3.1_05
sun jdk 1.3.1_06

…and 102 more

GitHub Security Advisory GHSA-wf3m-v872-644c

Unspecified vulnerability in reflection APIs in Java SDK and JRE 1.3.1_15 and earlier, 1.4.2_08...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 5.17%

Top 8% most likely to be exploited

Threat Score 31.6 / 100

Data Sources

NVD EPSS GitHub