Vulnerability Name: | CVE-2008-3553 (CCN-44437) | ||||||||
Assigned: | 2008-08-07 | ||||||||
Published: | 2008-08-07 | ||||||||
Updated: | 2018-10-11 | ||||||||
Summary: | Multiple unspecified vulnerabilities in Nokia Series 40 3rd edition devices allow remote attackers to execute arbitrary code via unknown vectors, probably related to MIDP privilege escalation and persistent MIDlets, aka "ISSUES 3-10." Note: as of 20080807, the only disclosure is a vague pre-advisory with no actionable information. However, because it is from a company led by a well-known researcher, it is being assigned a CVE identifier for tracking purposes. | ||||||||
CVSS v3 Severity: | 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||
CVSS v2 Severity: | 10.0 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C) 8.1 High (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C/E:U/RL:U/RC:UR)
5.5 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P/E:U/RL:U/RC:UR)
| ||||||||
Vulnerability Type: | CWE-264 | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: CCN Type: BugTraq Mailing List, Thu Aug 07 2008 - 10:26:14 CDT J2ME Security Vulnerabilities 2008 Source: MITRE Type: CNA CVE-2008-3553 Source: CCN Type: Nokia Forum Web site Series 40 Platform Source: CCN Type: OSVDB ID: 50233 Nokia Series 40 Unspecified MIDP Privilege Escalation Source: MISC Type: UNKNOWN http://www.security-explorations.com/n2press.htm Source: MISC Type: UNKNOWN http://www.security-explorations.com/n2srp.htm Source: MISC Type: UNKNOWN http://www.security-explorations.com/n2vendors.htm Source: CCN Type: J2ME Research Report, SE-2008-01 J2ME Security Vulnerabilities 2008 Source: MISC Type: UNKNOWN http://www.security-explorations.com/report_toc.pdf Source: BUGTRAQ Type: UNKNOWN 20080807 [SE-2008-01] J2ME Security Vulnerabilities 2008 Source: BID Type: UNKNOWN 30591 Source: CCN Type: BID-30591 Sun Java Micro Edition (ME) Multiple Unspecified Security-Bypass Vulnerabilities Source: BID Type: UNKNOWN 30592 Source: CCN Type: BID-30592 Nokia Series 40 Multiple Unspecified Unauthorized Access Vulnerabilities Source: XF Type: UNKNOWN nokia-multiple-unspecified-code-execution(44437) Source: XF Type: UNKNOWN nokia-multiple-unspecified-code-execution(44437) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration CCN 1: ![]() | ||||||||
BACK |