AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2008-3637

HIGH · CVSS 8.8 EPSS 5.73%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2008-09-26 · Last synced 2026-08-04

CyberRota Analysis

This is a high severity vulnerability with a CVSS score of 8.8. It affects Java. It may be remotely exploitable.

CVE
CVE-2008-3637
Severity
HIGH
CVSS
8.8
EPSS
5.73%
Java

Original NVD Description

The Hash-based Message Authentication Code (HMAC) provider in Java on Apple Mac OS X 10.4.11, 10.5.4, and 10.5.5 uses an uninitialized variable, which allows remote attackers to execute arbitrary code via a crafted applet, related to an "error checking issue."