CVE-2007-5689

Sun JDK < 1.6.0 and JRE < 1.3.1/1.4.2/1.5.0 - Remote Code Execution via Applet Privilege Escalation

Title source: manual
STIX 2.1

Description

The Java Virtual Machine (JVM) in Sun Java Runtime Environment (JRE) in SDK and JRE 1.3.x through 1.3.1_20 and 1.4.x through 1.4.2_15, and JDK and JRE 5.x through 5.0 Update 12 and 6.x through 6 Update 2, allows remote attackers to execute arbitrary programs, or read or modify arbitrary files, via applets that grant privileges to themselves.

References (22)

Core 22
Core References
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2007/3895
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/30676
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/29042
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/27693
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1018847
Patch vendor-advisory x_refsource_sunalert
http://sunsolve.sun.com/search/document.do?assetkey=1-26-103112-1
Patch, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/27320
Third Party Advisory vendor-advisory x_refsource_gentoo
http://security.gentoo.org/glsa/glsa-200804-28.xml
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/29858
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2008/0609
Vendor Advisory vendor-advisory x_refsource_bea
http://dev2dev.bea.com/pub/advisory/272
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/26185
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/30780
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2008/1856/references
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/40834
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9898
Third Party Advisory vendor-advisory x_refsource_gentoo
http://www.gentoo.org/security/en/glsa/glsa-200804-20.xml
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2007/3589
Third Party Advisory vendor-advisory x_refsource_gentoo
http://www.gentoo.org/security/en/glsa/glsa-200806-11.xml

Scores

EPSS 0.0982
EPSS Percentile 93.1%

Details

Status published
Products (24)
sun/jdk 1.5.0 update1 (11 CPE variants)
sun/jdk 1.6.0 update1
sun/jdk < 1.6.0
sun/jre 1.3.0 (2 CPE variants)
sun/jre 1.3.1 update1 (5 CPE variants)
sun/jre 1.4
sun/jre 1.4.1 update3
sun/jre 1.4.2
sun/jre 1.4.2_1
sun/jre 1.4.2_3
... and 14 more
Published Oct 29, 2007
Tracked Since Feb 18, 2026