10
CVSSv2

CVE-2007-2435

Published: 02/05/2007 Updated: 11/10/2017
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 890
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Sun Java Web Start in JDK and JRE 5.0 Update 10 and previous versions, and Java Web Start in SDK and JRE 1.4.2_13 and previous versions, allows remote malicious users to perform unauthorized actions via an application that grants privileges to itself, related to "Incorrect Use of System Classes" and probably related to support for JNLP files.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

sun jre

sun sdk

sun java enterprise system

References

CWE-264http://sunsolve.sun.com/search/document.do?assetkey=1-26-102881-1http://www.securityfocus.com/bid/23728http://secunia.com/advisories/25069http://www.securitytracker.com/id?1017986http://dev2dev.bea.com/pub/advisory/241http://secunia.com/advisories/25283http://support.avaya.com/elmodocs2/security/ASA-2007-199.htmhttp://www.gentoo.org/security/en/glsa/glsa-200705-23.xmlhttp://security.gentoo.org/glsa/glsa-200706-08.xmlhttp://www.redhat.com/support/errata/RHSA-2007-0817.htmlhttp://www.redhat.com/support/errata/RHSA-2007-0829.htmlhttp://secunia.com/advisories/25413http://secunia.com/advisories/25474http://secunia.com/advisories/25832http://secunia.com/advisories/26311http://secunia.com/advisories/26369http://docs.info.apple.com/article.html?artnum=307177http://lists.apple.com/archives/Security-announce/2007/Dec/msg00001.htmlhttp://secunia.com/advisories/28115http://www.gentoo.org/security/en/glsa/glsa-200804-20.xmlhttp://secunia.com/advisories/29858http://security.gentoo.org/glsa/glsa-200804-28.xmlhttp://www.redhat.com/support/errata/RHSA-2008-0261.htmlhttp://www.gentoo.org/security/en/glsa/glsa-200806-11.xmlhttp://secunia.com/advisories/30780http://www.vupen.com/english/advisories/2007/1814http://www.vupen.com/english/advisories/2007/1598http://www.vupen.com/english/advisories/2007/4224http://osvdb.org/35483https://exchange.xforce.ibmcloud.com/vulnerabilities/33984https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10999https://nvd.nist.gov