9.3
CVSSv2

CVE-2007-4381

Published: 17/08/2007 Updated: 29/09/2017
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 935
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Unspecified vulnerability in the font parsing implementation in Sun JDK and JRE 5.0 Update 9 and previous versions, and SDK and JRE 1.4.2_14 and previous versions, allows remote malicious users to perform unauthorized actions via an applet that grants certain privileges to itself.

Vulnerable Product Search on Vulmon Subscribe to Product

sun jdk

sun jre

sun sdk

Exploits

source: wwwsecurityfocuscom/bid/25340/info The Sun Java Runtime Environment is prone to a remote privilege-escalation vulnerability An attacker can exploit this issue to execute arbitrary code within the context of the user who invoked the Java applet Successfully exploiting this issue may result in the remote compromise of affected co ...

References

NVD-CWE-Otherhttp://sunsolve.sun.com/search/document.do?assetkey=1-26-103024-1http://support.novell.com/techcenter/psdb/0c36b6416afc3868b8b1b9012955e323.htmlhttp://dev2dev.bea.com/pub/advisory/248http://www.gentoo.org/security/en/glsa/glsa-200709-15.xmlhttp://www.redhat.com/support/errata/RHSA-2007-0956.htmlhttp://www.securityfocus.com/bid/25340http://www.securitytracker.com/id?1018576http://secunia.com/advisories/26631http://secunia.com/advisories/26933http://secunia.com/advisories/26402http://secunia.com/advisories/27203http://secunia.com/advisories/27716http://docs.info.apple.com/article.html?artnum=307177http://lists.apple.com/archives/Security-announce/2007/Dec/msg00001.htmlhttp://www.redhat.com/support/errata/RHSA-2007-1086.htmlhttp://secunia.com/advisories/28056http://secunia.com/advisories/28115http://secunia.com/advisories/28777http://www.redhat.com/support/errata/RHSA-2008-0132.htmlhttp://secunia.com/advisories/28880http://www.redhat.com/support/errata/RHSA-2008-0100.htmlhttp://secunia.com/advisories/29340http://lists.opensuse.org/opensuse-security-announce/2008-04/msg00010.htmlhttp://secunia.com/advisories/29897http://www.vupen.com/english/advisories/2007/2910http://www.vupen.com/english/advisories/2007/4224http://www.vupen.com/english/advisories/2007/3009https://exchange.xforce.ibmcloud.com/vulnerabilities/36061https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10290https://nvd.nist.govhttps://www.exploit-db.com/exploits/30502/