cbcvebase.
CVE-2007-2788
published 2007-05-22

CVE-2007-2788: Integer overflow in the embedded ICC profile image parser in Sun Java Development Kit (JDK) before 1.5.0_11-b03 and 1.6.x before 1.6.0_01-b06, and Sun Java…

PriorityP346medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EXPLOIT
EPSS
18.19%
96.9th percentile
Integer overflow in the embedded ICC profile image parser in Sun Java Development Kit (JDK) before 1.5.0_11-b03 and 1.6.x before 1.6.0_01-b06, and Sun Java Runtime Environment in JDK and JRE 6, JDK and JRE 5.0 Update 10 and earlier, SDK and JRE 1.4.2_14 and earlier, and SDK and JRE 1.3.1_20 and earlier, allows remote attackers to execute arbitrary code or cause a denial of service (JVM crash) via a crafted JPEG or BMP file that triggers a buffer overflow.

Affected

76 ranges· showing 25
VendorProductVersion rangeFixed in
sunjdk
sunjdk
sunjre
sunjre
sunjre
sunjre
sunjre
sunjre
sunjre
sunjre
sunjre
sunjre
sunjre
sunjre
sunjre
sunjre
sunjre
sunjre
sunjre
sunjre
sunjre
sunjre
sunjre
sunjre
sunjre

Detection & IOCsextracted from sources · hover to see the quote

urlhttps://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/30043.zip
  • Detect delivery of crafted JPEG or BMP files containing malicious embedded ICC profiles targeting Java parsers; monitor for JVM crashes triggered by such files.
  • Flag use of Sun JDK 1.5.0_07-b03 as a known vulnerable version in asset inventory and network traffic (e.g., User-Agent strings or JNLP negotiation).
  • CVE-2007-3004 (IBM JDK ICC profile parser integer overflow) is a duplicate of this CVE; detections for either should be unified under CVE-2007-2788.
  • ·Vulnerability affects multiple JDK/JRE release trains; ensure patching covers all branches: JDK/JRE 6 before 1.6.0_01-b06, JDK/JRE 5.0 Update 10 and earlier, SDK/JRE 1.4.2_14 and earlier, and SDK/JRE 1.3.1_20 and earlier.
  • ·IBM JDK is also affected via the same ICC profile parser integer overflow (originally tracked as CVE-2007-3004, now merged into CVE-2007-2788); IBM JDK deployments must be patched separately.

CVSS provenance

nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vendor_redhat6.8MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.