CVE-2007-3922
published 2007-07-21CVE-2007-3922: Unspecified vulnerability in the Java Runtime Environment (JRE) Applet Class Loader in Sun JDK and JRE 5.0 Update 11 and earlier, 6 through 6 Update 1, and SDK…
PriorityP432medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
2.87%
85.2th percentile
Unspecified vulnerability in the Java Runtime Environment (JRE) Applet Class Loader in Sun JDK and JRE 5.0 Update 11 and earlier, 6 through 6 Update 1, and SDK and JRE 1.4.2_14 and earlier, allows remote attackers to violate the security model for an applet's outbound connections by connecting to certain localhost services running on the machine that loaded the applet.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| sun | jdk | <= 1.5.0 | — |
| sun | jdk | <= 1.6.0 | — |
| sun | jre | <= 1.5.0 | — |
| sun | jre | <= 1.6.0 | — |
| sun | sdk | <= 1.4.2_14 | — |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-c2xh-7j87-6j25: Unspecified vulnerability in the Java Runtime Environment (JRE) Applet Class Loader in Sun JDK and JRE 5
ghsa_unreviewed·2022-05-01
CVE-2007-3922 [MEDIUM] GHSA-c2xh-7j87-6j25: Unspecified vulnerability in the Java Runtime Environment (JRE) Applet Class Loader in Sun JDK and JRE 5
Unspecified vulnerability in the Java Runtime Environment (JRE) Applet Class Loader in Sun JDK and JRE 5.0 Update 11 and earlier, 6 through 6 Update 1, and SDK and JRE 1.4.2_14 and earlier, allows remote attackers to violate the security model for an applet's outbound connections by connecting to certain localhost services running on the machine that loaded the applet.
Red Hat
Vulnerability in the Java Runtime Environment May Allow an Untrusted Applet to Circumvent Network Access Restrictions
vendor_redhat·2007-07-18·CVSS 6.8
CVE-2007-3922 [MEDIUM] Vulnerability in the Java Runtime Environment May Allow an Untrusted Applet to Circumvent Network Access Restrictions
Vulnerability in the Java Runtime Environment May Allow an Untrusted Applet to Circumvent Network Access Restrictions
Unspecified vulnerability in the Java Runtime Environment (JRE) Applet Class Loader in Sun JDK and JRE 5.0 Update 11 and earlier, 6 through 6 Update 1, and SDK and JRE 1.4.2_14 and earlier, allows remote attackers to violate the security model for an applet's outbound connections by connecting to certain localhost services running on the machine that loaded the applet.
No detection rules found.
No public exploits indexed.
http://dev2dev.bea.com/pub/advisory/248http://docs.info.apple.com/article.html?artnum=307177http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01269450http://lists.apple.com/archives/Security-announce/2007/Dec/msg00001.htmlhttp://secunia.com/advisories/26314http://secunia.com/advisories/26369http://secunia.com/advisories/26631http://secunia.com/advisories/26645http://secunia.com/advisories/26933http://secunia.com/advisories/27266http://secunia.com/advisories/27635http://secunia.com/advisories/28115http://secunia.com/advisories/30805http://slackware.com/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.486841http://sunsolve.sun.com/search/document.do?assetkey=1-26-102995-1http://support.avaya.com/elmodocs2/security/ASA-2007-322.htmhttp://www.gentoo.org/security/en/glsa/glsa-200709-15.xmlhttp://www.novell.com/linux/security/advisories/2007_56_ibmjava.htmlhttp://www.redhat.com/support/errata/RHSA-2007-0818.htmlhttp://www.redhat.com/support/errata/RHSA-2007-0829.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0133.htmlhttp://www.securityfocus.com/bid/25054http://www.securitytracker.com/id?1018428http://www.vupen.com/english/advisories/2007/2573http://www.vupen.com/english/advisories/2007/3009http://www.vupen.com/english/advisories/2007/3861http://www.vupen.com/english/advisories/2007/4224https://exchange.xforce.ibmcloud.com/vulnerabilities/35491https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10387http://dev2dev.bea.com/pub/advisory/248http://docs.info.apple.com/article.html?artnum=307177http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01269450http://lists.apple.com/archives/Security-announce/2007/Dec/msg00001.htmlhttp://secunia.com/advisories/26314http://secunia.com/advisories/26369http://secunia.com/advisories/26631http://secunia.com/advisories/26645http://secunia.com/advisories/26933http://secunia.com/advisories/27266http://secunia.com/advisories/27635http://secunia.com/advisories/28115http://secunia.com/advisories/30805http://slackware.com/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.486841http://sunsolve.sun.com/search/document.do?assetkey=1-26-102995-1http://support.avaya.com/elmodocs2/security/ASA-2007-322.htmhttp://www.gentoo.org/security/en/glsa/glsa-200709-15.xmlhttp://www.novell.com/linux/security/advisories/2007_56_ibmjava.htmlhttp://www.redhat.com/support/errata/RHSA-2007-0818.htmlhttp://www.redhat.com/support/errata/RHSA-2007-0829.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0133.htmlhttp://www.securityfocus.com/bid/25054http://www.securitytracker.com/id?1018428http://www.vupen.com/english/advisories/2007/2573http://www.vupen.com/english/advisories/2007/3009http://www.vupen.com/english/advisories/2007/3861http://www.vupen.com/english/advisories/2007/4224https://exchange.xforce.ibmcloud.com/vulnerabilities/35491https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10387
2007-07-21
Published