cbcvebase.
CVE-2007-3922
published 2007-07-21

CVE-2007-3922: Unspecified vulnerability in the Java Runtime Environment (JRE) Applet Class Loader in Sun JDK and JRE 5.0 Update 11 and earlier, 6 through 6 Update 1, and SDK…

PriorityP432medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
2.87%
85.2th percentile
Unspecified vulnerability in the Java Runtime Environment (JRE) Applet Class Loader in Sun JDK and JRE 5.0 Update 11 and earlier, 6 through 6 Update 1, and SDK and JRE 1.4.2_14 and earlier, allows remote attackers to violate the security model for an applet's outbound connections by connecting to certain localhost services running on the machine that loaded the applet.

Affected

5 ranges
VendorProductVersion rangeFixed in
sunjdk<= 1.5.0
sunjdk<= 1.6.0
sunjre<= 1.5.0
sunjre<= 1.6.0
sunsdk<= 1.4.2_14

CVSS provenance

nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.