CVE-2007-5232
published 2007-10-05CVE-2007-5232: Sun Java Runtime Environment (JRE) in JDK and JRE 6 Update 2 and earlier, JDK and JRE 5.0 Update 12 and earlier, SDK and JRE 1.4.2_15 and earlier, and SDK and…
PriorityP421medium4CVSS 2.0
AVNACHAuNCPIPAN
EPSS
3.42%
87.5th percentile
Sun Java Runtime Environment (JRE) in JDK and JRE 6 Update 2 and earlier, JDK and JRE 5.0 Update 12 and earlier, SDK and JRE 1.4.2_15 and earlier, and SDK and JRE 1.3.1_20 and earlier, when applet caching is enabled, allows remote attackers to violate the security model for an applet's outbound connections via a DNS rebinding attack.
Affected
41 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| sun | jdk | <= 1.6.0 | — |
| sun | jdk | — | — |
| sun | jdk | — | — |
| sun | jdk | — | — |
| sun | jre | <= 1.3.1 | — |
| sun | jre | <= 1.4.2 | — |
| sun | jre | <= 1.6.0 | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | sdk | <= 1.3.1_20 | — |
CVSS provenance
nvdv2.04.0MEDIUMAV:N/AC:H/Au:N/C:P/I:P/A:N
vendor_redhat4.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-7mgj-mxcg-g7rv: Sun Java Runtime Environment (JRE) in JDK and JRE 6 Update 2 and earlier, JDK and JRE 5
ghsa_unreviewed·2022-05-01·CVSS 4.0
CVE-2007-5273 [MEDIUM] GHSA-7mgj-mxcg-g7rv: Sun Java Runtime Environment (JRE) in JDK and JRE 6 Update 2 and earlier, JDK and JRE 5
Sun Java Runtime Environment (JRE) in JDK and JRE 6 Update 2 and earlier, JDK and JRE 5.0 Update 12 and earlier, SDK and JRE 1.4.2_15 and earlier, and SDK and JRE 1.3.1_20 and earlier, when an HTTP proxy server is used, allows remote attackers to violate the security model for an applet's outbound connections via a multi-pin DNS rebinding attack in which the applet download relies on DNS resolution on the proxy server, but the applet's socket operations rely on DNS resolution on the local machine, a different issue than CVE-2007-5274. NOTE: this is similar to CVE-2007-5232.
GHSA
GHSA-jx69-94fj-8m45: Sun Java Runtime Environment (JRE) in JDK and JRE 6 Update 2 and earlier, JDK and JRE 5
ghsa_unreviewed·2022-05-01
CVE-2007-5232 [MEDIUM] GHSA-jx69-94fj-8m45: Sun Java Runtime Environment (JRE) in JDK and JRE 6 Update 2 and earlier, JDK and JRE 5
Sun Java Runtime Environment (JRE) in JDK and JRE 6 Update 2 and earlier, JDK and JRE 5.0 Update 12 and earlier, SDK and JRE 1.4.2_15 and earlier, and SDK and JRE 1.3.1_20 and earlier, when applet caching is enabled, allows remote attackers to violate the security model for an applet's outbound connections via a DNS rebinding attack.
GHSA
GHSA-8686-7jv2-5qvr: Sun Java Runtime Environment (JRE) in JDK and JRE 6 Update 2 and earlier, JDK and JRE 5
ghsa_unreviewed·2022-05-01·CVSS 4.0
CVE-2007-5274 [MEDIUM] GHSA-8686-7jv2-5qvr: Sun Java Runtime Environment (JRE) in JDK and JRE 6 Update 2 and earlier, JDK and JRE 5
Sun Java Runtime Environment (JRE) in JDK and JRE 6 Update 2 and earlier, JDK and JRE 5.0 Update 12 and earlier, SDK and JRE 1.4.2_15 and earlier, and SDK and JRE 1.3.1_20 and earlier, when Firefox or Opera is used, allows remote attackers to violate the security model for JavaScript outbound connections via a multi-pin DNS rebinding attack dependent on the LiveConnect API, in which JavaScript download relies on DNS resolution by the browser, but JavaScript socket operations rely on separate DNS resolution by a Java Virtual Machine (JVM), a different issue than CVE-2007-5273. NOTE: this is similar to CVE-2007-5232.
Red Hat
Anti-DNS Pinning and Java Applets with Opera and Firefox
vendor_redhat·2007-10-04·CVSS 4.0
CVE-2007-5274 [MEDIUM] Anti-DNS Pinning and Java Applets with Opera and Firefox
Anti-DNS Pinning and Java Applets with Opera and Firefox
Sun Java Runtime Environment (JRE) in JDK and JRE 6 Update 2 and earlier, JDK and JRE 5.0 Update 12 and earlier, SDK and JRE 1.4.2_15 and earlier, and SDK and JRE 1.3.1_20 and earlier, when Firefox or Opera is used, allows remote attackers to violate the security model for JavaScript outbound connections via a multi-pin DNS rebinding attack dependent on the LiveConnect API, in which JavaScript download relies on DNS resolution by the browser, but JavaScript socket operations rely on separate DNS resolution by a Java Virtual Machine (JVM), a different issue than CVE-2007-5273. NOTE: this is similar to CVE-2007-5232.
Red Hat
Security Vulnerability in Java Runtime Environment With Applet Caching
vendor_redhat·2007-10-03·CVSS 4.0
CVE-2007-5232 [MEDIUM] Security Vulnerability in Java Runtime Environment With Applet Caching
Security Vulnerability in Java Runtime Environment With Applet Caching
Sun Java Runtime Environment (JRE) in JDK and JRE 6 Update 2 and earlier, JDK and JRE 5.0 Update 12 and earlier, SDK and JRE 1.4.2_15 and earlier, and SDK and JRE 1.3.1_20 and earlier, when applet caching is enabled, allows remote attackers to violate the security model for an applet's outbound connections via a DNS rebinding attack.
Red Hat
Anti-DNS Pinning and Java Applets with HTTP proxy
vendor_redhat·2007-07-09·CVSS 4.0
CVE-2007-5273 [MEDIUM] Anti-DNS Pinning and Java Applets with HTTP proxy
Anti-DNS Pinning and Java Applets with HTTP proxy
Sun Java Runtime Environment (JRE) in JDK and JRE 6 Update 2 and earlier, JDK and JRE 5.0 Update 12 and earlier, SDK and JRE 1.4.2_15 and earlier, and SDK and JRE 1.3.1_20 and earlier, when an HTTP proxy server is used, allows remote attackers to violate the security model for an applet's outbound connections via a multi-pin DNS rebinding attack in which the applet download relies on DNS resolution on the proxy server, but the applet's socket operations rely on DNS resolution on the local machine, a different issue than CVE-2007-5274. NOTE: this is similar to CVE-2007-5232.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2007-5274 Anti-DNS Pinning and Java Applets with Opera and Firefox
bugzilla·2007-10-09·CVSS 4.0
CVE-2007-5274 [MEDIUM] CVE-2007-5274 Anti-DNS Pinning and Java Applets with Opera and Firefox
CVE-2007-5274 Anti-DNS Pinning and Java Applets with Opera and Firefox
Sun Java Runtime Environment (JRE) in JDK and JRE 6 Update 2 and
earlier, JDK and JRE 5.0 Update 12 and earlier, SDK and JRE 1.4.2_15
and earlier, and SDK and JRE 1.3.1_20 and earlier, when Firefox or
Opera is used, allows remote attackers to violate the security model
for JavaScript outbound connections via a multi-pin DNS rebinding
attack dependent on the LiveConnect API, in which JavaScript download
relies on DNS resolution by the browser, but JavaScript socket
operations rely on separate DNS resolution by a Java Virtual Machine
(JVM), a different issue than CVE-2007-5273. NOTE: this is similar to
CVE-2007-5232, but affects different product versions.
Discussion:
The list of fixed products with their respective er
Bugzilla
CVE-2007-5273 Anti-DNS Pinning and Java Applets with HTTP proxy
bugzilla·2007-10-09·CVSS 4.0
CVE-2007-5273 [MEDIUM] CVE-2007-5273 Anti-DNS Pinning and Java Applets with HTTP proxy
CVE-2007-5273 Anti-DNS Pinning and Java Applets with HTTP proxy
Sun Java Runtime Environment (JRE) in JDK and JRE 6 Update 2 and
earlier, JDK and JRE 5.0 Update 12 and earlier, SDK and JRE 1.4.2_15
and earlier, and SDK and JRE 1.3.1_20 and earlier, when an HTTP proxy
server is used, allows remote attackers to violate the security model
for an applet's outbound connections via a multi-pin DNS rebinding
attack in which the applet download relies on DNS resolution on the
proxy server, but the applet's socket operations rely on DNS
resolution on the local machine, a different issue than CVE-2007-5274.
NOTE: this is similar to CVE-2007-5232, but affects different product
versions.
Discussion:
The list of fixed products with their respective errata is here:
https://access.redhat.com/security
Bugzilla
CVE-2007-5232 Security Vulnerability in Java Runtime Environment With Applet Caching
bugzilla·2007-10-07·CVSS 4.0
CVE-2007-5232 [MEDIUM] CVE-2007-5232 Security Vulnerability in Java Runtime Environment With Applet Caching
CVE-2007-5232 Security Vulnerability in Java Runtime Environment With Applet Caching
Sun describes a flaw at:
http://sunsolve.sun.com/search/document.do?assetkey=1-26-103079-1
A vulnerability in the Java Runtime Environment (JRE) with applet caching may
allow an untrusted applet that is downloaded from a malicious website to make
network connections to network services on machines other than the one that the
applet was downloaded from. This may allow network resources (such as web pages)
and vulnerabilities (that exist on these network services) which are not
otherwise normally accessible to be accessed or exploited.
Discussion:
The list of fixed products with their respective errata is here:
https://access.redhat.com/security/cve/CVE-2007-5232
http://conference.hitb.org/hitbsecconf2007kl/?page_id=148http://conference.hitb.org/hitbsecconf2007kl/materials/D2T1%20-%20Billy%20Rios%20-%20Slipping%20Past%20the%20Firewall.pdfhttp://dev2dev.bea.com/pub/advisory/272http://docs.info.apple.com/article.html?artnum=307177http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01234533http://lists.apple.com/archives/Security-announce/2007/Dec/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-04/msg00010.htmlhttp://secunia.com/advisories/27206http://secunia.com/advisories/27261http://secunia.com/advisories/27693http://secunia.com/advisories/27716http://secunia.com/advisories/27804http://secunia.com/advisories/28115http://secunia.com/advisories/28777http://secunia.com/advisories/28880http://secunia.com/advisories/29042http://secunia.com/advisories/29214http://secunia.com/advisories/29340http://secunia.com/advisories/29858http://secunia.com/advisories/29897http://secunia.com/advisories/30676http://secunia.com/advisories/30780http://security.gentoo.org/glsa/glsa-200804-28.xmlhttp://sunsolve.sun.com/search/document.do?assetkey=1-26-103079-1http://sunsolve.sun.com/search/document.do?assetkey=1-66-201519-1http://support.novell.com/techcenter/psdb/0c36b6416afc3868b8b1b9012955e323.htmlhttp://www.gentoo.org/security/en/glsa/glsa-200804-20.xmlhttp://www.gentoo.org/security/en/glsa/glsa-200806-11.xmlhttp://www.kb.cert.org/vuls/id/336105http://www.novell.com/linux/security/advisories/2007_55_java.htmlhttp://www.redhat.com/support/errata/RHSA-2007-0963.htmlhttp://www.redhat.com/support/errata/RHSA-2007-1041.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0100.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0132.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0156.htmlhttp://www.securityfocus.com/archive/1/482926/100/0/threadedhttp://www.securityfocus.com/bid/25918http://www.securitytracker.com/id?1018768http://www.vmware.com/security/advisories/VMSA-2008-0010.htmlhttp://www.vupen.com/english/advisories/2007/3895http://www.vupen.com/english/advisories/2007/4224http://www.vupen.com/english/advisories/2008/0609http://www.vupen.com/english/advisories/2008/1856/referenceshttps://exchange.xforce.ibmcloud.com/vulnerabilities/36941https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9331http://conference.hitb.org/hitbsecconf2007kl/?page_id=148http://conference.hitb.org/hitbsecconf2007kl/materials/D2T1%20-%20Billy%20Rios%20-%20Slipping%20Past%20the%20Firewall.pdfhttp://dev2dev.bea.com/pub/advisory/272http://docs.info.apple.com/article.html?artnum=307177http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01234533http://lists.apple.com/archives/Security-announce/2007/Dec/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-04/msg00010.htmlhttp://secunia.com/advisories/27206http://secunia.com/advisories/27261http://secunia.com/advisories/27693http://secunia.com/advisories/27716http://secunia.com/advisories/27804http://secunia.com/advisories/28115http://secunia.com/advisories/28777http://secunia.com/advisories/28880http://secunia.com/advisories/29042http://secunia.com/advisories/29214http://secunia.com/advisories/29340http://secunia.com/advisories/29858http://secunia.com/advisories/29897http://secunia.com/advisories/30676http://secunia.com/advisories/30780http://security.gentoo.org/glsa/glsa-200804-28.xmlhttp://sunsolve.sun.com/search/document.do?assetkey=1-26-103079-1http://sunsolve.sun.com/search/document.do?assetkey=1-66-201519-1http://support.novell.com/techcenter/psdb/0c36b6416afc3868b8b1b9012955e323.htmlhttp://www.gentoo.org/security/en/glsa/glsa-200804-20.xmlhttp://www.gentoo.org/security/en/glsa/glsa-200806-11.xmlhttp://www.kb.cert.org/vuls/id/336105http://www.novell.com/linux/security/advisories/2007_55_java.htmlhttp://www.redhat.com/support/errata/RHSA-2007-0963.htmlhttp://www.redhat.com/support/errata/RHSA-2007-1041.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0100.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0132.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0156.htmlhttp://www.securityfocus.com/archive/1/482926/100/0/threadedhttp://www.securityfocus.com/bid/25918http://www.securitytracker.com/id?1018768http://www.vmware.com/security/advisories/VMSA-2008-0010.htmlhttp://www.vupen.com/english/advisories/2007/3895http://www.vupen.com/english/advisories/2007/4224http://www.vupen.com/english/advisories/2008/0609http://www.vupen.com/english/advisories/2008/1856/referenceshttps://exchange.xforce.ibmcloud.com/vulnerabilities/36941https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9331
2007-10-05
Published