cbcvebase.
CVE-2007-5237
published 2007-10-06

CVE-2007-5237: Java Web Start in Sun JDK and JRE 6 Update 2 and earlier does not properly enforce access restrictions for untrusted applications, which allows user-assisted…

PriorityP428high7.1CVSS 2.0
AVNACHAuNCCICAN
EPSS
3.29%
87.1th percentile
Java Web Start in Sun JDK and JRE 6 Update 2 and earlier does not properly enforce access restrictions for untrusted applications, which allows user-assisted remote attackers to read and modify local files via an untrusted application, aka "two vulnerabilities."

Affected

2 ranges
VendorProductVersion rangeFixed in
sunjdk<= 1.6.0
sunjre<= 1.6.0

CVSS provenance

nvdv2.07.1HIGHAV:N/AC:H/Au:N/C:C/I:C/A:N
vendor_redhat7.1HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.