CVE-2007-5240
published 2007-10-06CVE-2007-5240: Visual truncation vulnerability in the Java Runtime Environment in Sun JDK and JRE 6 Update 2 and earlier, JDK and JRE 5.0 Update 12 and earlier, SDK and JRE…
PriorityP426medium5CVSS 2.0
AVNACLAuNCNIPAN
EPSS
2.96%
85.6th percentile
Visual truncation vulnerability in the Java Runtime Environment in Sun JDK and JRE 6 Update 2 and earlier, JDK and JRE 5.0 Update 12 and earlier, SDK and JRE 1.4.2_15 and earlier, and SDK and JRE 1.3.1_20 and earlier allows remote attackers to circumvent display of the untrusted-code warning banner by creating a window larger than the workstation screen.
Affected
35 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| sun | jdk | — | — |
| sun | jdk | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | sdk | — | — |
| sun | sdk | — | — |
| sun | sdk | — | — |
| sun | sdk | — | — |
| sun | sdk | — | — |
| sun | sdk | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-9xph-fqp4-xrxv: Visual truncation vulnerability in the Java Runtime Environment in Sun JDK and JRE 6 Update 2 and earlier, JDK and JRE 5
ghsa_unreviewed·2022-05-01
CVE-2007-5240 [MEDIUM] GHSA-9xph-fqp4-xrxv: Visual truncation vulnerability in the Java Runtime Environment in Sun JDK and JRE 6 Update 2 and earlier, JDK and JRE 5
Visual truncation vulnerability in the Java Runtime Environment in Sun JDK and JRE 6 Update 2 and earlier, JDK and JRE 5.0 Update 12 and earlier, SDK and JRE 1.4.2_15 and earlier, and SDK and JRE 1.3.1_20 and earlier allows remote attackers to circumvent display of the untrusted-code warning banner by creating a window larger than the workstation screen.
Red Hat
Applets or Applications are allowed to display an oversized window
vendor_redhat·2007-10-03·CVSS 5.0
CVE-2007-5240 [MEDIUM] Applets or Applications are allowed to display an oversized window
Applets or Applications are allowed to display an oversized window
Visual truncation vulnerability in the Java Runtime Environment in Sun JDK and JRE 6 Update 2 and earlier, JDK and JRE 5.0 Update 12 and earlier, SDK and JRE 1.4.2_15 and earlier, and SDK and JRE 1.3.1_20 and earlier allows remote attackers to circumvent display of the untrusted-code warning banner by creating a window larger than the workstation screen.
No detection rules found.
No public exploits indexed.
http://dev2dev.bea.com/pub/advisory/272http://download.novell.com/Download?buildid=q5exhSqeBjA~http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01234533http://lists.opensuse.org/opensuse-security-announce/2008-04/msg00010.htmlhttp://secunia.com/advisories/27206http://secunia.com/advisories/27261http://secunia.com/advisories/27693http://secunia.com/advisories/27716http://secunia.com/advisories/27804http://secunia.com/advisories/28777http://secunia.com/advisories/28880http://secunia.com/advisories/29042http://secunia.com/advisories/29214http://secunia.com/advisories/29340http://secunia.com/advisories/29858http://secunia.com/advisories/29897http://secunia.com/advisories/30676http://secunia.com/advisories/30780http://secunia.com/advisories/31580http://secunia.com/advisories/31586http://security.gentoo.org/glsa/glsa-200804-28.xmlhttp://sunsolve.sun.com/search/document.do?assetkey=1-26-103071-1http://support.novell.com/docs/Readmes/InfoDocument/patchbuilder/readme_5033642.htmlhttp://support.novell.com/techcenter/psdb/0c36b6416afc3868b8b1b9012955e323.htmlhttp://www.gentoo.org/security/en/glsa/glsa-200804-20.xmlhttp://www.gentoo.org/security/en/glsa/glsa-200806-11.xmlhttp://www.novell.com/linux/security/advisories/2007_55_java.htmlhttp://www.redhat.com/support/errata/RHSA-2007-0963.htmlhttp://www.redhat.com/support/errata/RHSA-2007-1041.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0100.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0132.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0156.htmlhttp://www.securityfocus.com/archive/1/482926/100/0/threadedhttp://www.securityfocus.com/bid/25918http://www.securitytracker.com/id?1018769http://www.vmware.com/security/advisories/VMSA-2008-0010.htmlhttp://www.vupen.com/english/advisories/2007/3895http://www.vupen.com/english/advisories/2008/0609http://www.vupen.com/english/advisories/2008/1856/referenceshttps://exchange.xforce.ibmcloud.com/vulnerabilities/36942https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10783http://dev2dev.bea.com/pub/advisory/272http://download.novell.com/Download?buildid=q5exhSqeBjA~http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01234533http://lists.opensuse.org/opensuse-security-announce/2008-04/msg00010.htmlhttp://secunia.com/advisories/27206http://secunia.com/advisories/27261http://secunia.com/advisories/27693http://secunia.com/advisories/27716http://secunia.com/advisories/27804http://secunia.com/advisories/28777http://secunia.com/advisories/28880http://secunia.com/advisories/29042http://secunia.com/advisories/29214http://secunia.com/advisories/29340http://secunia.com/advisories/29858http://secunia.com/advisories/29897http://secunia.com/advisories/30676http://secunia.com/advisories/30780http://secunia.com/advisories/31580http://secunia.com/advisories/31586http://security.gentoo.org/glsa/glsa-200804-28.xmlhttp://sunsolve.sun.com/search/document.do?assetkey=1-26-103071-1http://support.novell.com/docs/Readmes/InfoDocument/patchbuilder/readme_5033642.htmlhttp://support.novell.com/techcenter/psdb/0c36b6416afc3868b8b1b9012955e323.htmlhttp://www.gentoo.org/security/en/glsa/glsa-200804-20.xmlhttp://www.gentoo.org/security/en/glsa/glsa-200806-11.xmlhttp://www.novell.com/linux/security/advisories/2007_55_java.htmlhttp://www.redhat.com/support/errata/RHSA-2007-0963.htmlhttp://www.redhat.com/support/errata/RHSA-2007-1041.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0100.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0132.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0156.htmlhttp://www.securityfocus.com/archive/1/482926/100/0/threadedhttp://www.securityfocus.com/bid/25918http://www.securitytracker.com/id?1018769http://www.vmware.com/security/advisories/VMSA-2008-0010.htmlhttp://www.vupen.com/english/advisories/2007/3895http://www.vupen.com/english/advisories/2008/0609http://www.vupen.com/english/advisories/2008/1856/referenceshttps://exchange.xforce.ibmcloud.com/vulnerabilities/36942https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10783
2007-10-06
Published