CVE-2007-5689
published 2007-10-29CVE-2007-5689: The Java Virtual Machine (JVM) in Sun Java Runtime Environment (JRE) in SDK and JRE 1.3.x through 1.3.1_20 and 1.4.x through 1.4.2_15, and JDK and JRE 5.x…
PriorityP349critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
4.89%
91.1th percentile
The Java Virtual Machine (JVM) in Sun Java Runtime Environment (JRE) in SDK and JRE 1.3.x through 1.3.1_20 and 1.4.x through 1.4.2_15, and JDK and JRE 5.x through 5.0 Update 12 and 6.x through 6 Update 2, allows remote attackers to execute arbitrary programs, or read or modify arbitrary files, via applets that grant privileges to themselves.
Affected
38 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| sun | jdk | <= 1.6.0 | — |
| sun | jdk | — | — |
| sun | jdk | — | — |
| sun | jre | <= 1.3.1 | — |
| sun | jre | <= 1.4.2 | — |
| sun | jre | <= 1.5.0 | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | sdk | <= 1.4.2_15 | — |
| sun | sdk | — | — |
| sun | sdk | — | — |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vendor_redhat10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
java-jre: Applet Privilege Escalation
vendor_redhat·2007-10-23·CVSS 10.0
CVE-2007-5689 [CRITICAL] java-jre: Applet Privilege Escalation
java-jre: Applet Privilege Escalation
The Java Virtual Machine (JVM) in Sun Java Runtime Environment (JRE) in SDK and JRE 1.3.x through 1.3.1_20 and 1.4.x through 1.4.2_15, and JDK and JRE 5.x through 5.0 Update 12 and 6.x through 6 Update 2, allows remote attackers to execute arbitrary programs, or read or modify arbitrary files, via applets that grant privileges to themselves.
GHSA
GHSA-83vr-hv42-q4v5: The Java Virtual Machine (JVM) in Sun Java Runtime Environment (JRE) in SDK and JRE 1
ghsa_unreviewed·2022-05-01
CVE-2007-5689 [HIGH] GHSA-83vr-hv42-q4v5: The Java Virtual Machine (JVM) in Sun Java Runtime Environment (JRE) in SDK and JRE 1
The Java Virtual Machine (JVM) in Sun Java Runtime Environment (JRE) in SDK and JRE 1.3.x through 1.3.1_20 and 1.4.x through 1.4.2_15, and JDK and JRE 5.x through 5.0 Update 12 and 6.x through 6 Update 2, allows remote attackers to execute arbitrary programs, or read or modify arbitrary files, via applets that grant privileges to themselves.
No detection rules found.
No public exploits indexed.
http://dev2dev.bea.com/pub/advisory/272http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01234533http://osvdb.org/40834http://secunia.com/advisories/27320http://secunia.com/advisories/27693http://secunia.com/advisories/29042http://secunia.com/advisories/29858http://secunia.com/advisories/30676http://secunia.com/advisories/30780http://security.gentoo.org/glsa/glsa-200804-28.xmlhttp://sunsolve.sun.com/search/document.do?assetkey=1-26-103112-1http://support.avaya.com/elmodocs2/security/ASA-2007-480.htmhttp://www.gentoo.org/security/en/glsa/glsa-200804-20.xmlhttp://www.gentoo.org/security/en/glsa/glsa-200806-11.xmlhttp://www.securityfocus.com/bid/26185http://www.securitytracker.com/id?1018847http://www.vmware.com/security/advisories/VMSA-2008-0010.htmlhttp://www.vupen.com/english/advisories/2007/3589http://www.vupen.com/english/advisories/2007/3895http://www.vupen.com/english/advisories/2008/0609http://www.vupen.com/english/advisories/2008/1856/referenceshttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9898http://dev2dev.bea.com/pub/advisory/272http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01234533http://osvdb.org/40834http://secunia.com/advisories/27320http://secunia.com/advisories/27693http://secunia.com/advisories/29042http://secunia.com/advisories/29858http://secunia.com/advisories/30676http://secunia.com/advisories/30780http://security.gentoo.org/glsa/glsa-200804-28.xmlhttp://sunsolve.sun.com/search/document.do?assetkey=1-26-103112-1http://support.avaya.com/elmodocs2/security/ASA-2007-480.htmhttp://www.gentoo.org/security/en/glsa/glsa-200804-20.xmlhttp://www.gentoo.org/security/en/glsa/glsa-200806-11.xmlhttp://www.securityfocus.com/bid/26185http://www.securitytracker.com/id?1018847http://www.vmware.com/security/advisories/VMSA-2008-0010.htmlhttp://www.vupen.com/english/advisories/2007/3589http://www.vupen.com/english/advisories/2007/3895http://www.vupen.com/english/advisories/2008/0609http://www.vupen.com/english/advisories/2008/1856/referenceshttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9898
2007-10-29
Published