[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250108

 
 

909

 
 

196064

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2007-4381Date: (C)2007-08-17   (M)2023-12-22


Unspecified vulnerability in the font parsing implementation in Sun JDK and JRE 5.0 Update 9 and earlier, and SDK and JRE 1.4.2_14 and earlier, allows remote attackers to perform unauthorized actions via an applet that grants certain privileges to itself.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 9.3
Exploit Score: 8.6
Impact Score: 10.0
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: MEDIUM
Authentication: NONE
Confidentiality: COMPLETE
Integrity: COMPLETE
Availability: COMPLETE
  
Reference:
SECTRACK-1018576
SUNALERT-103024
BID-25340
SECUNIA-26402
SECUNIA-26631
SECUNIA-26933
SECUNIA-27203
SECUNIA-27716
SECUNIA-28056
SECUNIA-28115
SECUNIA-28777
SECUNIA-28880
SECUNIA-29340
SECUNIA-29897
ADV-2007-2910
ADV-2007-3009
ADV-2007-4224
APPLE-SA-2007-12-14
BEA07-177.00
GLSA-200709-15
RHSA-2007:0956
RHSA-2007:1086
RHSA-2008:0100
RHSA-2008:0132
SUSE-SA:2008:025
http://docs.info.apple.com/article.html?artnum=307177
http://support.novell.com/techcenter/psdb/0c36b6416afc3868b8b1b9012955e323.html
oval:org.mitre.oval:def:10290
sun-java-font-privilege-escalation(36061)

CPE    1
cpe:/a:sun:sdk

© SecPod Technologies