CVE-2007-4381
Unspecified vulnerability in the font parsing implementation in Sun JDK and JRE 5.0 Update 9 and earlier, and SDK and JRE 1.4.2_14 and earlier, allows remote attackers to perform unauthorized actions via an applet that grants certain privileges to itself.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (5.42%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Unspecified vulnerability in the font parsing implementation in Sun JDK and JRE 5.0 Update 9 and earlier, and SDK and JRE 1.4.2_14 and earlier, allows remote attackers to perform unauthorized actions via an applet that grants certain privileges to itself.
- CVSS 2.0
- 9.3 HIGHAV:N/AC:M/Au:N/C:C/I:C/A:C
- EPSS
- 5.42% probability · 92th percentile
- CISA KEV
- Not listed
- Affected
- sun/jdk · sun/jre · sun/sdk
- Source
- cve@mitre.org
References
- http://dev2dev.bea.com/pub/advisory/248
- http://docs.info.apple.com/article.html?artnum=307177
- http://lists.apple.com/archives/Security-announce/2007/Dec/msg00001.html
- http://lists.opensuse.org/opensuse-security-announce/2008-04/msg00010.html
- http://secunia.com/advisories/26402
- http://secunia.com/advisories/26631
- http://secunia.com/advisories/26933
- http://secunia.com/advisories/27203
- http://secunia.com/advisories/27716
- http://secunia.com/advisories/28056
- http://secunia.com/advisories/28115
- http://secunia.com/advisories/28777
- http://secunia.com/advisories/28880
- http://secunia.com/advisories/29340
- http://secunia.com/advisories/29897
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-103024-1
- http://support.novell.com/techcenter/psdb/0c36b6416afc3868b8b1b9012955e323.html
- http://www.gentoo.org/security/en/glsa/glsa-200709-15.xml
- http://www.redhat.com/support/errata/RHSA-2007-0956.html
- http://www.redhat.com/support/errata/RHSA-2007-1086.html
- http://www.redhat.com/support/errata/RHSA-2008-0100.html
- http://www.redhat.com/support/errata/RHSA-2008-0132.html
- http://www.securityfocus.com/bid/25340
- http://www.securitytracker.com/id?1018576
- http://www.vupen.com/english/advisories/2007/2910
- http://www.vupen.com/english/advisories/2007/3009
- http://www.vupen.com/english/advisories/2007/4224
- https://exchange.xforce.ibmcloud.com/vulnerabilities/36061
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10290
- http://dev2dev.bea.com/pub/advisory/248
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.