← Back

CVE-2007-5238

nvd nist
Published: Oct 6, 2007Modified: Apr 23, 2026

JSON object

Loading...
2.6
Vector
AV:N/AC:H/Au:N/C:P/I:N/A:N
Exploitability: 4.9 / Impact: 2.9
Source: NVD

Description

Java Web Start in Sun JDK and JRE 6 Update 2 and earlier, JDK and JRE 5.0 Update 12 and earlier, and SDK and JRE 1.4.2_15 and earlier does not properly enforce access restrictions for untrusted applications, which allows user-assisted remote attackers to obtain sensitive information (the Java Web Start cache location) via an untrusted application, aka "three vulnerabilities."

Affected (64)

Products: Sun: Jdk, Jre, Sdk
3 products
Jdk
Jre
Sdk
Configuration A
64 vulnerable
Vulnerable SoftwareAffected Versions
Sun
Version 1.5.0 update10
Version 1.5.0 update11
Version 1.5.0 update12
Version 1.5.0 update1
Version 1.5.0 update2
Version 1.5.0 update3
Version 1.5.0 update4
Version 1.5.0 update5
Version 1.5.0 update7
Version 1.5.0 update8
Version 1.5.0 update9
Version 1.6.0 update1
Version 1.6.0 update2
Sun
Version 1.3.0
Version 1.3.0 update5
Version 1.3.1 update16
Version 1.3.1 update18
Version 1.3.1 update19
Version 1.3.1 update1
Version 1.3.1 update1a
Version 1.3.1 update20
Version 1.4.1 update3
Version 1.4.2
Version 1.4.2_10
Version 1.4.2_11
Version 1.4.2_12
Version 1.4.2_13
Version 1.4.2_14
Version 1.4.2_15
Version 1.4.2_1
Version 1.4.2_3
Version 1.4.2_8
Version 1.4.2_9
Version 1.4
Version 1.5.0 update10
Version 1.5.0 update11
Version 1.5.0 update12
Version 1.5.0 update1
Version 1.5.0 update2
Version 1.5.0 update3
Version 1.5.0 update4
Version 1.5.0 update5
Version 1.5.0 update6
Version 1.5.0 update7
Version 1.5.0 update8
Version 1.5.0 update9
Version 1.6.0 update_1
Version 1.6.0 update_2
Sun
Version 1.3.1_01
Version 1.3.1_01a
Version 1.3.1_16
Version 1.3.1_18
Version 1.3.1_19
Version 1.3.1_20
Version 1.4.2
Version 1.4.2_03
Version 1.4.2_08
Version 1.4.2_09
Version 1.4.2_10
Version 1.4.2_11
Version 1.4.2_12
Version 1.4.2_13
Version 1.4.2_14
Version 1.4.2_15

Related CWEs

References (66)

Source: cve@mitre.org
Patch
Source: cve@mitre.org
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.