← Back

CVE-2007-5274

nvd nist
Published: Oct 8, 2007Modified: Apr 23, 2026

JSON object

Loading...
2.6
Vector
AV:N/AC:H/Au:N/C:N/I:P/A:N
Exploitability: 4.9 / Impact: 2.9
Source: NVD

Description

Sun Java Runtime Environment (JRE) in JDK and JRE 6 Update 2 and earlier, JDK and JRE 5.0 Update 12 and earlier, SDK and JRE 1.4.2_15 and earlier, and SDK and JRE 1.3.1_20 and earlier, when Firefox or Opera is used, allows remote attackers to violate the security model for JavaScript outbound connections via a multi-pin DNS rebinding attack dependent on the LiveConnect API, in which JavaScript download relies on DNS resolution by the browser, but JavaScript socket operations rely on separate DNS resolution by a Java Virtual Machine (JVM), a different issue than CVE-2007-5273. NOTE: this is similar to CVE-2007-5232.

Affected (67)

Products: Sun: Jdk, Jre, Sdk
3 products
Jdk
Jre
Sdk
Configuration A
67 vulnerable · 2 platform
Vulnerable SoftwareAffected Versions
Sun
Up to 1.6.0
Version 1.5.0 update10
Version 1.5.0 update11
Version 1.5.0 update12
Version 1.5.0 update1
Version 1.5.0 update2
Version 1.5.0 update3
Version 1.5.0 update4
Version 1.5.0 update5
Version 1.5.0 update7
Version 1.5.0 update8
Version 1.5.0 update9
Version 1.6.0 update1
Version 1.6.0 update2
Version 6
Version 6 update_1
Sun
Up to 1.4.2
Up to 1.3.1
Up to 1.6.0
Version 1.3.0
Version 1.3.0 update5
Version 1.3.1 update16
Version 1.3.1 update18
Version 1.3.1 update19
Version 1.3.1 update1
Version 1.3.1 update1a
Version 1.4.1 update3
Version 1.4.2
Version 1.4.2_10
Version 1.4.2_11
Version 1.4.2_12
Version 1.4.2_13
Version 1.4.2_14
Version 1.4.2_1
Version 1.4.2_3
Version 1.4.2_8
Version 1.4.2_9
Version 1.4
Version 1.5.0 update10
Version 1.5.0 update11
Version 1.5.0 update12
Version 1.5.0 update1
Version 1.5.0 update2
Version 1.5.0 update3
Version 1.5.0 update4
Version 1.5.0 update5
Version 1.5.0 update6
Version 1.5.0 update7
Version 1.5.0 update8
Version 1.5.0 update9
Version 1.6.0 update_1
Sun
Up to 1.3.1_20
Version 1.3.1_01
Version 1.3.1_01a
Version 1.3.1_16
Version 1.3.1_18
Version 1.3.1_19
Version 1.4.2
Version 1.4.2_03
Version 1.4.2_08
Version 1.4.2_09
Version 1.4.2_10
Version 1.4.2_11
Version 1.4.2_12
Version 1.4.2_13
Version 1.4.2_14
Version 1.4.2_15
Running on/withPlatform Versions
Mozilla
Firefox
All versions
Opera
Opera Browser
All versions

References (68)

Source: cve@mitre.org
Vendor Advisory
Source: cve@mitre.org
Vendor Advisory
Source: cve@mitre.org
Vendor Advisory
Source: cve@mitre.org
Vendor Advisory
Source: cve@mitre.org
Vendor Advisory
Source: cve@mitre.org
Vendor Advisory
Source: cve@mitre.org
Vendor Advisory
Source: cve@mitre.org
Vendor Advisory
Source: cve@mitre.org
Vendor Advisory
Source: cve@mitre.org
Vendor Advisory
Source: cve@mitre.org
Vendor Advisory
Source: cve@mitre.org
Vendor Advisory
Source: cve@mitre.org
Vendor Advisory
Source: cve@mitre.org
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.