Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2007-3922

Опубликовано: 21 июл. 2007
Источник: nvd
CVSS2: 6.8
EPSS Низкий

Описание

Unspecified vulnerability in the Java Runtime Environment (JRE) Applet Class Loader in Sun JDK and JRE 5.0 Update 11 and earlier, 6 through 6 Update 1, and SDK and JRE 1.4.2_14 and earlier, allows remote attackers to violate the security model for an applet's outbound connections by connecting to certain localhost services running on the machine that loaded the applet.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:sun:jdk:*:update9:*:*:*:*:*:*
Версия до 1.5.0 (включая)
cpe:2.3:a:sun:jdk:*:update1:*:*:*:*:*:*
Версия до 1.6.0 (включая)
cpe:2.3:a:sun:jre:*:update11:*:*:*:*:*:*
Версия до 1.5.0 (включая)
cpe:2.3:a:sun:jre:*:update1:*:*:*:*:*:*
Версия до 1.6.0 (включая)
cpe:2.3:a:sun:sdk:*:*:*:*:*:*:*:*
Версия до 1.4.2_14 (включая)

EPSS

Процентиль: 88%
0.03737
Низкий

6.8 Medium

CVSS2

Дефекты

NVD-CWE-noinfo

Связанные уязвимости

ubuntu
около 18 лет назад

Unspecified vulnerability in the Java Runtime Environment (JRE) Applet Class Loader in Sun JDK and JRE 5.0 Update 11 and earlier, 6 through 6 Update 1, and SDK and JRE 1.4.2_14 and earlier, allows remote attackers to violate the security model for an applet's outbound connections by connecting to certain localhost services running on the machine that loaded the applet.

redhat
около 18 лет назад

Unspecified vulnerability in the Java Runtime Environment (JRE) Applet Class Loader in Sun JDK and JRE 5.0 Update 11 and earlier, 6 through 6 Update 1, and SDK and JRE 1.4.2_14 and earlier, allows remote attackers to violate the security model for an applet's outbound connections by connecting to certain localhost services running on the machine that loaded the applet.

debian
около 18 лет назад

Unspecified vulnerability in the Java Runtime Environment (JRE) Applet ...

github
больше 3 лет назад

Unspecified vulnerability in the Java Runtime Environment (JRE) Applet Class Loader in Sun JDK and JRE 5.0 Update 11 and earlier, 6 through 6 Update 1, and SDK and JRE 1.4.2_14 and earlier, allows remote attackers to violate the security model for an applet's outbound connections by connecting to certain localhost services running on the machine that loaded the applet.

EPSS

Процентиль: 88%
0.03737
Низкий

6.8 Medium

CVSS2

Дефекты

NVD-CWE-noinfo