Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2007-5239

Опубликовано: 06 окт. 2007
Источник: ubuntu
Приоритет: low
EPSS Низкий
CVSS2: 4

Описание

Java Web Start in Sun JDK and JRE 6 Update 2 and earlier, JDK and JRE 5.0 Update 12 and earlier, SDK and JRE 1.4.2_15 and earlier, and SDK and JRE 1.3.1_20 and earlier does not properly enforce access restrictions for untrusted (1) applications and (2) applets, which allows user-assisted remote attackers to copy or rename arbitrary files when local users perform drag-and-drop operations from the untrusted application or applet window onto certain types of desktop applications.

РелизСтатусПримечание
dapper

ignored

end of life
devel

DNE

edgy

ignored

end of life, was needed
feisty

ignored

end of life, was needed
gutsy

released

1.5.0-13-0ubuntu1
hardy

released

1.5.0-13-0ubuntu1
intrepid

released

1.5.0-13-0ubuntu1
jaunty

released

1.5.0-13-0ubuntu1
karmic

DNE

upstream

released

5.0 Update 13

Показывать по

РелизСтатусПримечание
dapper

DNE

devel

released

6-03-0ubuntu2
edgy

DNE

feisty

ignored

end of life, was needed
gutsy

released

6-03-0ubuntu2
hardy

released

6-03-0ubuntu2
intrepid

released

6-03-0ubuntu2
jaunty

released

6-03-0ubuntu2
karmic

released

6-03-0ubuntu2
upstream

released

6 Update 3

Показывать по

Ссылки на источники

EPSS

Процентиль: 81%
0.01538
Низкий

4 Medium

CVSS2

Связанные уязвимости

redhat
почти 18 лет назад

Java Web Start in Sun JDK and JRE 6 Update 2 and earlier, JDK and JRE 5.0 Update 12 and earlier, SDK and JRE 1.4.2_15 and earlier, and SDK and JRE 1.3.1_20 and earlier does not properly enforce access restrictions for untrusted (1) applications and (2) applets, which allows user-assisted remote attackers to copy or rename arbitrary files when local users perform drag-and-drop operations from the untrusted application or applet window onto certain types of desktop applications.

nvd
почти 18 лет назад

Java Web Start in Sun JDK and JRE 6 Update 2 and earlier, JDK and JRE 5.0 Update 12 and earlier, SDK and JRE 1.4.2_15 and earlier, and SDK and JRE 1.3.1_20 and earlier does not properly enforce access restrictions for untrusted (1) applications and (2) applets, which allows user-assisted remote attackers to copy or rename arbitrary files when local users perform drag-and-drop operations from the untrusted application or applet window onto certain types of desktop applications.

debian
почти 18 лет назад

Java Web Start in Sun JDK and JRE 6 Update 2 and earlier, JDK and JRE ...

github
больше 3 лет назад

Java Web Start in Sun JDK and JRE 6 Update 2 and earlier, JDK and JRE 5.0 Update 12 and earlier, SDK and JRE 1.4.2_15 and earlier, and SDK and JRE 1.3.1_20 and earlier does not properly enforce access restrictions for untrusted (1) applications and (2) applets, which allows user-assisted remote attackers to copy or rename arbitrary files when local users perform drag-and-drop operations from the untrusted application or applet window onto certain types of desktop applications.

EPSS

Процентиль: 81%
0.01538
Низкий

4 Medium

CVSS2