CVE-2007-5274 - CVE House
Back to Database
Status published Low CVE-2007-5274

Sun Java Runtime Environment (JRE) in JDK and JRE 6...

Vulnerability Description

Sun Java Runtime Environment (JRE) in JDK and JRE 6 Update 2 and earlier, JDK and JRE 5.0 Update 12 and earlier, SDK and JRE 1.4.2_15 and earlier, and SDK and JRE 1.3.1_20 and earlier, when Firefox or Opera is used, allows remote attackers to violate the security model for JavaScript outbound connections via a multi-pin DNS rebinding attack dependent on the LiveConnect API, in which JavaScript download relies on DNS resolution by the browser, but JavaScript socket operations rely on separate DNS resolution by a Java Virtual Machine (JVM), a different issue than CVE-2007-5273. NOTE: this is similar to CVE-2007-5232.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2007-5274

Credits & Attribution

No credits recorded in the NVD database.

References

Affected Vendor

Affected Software

jdk, jre, sdk
Vulnerable Versions:
0, 1.5.0, 1.6.0, 6, 1.3.0, 1.3.1, 1.4, 1.4.1, 1.4.2, 1.4.2_1, 1.4.2_3, 1.4.2_8, 1.4.2_9, 1.4.2_10, 1.4.2_11, 1.4.2_12, 1.4.2_13, 1.4.2_14, 1.3.1_01, 1.3.1_01a, 1.3.1_16, 1.3.1_18, 1.3.1_19, 1.4.2_03, 1.4.2_08, 1.4.2_09, 1.4.2_15

Timeline

Official Publish: October 8th, 2007
Last Modified: August 7th, 2024
Added to House: July 18th, 2026

CVSS Vectors

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.