CVE-2007-3716
Last modified
CVE-2007-3716 is a vulnerability of currently unknown severity. The Java XML Digital Signature implementation in Sun JDK and JRE 6 before Update 2 does not properly process XSLT stylesheets in XSLT transforms in XML signatures, which allows context-dependent attackers to execute arbitrary code via a crafted stylesheet, a related issue to CVE-2007-3715.. EPSS estimates a 3.55% chance of exploitation in the next 30 days.
Description
The Java XML Digital Signature implementation in Sun JDK and JRE 6 before Update 2 does not properly process XSLT stylesheets in XSLT transforms in XML signatures, which allows context-dependent attackers to execute arbitrary code via a crafted stylesheet, a related issue to CVE-2007-3715.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Sun | Jdk | <= 6 | Update 1 |
| Sun | Jre | <= 6 | Update 1 |
References
- http://secunia.com/advisories/26031Vendor Advisory
- http://secunia.com/advisories/26631Vendor Advisory
- http://secunia.com/advisories/26933Vendor Advisory
- http://www.vupen.com/english/advisories/2007/2492Vendor Advisory
- http://www.vupen.com/english/advisories/2007/3009Vendor Advisory
- http://secunia.com/advisories/26031Vendor Advisory
- http://secunia.com/advisories/26631Vendor Advisory
- http://secunia.com/advisories/26933Vendor Advisory
- http://www.vupen.com/english/advisories/2007/2492Vendor Advisory
- http://www.vupen.com/english/advisories/2007/3009Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2007-3716?
How severe is CVE-2007-3716?
How do I fix CVE-2007-3716?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2007
- CVE-2007-3710PHP remote file inclusion vulnerability in example/gamedemo/…
- CVE-2007-3711Unspecified vulnerability in TOS 2.1.x, 2.2.x before 2.2.5, …
- CVE-2007-3712Multiple cross-site scripting (XSS) vulnerabilities in Hidde…
- CVE-2007-3713Multiple buffer overflows in Konst CenterICQ 4.9.11 through …
- CVE-2007-3714Directory traversal vulnerability in Ada Image Server (ImgSv…
- CVE-2007-3715Sun Java System Application Server and Web Server 7.0 throug…
- CVE-2007-3717rcp on Sun Solaris 8, 9, and 10 before 20070710 does not pro…
- CVE-2007-3718Multiple unspecified vulnerabilities in the SVG parsing engi…
- CVE-2007-3719The process scheduler in the Linux kernel 2.6.16 gives prefe…
- CVE-2007-3720The process scheduler in the Linux kernel 2.4 performs sched…
- CVE-2007-3721The ULE process scheduler in the FreeBSD kernel gives prefer…
- CVE-2007-3722The 4BSD process scheduler in the FreeBSD kernel performs sc…
Are you affected by CVE-2007-3716?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
