CVE-2007-5274
Last modified
CVE-2007-5274 is a vulnerability of currently unknown severity. Sun Java Runtime Environment (JRE) in JDK and JRE 6 Update 2 and earlier, JDK and JRE 5.0 Update 12 and earlier, SDK and JRE 1.4.2_15 and earlier, and SDK and JRE 1.3.1_20 and earlier, when Firefox or Opera is used, allows remote attackers to violate the security model for JavaScript outbound connections via a multi-pin DNS rebinding attack dependent on the LiveConnect API, in which JavaScript download relies on DNS resolution by the browser, but JavaScript socket operations rely on separate DNS resolution by a Java Virtual Machine (JVM), a different issue than CVE-2007-5273. NOTE: this is similar to CVE-2007-5232.. EPSS estimates a 2.68% chance of exploitation in the next 30 days.
Description
Sun Java Runtime Environment (JRE) in JDK and JRE 6 Update 2 and earlier, JDK and JRE 5.0 Update 12 and earlier, SDK and JRE 1.4.2_15 and earlier, and SDK and JRE 1.3.1_20 and earlier, when Firefox or Opera is used, allows remote attackers to violate the security model for JavaScript outbound connections via a multi-pin DNS rebinding attack dependent on the LiveConnect API, in which JavaScript download relies on DNS resolution by the browser, but JavaScript socket operations rely on separate DNS resolution by a Java Virtual Machine (JVM), a different issue than CVE-2007-5273. NOTE: this is similar to CVE-2007-5232.
Metrics
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Sun | Jdk | <= 1.6.0 | Update2 |
| Sun | Jdk | 1.5.0 | Update1 |
| Sun | Jdk | 1.6.0 | Update1 |
| Sun | Jdk | 6 | — |
| Sun | Jre | <= 1.3.1 | Update20 |
| Sun | Jre | <= 1.4.2 | Update15 |
| Sun | Jre | <= 1.6.0 | Update2 |
| Sun | Jre | 1.3.0 | — |
| Sun | Jre | 1.3.1 | Update1 |
| Sun | Jre | 1.4 | — |
| Sun | Jre | 1.4.1 | Update3 |
| Sun | Jre | 1.4.2 | — |
| Sun | Jre | 1.4.2_1 | — |
| Sun | Jre | 1.4.2_3 | — |
| Sun | Jre | 1.4.2_8 | — |
| Sun | Jre | 1.4.2_9 | — |
| Sun | Jre | 1.4.2_10 | — |
| Sun | Jre | 1.4.2_11 | — |
| Sun | Jre | 1.4.2_12 | — |
| Sun | Jre | 1.4.2_13 | — |
| Sun | Jre | 1.4.2_14 | — |
| Sun | Jre | 1.5.0 | Update1 |
| Sun | Jre | 1.6.0 | Update 1 |
| Sun | Sdk | <= 1.3.1_20 | — |
| Sun | Sdk | 1.3.1_01 | — |
| Sun | Sdk | 1.3.1_01a | — |
| Sun | Sdk | 1.3.1_16 | — |
| Sun | Sdk | 1.3.1_18 | — |
| Sun | Sdk | 1.3.1_19 | — |
| Sun | Sdk | 1.4.2 | — |
| Sun | Sdk | 1.4.2_03 | — |
| Sun | Sdk | 1.4.2_08 | — |
| Sun | Sdk | 1.4.2_09 | — |
| Sun | Sdk | 1.4.2_10 | — |
| Sun | Sdk | 1.4.2_11 | — |
| Sun | Sdk | 1.4.2_12 | — |
| Sun | Sdk | 1.4.2_13 | — |
| Sun | Sdk | 1.4.2_14 | — |
| Sun | Sdk | 1.4.2_15 | — |
References
- http://secunia.com/advisories/27206Vendor Advisory
- http://secunia.com/advisories/27261Vendor Advisory
- http://secunia.com/advisories/27693Vendor Advisory
- http://secunia.com/advisories/27716Vendor Advisory
- http://secunia.com/advisories/27804Vendor Advisory
- http://secunia.com/advisories/28777Vendor Advisory
- http://secunia.com/advisories/28880Vendor Advisory
- http://secunia.com/advisories/29042Vendor Advisory
- http://secunia.com/advisories/29858Vendor Advisory
- http://secunia.com/advisories/29897Vendor Advisory
- http://secunia.com/advisories/30676Vendor Advisory
- http://secunia.com/advisories/30780Vendor Advisory
- http://www.vupen.com/english/advisories/2007/3895Vendor Advisory
- http://www.vupen.com/english/advisories/2008/0609Vendor Advisory
- http://www.vupen.com/english/advisories/2008/1856/referencesVendor Advisory
- http://secunia.com/advisories/27206Vendor Advisory
- http://secunia.com/advisories/27261Vendor Advisory
- http://secunia.com/advisories/27693Vendor Advisory
- http://secunia.com/advisories/27716Vendor Advisory
- http://secunia.com/advisories/27804Vendor Advisory
- http://secunia.com/advisories/28777Vendor Advisory
- http://secunia.com/advisories/28880Vendor Advisory
- http://secunia.com/advisories/29042Vendor Advisory
- http://secunia.com/advisories/29858Vendor Advisory
- http://secunia.com/advisories/29897Vendor Advisory
- http://secunia.com/advisories/30676Vendor Advisory
- http://secunia.com/advisories/30780Vendor Advisory
- http://www.vupen.com/english/advisories/2007/3895Vendor Advisory
- http://www.vupen.com/english/advisories/2008/0609Vendor Advisory
- http://www.vupen.com/english/advisories/2008/1856/referencesVendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2007-5274?
How severe is CVE-2007-5274?
How do I fix CVE-2007-5274?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2007
- CVE-2007-5268pngrtran.c in libpng before 1.0.29 and 1.2.x before 1.2.21 u…
- CVE-2007-5269Certain chunk handlers in libpng before 1.0.29 and 1.2.x bef…
- CVE-2007-5270Unspecified vulnerability in the Boost module before 4.7.x-1…
- CVE-2007-5271Multiple PHP remote file inclusion vulnerabilities in Trioni…
- CVE-2007-5272SQL injection vulnerability in kategori.asp in Furkan Tastan…
- CVE-2007-5273Sun Java Runtime Environment (JRE) in JDK and JRE 6 Update 2…
- CVE-2007-5275The Adobe Macromedia Flash 9 plug-in allows remote attackers…
- CVE-2007-5276Opera 9 drops DNS pins based on failed connections to irrele…
- CVE-2007-5277Microsoft Internet Explorer 6 drops DNS pins based on failed…
- CVE-2007-5278Zomplog 3.8.1 and earlier stores potentially sensitive infor…
- CVE-2007-5279Heap-based buffer overflow in ConeXware PowerArchiver before…
- CVE-2007-5280Multiple cross-site scripting (XSS) vulnerabilities in messa…
Are you affected by CVE-2007-5274?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
