CVE Vulnerabilities

CVE-2007-4381

Published: Aug 17, 2007 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
9.3 HIGH
AV:N/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Unspecified vulnerability in the font parsing implementation in Sun JDK and JRE 5.0 Update 9 and earlier, and SDK and JRE 1.4.2_14 and earlier, allows remote attackers to perform unauthorized actions via an applet that grants certain privileges to itself.

Affected Software

NameVendorStart VersionEnd Version
JdkSun*1.5.0 (including)
JreSun*1.4.2 (including)
SdkSun*1.4.2_14 (including)
Extras for RHEL 3RedHatjava-1.4.2-bea-0:1.4.2.16-1jpp.1.el3*
Extras for RHEL 3RedHatjava-1.4.2-ibm-0:1.4.2.10-1jpp.2.el3*
Extras for RHEL 4RedHatjava-1.5.0-ibm-1:1.5.0.5-1jpp.2.el4*
Extras for RHEL 4RedHatjava-1.4.2-bea-0:1.4.2.15-1jpp.2.el4*
Extras for RHEL 4RedHatjava-1.4.2-ibm-0:1.4.2.10-1jpp.2.el4*
Supplementary for Red Hat Enterprise Linux 5RedHatjava-1.5.0-ibm-1:1.5.0.5-1jpp.0.1.el5*
Supplementary for Red Hat Enterprise Linux 5RedHatjava-1.5.0-bea-0:1.5.0.11-1jpp.1.el5*
Supplementary for Red Hat Enterprise Linux 5RedHatjava-1.4.2-bea-0:1.4.2.16-1jpp.1.el5*
Supplementary for Red Hat Enterprise Linux 5RedHatjava-1.4.2-ibm-0:1.4.2.10-1jpp.2.el5*
Sun-java5Ubuntudapper*
Sun-java5Ubuntuedgy*

References