Unrated severityNVD Advisory· Published Oct 6, 2007· Updated Jun 16, 2026
CVE-2007-5237
CVE-2007-5237
Description
Java Web Start in Sun JDK and JRE 6 Update 2 and earlier does not properly enforce access restrictions for untrusted applications, which allows user-assisted remote attackers to read and modify local files via an untrusted application, aka "two vulnerabilities."
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
6cpe:2.3:a:sun:jdk:*:update2:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:sun:jdk:*:update2:*:*:*:*:*:*range: <=1.6.0
- (no CPE)range: <=6 Update 2
cpe:2.3:a:sun:jre:*:update1:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:sun:jre:*:update1:*:*:*:*:*:*range: <=1.6.0
- cpe:2.3:a:sun:jre:*:update2:*:*:*:*:*:*range: <=1.6.0
- (no CPE)range: <=6 Update 2
- Range: <=6 Update 2
Patches
Vulnerability mechanics
References
21- sunsolve.sun.com/search/document.donvdPatch
- dev2dev.bea.com/pub/advisory/272nvd
- h20000.www2.hp.com/bizsupport/TechSupport/Document.jspnvd
- secunia.com/advisories/27261nvd
- secunia.com/advisories/27693nvd
- secunia.com/advisories/29042nvd
- secunia.com/advisories/29858nvd
- secunia.com/advisories/30676nvd
- secunia.com/advisories/30780nvd
- security.gentoo.org/glsa/glsa-200804-28.xmlnvd
- www.gentoo.org/security/en/glsa/glsa-200804-20.xmlnvd
- www.gentoo.org/security/en/glsa/glsa-200806-11.xmlnvd
- www.novell.com/linux/security/advisories/2007_55_java.htmlnvd
- www.securityfocus.com/bid/25920nvd
- www.securitytracker.com/idnvd
- www.vmware.com/security/advisories/VMSA-2008-0010.htmlnvd
- www.vupen.com/english/advisories/2007/3895nvd
- www.vupen.com/english/advisories/2008/0609nvd
- www.vupen.com/english/advisories/2008/1856/referencesnvd
- exchange.xforce.ibmcloud.com/vulnerabilities/36946nvd
- oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5899nvd
News mentions
0No linked articles in our index yet.