CVE-2007-2906: Medium severity Sun Java Embedding Plugin vulnerability
Published May 30, 2007
·Updated
Java Embedding Plugin 0.9.6.1 allows remote attackers to cause a denial of service (browser crash) via a Thread subclass that calls super.run from its run method.
Affected Software
1 affected component
Sun Java Embedding Plugin=0.9.6.1
Remediation
Event History
May 30, 2007
CVE Published
10:30 AM
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-2906?
CVE-2007-2906 has a medium severity rating due to its ability to cause denial of service by crashing the browser.
2
How do I fix CVE-2007-2906?
To fix CVE-2007-2906, update your Java Embedding Plugin to a version that addresses this vulnerability.
3
What does CVE-2007-2906 affect?
CVE-2007-2906 specifically affects version 0.9.6.1 of the Sun Java Embedding Plugin.
4
What type of attack does CVE-2007-2906 facilitate?
CVE-2007-2906 facilitates remote denial of service attacks by exploiting unsafe thread manipulation.
5
Is there a workaround for CVE-2007-2906?
As a workaround for CVE-2007-2906, consider disabling the Java Embedding Plugin if it is not critical for your applications.