CVE-2007-5274: Low severity Mozilla Firefox vulnerability
Sun Java Runtime Environment (JRE) in JDK and JRE 6 Update 2 and earlier, JDK and JRE 5.0 Update 12 and earlier, SDK and JRE 1.4.215 and earlier, and SDK and JRE 1.3.120 and earlier, when Firefox or Opera is used, allows remote attackers to violate the security model for JavaScript outbound connections via a multi-pin DNS rebinding attack dependent on the LiveConnect API, in which JavaScript download relies on DNS resolution by the browser, but JavaScript socket operations rely on separate DNS resolution by a Java Virtual Machine (JVM), a different issue than CVE-2007-5273. NOTE: this is similar to CVE-2007-5232.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2007-5274?
The severity of CVE-2007-5274 is considered high due to its potential for remote code execution.
How do I fix CVE-2007-5274?
To fix CVE-2007-5274, upgrade your JDK or JRE to the latest version that is not affected by this vulnerability.
What versions are affected by CVE-2007-5274?
CVE-2007-5274 affects JDK and JRE 6 Update 2 and earlier, JDK and JRE 5.0 Update 12 and earlier, and several other versions of Sun JDK and JRE.
Which browsers cause CVE-2007-5274 to be exploitable?
CVE-2007-5274 can be exploited when using Firefox or Opera with the vulnerable versions of the Java Runtime Environment.
What is the impact of CVE-2007-5274?
The impact of CVE-2007-5274 includes the ability for remote attackers to manipulate JavaScript outbound connections, potentially leading to data leakage or unauthorized actions.