java: Vulnerability in the font parsing code
Published Aug 17, 2007
9.3
HIGHCVSS 2.0
EPSS 5.42%
Description
Unspecified vulnerability in the font parsing implementation in Sun JDK and JRE 5.0 Update 9 and earlier, and SDK and JRE 1.4.2_14 and earlier, allows remote attackers to perform unauthorized actions via an applet that grants certain privileges to itself.
Affected products
No data.
No data.
Extras for RHEL 3
java-1.4.2-bea-0:1.4.2.16-1jpp.1.el3
Fixed · RHSA-2008:0100
Extras for RHEL 3
java-1.4.2-ibm-0:1.4.2.10-1jpp.2.el3
Fixed · RHSA-2008:0132
Extras for RHEL 4
java-1.4.2-bea-0:1.4.2.15-1jpp.2.el4
Fixed · RHSA-2007:1086
Extras for RHEL 4
java-1.4.2-ibm-0:1.4.2.10-1jpp.2.el4
Fixed · RHSA-2008:0132
Extras for RHEL 4
java-1.5.0-ibm-1:1.5.0.5-1jpp.2.el4
Fixed · RHSA-2007:0829
Supplementary for Red Hat Enterprise Linux 5
java-1.4.2-bea-0:1.4.2.16-1jpp.1.el5
Fixed · RHSA-2008:0100
Supplementary for Red Hat Enterprise Linux 5
java-1.4.2-ibm-0:1.4.2.10-1jpp.2.el5
Fixed · RHSA-2008:0132
Supplementary for Red Hat Enterprise Linux 5
java-1.5.0-bea-0:1.5.0.11-1jpp.1.el5
Fixed · RHSA-2007:0956
Supplementary for Red Hat Enterprise Linux 5
java-1.5.0-ibm-1:1.5.0.5-1jpp.0.1.el5
Fixed · RHSA-2007:0829
| Product | Package | State | Advisory |
|---|---|---|---|
| Extras for RHEL 3 | java-1.4.2-bea-0:1.4.2.16-1jpp.1.el3 | Fixed | RHSA-2008:0100 |
| Extras for RHEL 3 | java-1.4.2-ibm-0:1.4.2.10-1jpp.2.el3 | Fixed | RHSA-2008:0132 |
| Extras for RHEL 4 | java-1.4.2-bea-0:1.4.2.15-1jpp.2.el4 | Fixed | RHSA-2007:1086 |
| Extras for RHEL 4 | java-1.4.2-ibm-0:1.4.2.10-1jpp.2.el4 | Fixed | RHSA-2008:0132 |
| Extras for RHEL 4 | java-1.5.0-ibm-1:1.5.0.5-1jpp.2.el4 | Fixed | RHSA-2007:0829 |
| Supplementary for Red Hat Enterprise Linux 5 | java-1.4.2-bea-0:1.4.2.16-1jpp.1.el5 | Fixed | RHSA-2008:0100 |
| Supplementary for Red Hat Enterprise Linux 5 | java-1.4.2-ibm-0:1.4.2.10-1jpp.2.el5 | Fixed | RHSA-2008:0132 |
| Supplementary for Red Hat Enterprise Linux 5 | java-1.5.0-bea-0:1.5.0.11-1jpp.1.el5 | Fixed | RHSA-2007:0956 |
| Supplementary for Red Hat Enterprise Linux 5 | java-1.5.0-ibm-1:1.5.0.5-1jpp.0.1.el5 | Fixed | RHSA-2007:0829 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:N/AC:M/Au:N/C:C/I:C/A:C
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (16 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 5.42% (0.05424) | 92.45th | v5 (v2026.06.15) |
| Jun 15, 2026 | 5.42% (0.05424) | 91.65th | v5 (v2026.06.15) |
| Apr 5, 2026 | 18.44% (0.18441) | 95.21th | v4 (v2025.03.14) |
| May 1, 2025 | 16.43% (0.16430) | 94.52th | v4 (v2025.03.14) |
| Mar 30, 2025 | 20.14% (0.20143) | 95.02th | v4 (v2025.03.14) |
| Mar 29, 2025 | 32.67% (0.32675) | 95.10th | v4 (v2025.03.14) |
| Mar 17, 2025 | 20.14% (0.20143) | 95.03th | v4 (v2025.03.14) |
| Feb 26, 2025 | 19.19% (0.19193) | 96.34th | v3 (v2023.03.01) |
| Jun 20, 2024 | 15.54% (0.15545) | 95.95th | v3 (v2023.03.01) |
| May 13, 2024 | 8.36% (0.08358) | 94.36th | v3 (v2023.03.01) |
| Jan 19, 2024 | 8.62% (0.08618) | 93.89th | v3 (v2023.03.01) |
| Apr 2, 2023 | 7.69% (0.07692) | 93.12th | v3 (v2023.03.01) |
| Mar 7, 2023 | 8.44% (0.08444) | 93.38th | v3 (v2023.03.01) |
| Mar 6, 2023 | 12.57% (0.12567) | 95.52th | v2 (v2022.01.01) |
| Apr 1, 2022 | 12.57% (0.12567) | 95.18th | v2 (v2022.01.01) |
| Feb 4, 2022 | 12.57% (0.12567) | 90.03th | v2 (v2022.01.01) |
No CWE recorded.
References (33)
- http://dev2dev.bea.com/pub/advisory/248 vendor-advisoryx_refsource_BEA
- http://docs.info.apple.com/article.html?artnum=307177 x_refsource_MISC
- http://lists.apple.com/archives/Security-announce/2007/Dec/msg00001.html vendor-advisoryx_refsource_APPLE
- http://lists.opensuse.org/opensuse-security-announce/2008-04/msg00010.html vendor-advisoryx_refsource_SUSE
- http://secunia.com/advisories/26402 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/26631 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/26933 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/27203 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/27716 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/28056 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/28115 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/28777 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/28880 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/29340 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/29897 third-party-advisoryx_refsource_SECUNIA
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-103024-1 vendor-advisoryx_refsource_SUNALERT
- http://support.novell.com/techcenter/psdb/0c36b6416afc3868b8b1b9012955e323.html x_refsource_CONFIRM
- http://www.gentoo.org/security/en/glsa/glsa-200709-15.xml vendor-advisoryx_refsource_GENTOO
- http://www.redhat.com/support/errata/RHSA-2007-0956.html vendor-advisoryx_refsource_REDHAT
- http://www.redhat.com/support/errata/RHSA-2007-1086.html vendor-advisoryx_refsource_REDHAT
- http://www.redhat.com/support/errata/RHSA-2008-0100.html vendor-advisoryx_refsource_REDHAT
- http://www.redhat.com/support/errata/RHSA-2008-0132.html vendor-advisoryx_refsource_REDHAT
- http://www.securityfocus.com/bid/25340 vdb-entryx_refsource_BID
- http://www.securitytracker.com/id?1018576 vdb-entryx_refsource_SECTRACK
- http://www.vupen.com/english/advisories/2007/2910 vdb-entryx_refsource_VUPEN
- http://www.vupen.com/english/advisories/2007/3009 vdb-entryx_refsource_VUPEN
- http://www.vupen.com/english/advisories/2007/4224 vdb-entryx_refsource_VUPEN
- https://access.redhat.com/security/cve/CVE-2007-4381 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=253488 Issue Tracking
- https://exchange.xforce.ibmcloud.com/vulnerabilities/36061 vdb-entryx_refsource_XF
- https://nvd.nist.gov/vuln/detail/CVE-2007-4381
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10290 vdb-entrysignaturex_refsource_OVAL
- https://www.cve.org/CVERecord?id=CVE-2007-4381
Change history (0)
No recorded changes yet.