CVE-2007-2788
Summary
| CVE | CVE-2007-2788 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2007-05-22 00:30:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | Integer overflow in the embedded ICC profile image parser in Sun Java Development Kit (JDK) before 1.5.0_11-b03 and 1.6.x before 1.6.0_01-b06, and Sun Java Runtime Environment in JDK and JRE 6, JDK and JRE 5.0 Update 10 and earlier, SDK and JRE 1.4.2_14 and earlier, and SDK and JRE 1.3.1_20 and earlier, allows remote attackers to execute arbitrary code or cause a denial of service (JVM crash) via a crafted JPEG or BMP file that triggers a buffer overflow. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:M/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Sun | Jdk | 1.5.0 | - | All | All |
| Application | Sun | Jdk | 1.5.0 | update1 | All | All |
| Application | Sun | Jdk | 1.5.0 | update10 | All | All |
| Application | Sun | Jdk | 1.5.0 | update2 | All | All |
| Application | Sun | Jdk | 1.5.0 | update3 | All | All |
| Application | Sun | Jdk | 1.5.0 | update4 | All | All |
| Application | Sun | Jdk | 1.5.0 | update5 | All | All |
| Application | Sun | Jdk | 1.5.0 | update6 | All | All |
| Application | Sun | Jdk | 1.5.0 | update7 | All | All |
| Application | Sun | Jdk | 1.5.0 | update8 | All | All |
| Application | Sun | Jdk | 1.5.0 | update9 | All | All |
| Application | Sun | Jdk | 1.6.0 | - | All | All |
| Application | Sun | Jre | 1.3.1 | - | All | All |
| Application | Sun | Jre | 1.3.1_03 | All | All | All |
| Application | Sun | Jre | 1.3.1_04 | All | All | All |
| Application | Sun | Jre | 1.3.1_05 | All | All | All |
| Application | Sun | Jre | 1.3.1_06 | All | All | All |
| Application | Sun | Jre | 1.3.1_07 | All | All | All |
| Application | Sun | Jre | 1.3.1_08 | All | All | All |
| Application | Sun | Jre | 1.3.1_09 | All | All | All |
| Application | Sun | Jre | 1.3.1_10 | All | All | All |
| Application | Sun | Jre | 1.3.1_11 | All | All | All |
| Application | Sun | Jre | 1.3.1_12 | All | All | All |
| Application | Sun | Jre | 1.3.1_13 | All | All | All |
| Application | Sun | Jre | 1.3.1_14 | All | All | All |
| Application | Sun | Jre | 1.3.1_15 | All | All | All |
| Application | Sun | Jre | 1.3.1_16 | All | All | All |
| Application | Sun | Jre | 1.3.1_17 | All | All | All |
| Application | Sun | Jre | 1.3.1_18 | All | All | All |
| Application | Sun | Jre | 1.3.1_19 | All | All | All |
| Application | Sun | Jre | 1.3.1_2 | All | All | All |
| Application | Sun | Jre | 1.3.1_20 | All | All | All |
| Application | Sun | Jre | 1.4.2 | - | All | All |
| Application | Sun | Jre | 1.4.2_1 | All | All | All |
| Application | Sun | Jre | 1.4.2_10 | All | All | All |
| Application | Sun | Jre | 1.4.2_11 | All | All | All |
| Application | Sun | Jre | 1.4.2_12 | All | All | All |
| Application | Sun | Jre | 1.4.2_13 | All | All | All |
| Application | Sun | Jre | 1.4.2_14 | All | All | All |
| Application | Sun | Jre | 1.4.2_2 | All | All | All |
| Application | Sun | Jre | 1.4.2_3 | All | All | All |
| Application | Sun | Jre | 1.4.2_4 | All | All | All |
| Application | Sun | Jre | 1.4.2_5 | All | All | All |
| Application | Sun | Jre | 1.4.2_6 | All | All | All |
| Application | Sun | Jre | 1.4.2_7 | All | All | All |
| Application | Sun | Jre | 1.4.2_8 | All | All | All |
| Application | Sun | Jre | 1.4.2_9 | All | All | All |
| Application | Sun | Jre | 1.5.0 | - | All | All |
| Application | Sun | Jre | 1.5.0 | update1 | All | All |
| Application | Sun | Jre | 1.5.0 | update10 | All | All |
| Application | Sun | Jre | 1.5.0 | update2 | All | All |
| Application | Sun | Jre | 1.5.0 | update3 | All | All |
| Application | Sun | Jre | 1.5.0 | update4 | All | All |
| Application | Sun | Jre | 1.5.0 | update5 | All | All |
| Application | Sun | Jre | 1.5.0 | update6 | All | All |
| Application | Sun | Jre | 1.5.0 | update7 | All | All |
| Application | Sun | Jre | 1.5.0 | update8 | All | All |
| Application | Sun | Jre | 1.5.0 | update9 | All | All |
| Application | Sun | Jre | 1.6.0 | - | All | All |
| Application | Sun | Sdk | 1.3.1 | All | All | All |
| Application | Sun | Sdk | 1.3.1_01 | All | All | All |
| Application | Sun | Sdk | 1.3.1_01a | All | All | All |
| Application | Sun | Sdk | 1.3.1_02 | All | All | All |
| Application | Sun | Sdk | 1.3.1_03 | All | All | All |
| Application | Sun | Sdk | 1.3.1_04 | All | All | All |
| Application | Sun | Sdk | 1.3.1_05 | All | All | All |
| Application | Sun | Sdk | 1.3.1_06 | All | All | All |
| Application | Sun | Sdk | 1.3.1_07 | All | All | All |
| Application | Sun | Sdk | 1.3.1_08 | All | All | All |
| Application | Sun | Sdk | 1.3.1_09 | All | All | All |
| Application | Sun | Sdk | 1.3.1_10 | All | All | All |
| Application | Sun | Sdk | 1.3.1_11 | All | All | All |
| Application | Sun | Sdk | 1.3.1_12 | All | All | All |
| Application | Sun | Sdk | 1.3.1_13 | All | All | All |
| Application | Sun | Sdk | 1.3.1_14 | All | All | All |
| Application | Sun | Sdk | 1.3.1_15 | All | All | All |
| Application | Sun | Sdk | 1.3.1_16 | All | All | All |
| Application | Sun | Sdk | 1.3.1_17 | All | All | All |
| Application | Sun | Sdk | 1.3.1_18 | All | All | All |
| Application | Sun | Sdk | 1.3.1_19 | All | All | All |
| Application | Sun | Sdk | 1.3.1_20 | All | All | All |
| Application | Sun | Sdk | 1.4.2 | All | All | All |
| Application | Sun | Sdk | 1.4.2_1 | All | All | All |
| Application | Sun | Sdk | 1.4.2_10 | All | All | All |
| Application | Sun | Sdk | 1.4.2_11 | All | All | All |
| Application | Sun | Sdk | 1.4.2_12 | All | All | All |
| Application | Sun | Sdk | 1.4.2_13 | All | All | All |
| Application | Sun | Sdk | 1.4.2_14 | All | All | All |
| Application | Sun | Sdk | 1.4.2_2 | All | All | All |
| Application | Sun | Sdk | 1.4.2_3 | All | All | All |
| Application | Sun | Sdk | 1.4.2_4 | All | All | All |
| Application | Sun | Sdk | 1.4.2_5 | All | All | All |
| Application | Sun | Sdk | 1.4.2_6 | All | All | All |
| Application | Sun | Sdk | 1.4.2_7 | All | All | All |
| Application | Sun | Sdk | 1.4.2_8 | All | All | All |
| Application | Sun | Sdk | 1.4.2_9 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | Third Party Advisory, VDB Entry |
| Red Hat update for java-1.5.0-bea - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Third Party Advisory |
| Sun JDK/JRE: Multiple vulnerabilities — Gentoo Linux Documentation | af854a3a-2127-422b-91ae-364da2661108 | www.gentoo.org | Third Party Advisory |
| SUSE update for Java / IBM Java - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Third Party Advisory |
| SecurityTracker.com Archives - Sun Java Runtime Environment Buffer Overflow in Applet Image Parsing Lets Remote Users Gain Privileges | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | Third Party Advisory, VDB Entry |
| Webmail - OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Permissions Required |
| rhn.redhat.com | Red Hat Support | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | Third Party Advisory |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | Third Party Advisory |
| BEA JRockit Multiple Vulnerabilities - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Third Party Advisory |
| Gentoo update for sun-jdk, sun-jre-bin, and emul-linux-x86-java - Secunia Advisories - Vulnerability Intelligence - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Third Party Advisory |
| rhn.redhat.com | Red Hat Support | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | Third Party Advisory |
| APPLE-SA-2007-12-14 Java Release 6 for Mac OS X 10.4 | af854a3a-2127-422b-91ae-364da2661108 | lists.apple.com | Mailing List, Third Party Advisory |
| Gentoo Linux Documentation -- BEA JRockit: Multiple vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.gentoo.org | Third Party Advisory |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Permissions Required |
| sunsolve.sun.com/search/document.do | af854a3a-2127-422b-91ae-364da2661108 | sunsolve.sun.com | Broken Link |
| RETIRED: Sun Java Runtime Environment Image Parsing Buffer Overflow Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Third Party Advisory, VDB Entry |
| SUSE update for IBM JRE/SDK Java and Sun Java JRE/SDK - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Third Party Advisory |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Permissions Required |
| Security update for Java | af854a3a-2127-422b-91ae-364da2661108 | support.novell.com | Third Party Advisory |
| Red Hat update for java-1.4.2-bea - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Third Party Advisory |
| Red Hat update for java-1.4.2-bea - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Third Party Advisory |
| US-CERT Vulnerability Note VU#138545 | af854a3a-2127-422b-91ae-364da2661108 | www.kb.cert.org | Third Party Advisory, US Government Resource |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Permissions Required |
| Oracle Fusion Middleware Technologies | af854a3a-2127-422b-91ae-364da2661108 | dev2dev.bea.com | Third Party Advisory |
| #102934: Security Vulnerabilities in the Java Runtime Environment Image Parsing Code May Allow a Untrusted Applet to Elevate Privileges | af854a3a-2127-422b-91ae-364da2661108 | sunsolve.sun.com | Broken Link |
| [Security-announce] VMSA-2008-0002 Low severity security update for VirtualCenter and ESX Server 3.0.2, and ESX 3.0.1 | af854a3a-2127-422b-91ae-364da2661108 | lists.vmware.com | Mailing List, Third Party Advisory |
| About the security content of Java Release 6 for Mac OS X 10.4 | af854a3a-2127-422b-91ae-364da2661108 | docs.info.apple.com | Broken Link |
| Red Hat update for java-1.5.0-ibm - Secunia Advisories - Vulnerability Information - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Third Party Advisory |
| Gentoo update for jrockit-jdk-bin - Secunia Advisories - Vulnerability Intelligence - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Third Party Advisory |
| [VIM] Sun JDK Confusion | af854a3a-2127-422b-91ae-364da2661108 | www.attrition.org | Third Party Advisory |
| Security Announcement | af854a3a-2127-422b-91ae-364da2661108 | www.novell.com | Third Party Advisory |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | Third Party Advisory, VDB Entry |
| rhn.redhat.com | Red Hat Support | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | Third Party Advisory |
| rhn.redhat.com | Red Hat Support | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | Third Party Advisory |
| SUSE update for IBM Java - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Third Party Advisory |
| CESA-2006-004 - rev 2 | af854a3a-2127-422b-91ae-364da2661108 | scary.beasts.org | Third Party Advisory |
| Gentoo update for ibm-jdk-bin and ibm-jre-bin - Secunia Advisories - Vulnerability Intelligence - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Third Party Advisory |
| Sun JDK and JRE ICC and BMP Parser Vulnerabilities - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Patch, Third Party Advisory |
| rhn.redhat.com | Red Hat Support | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | Third Party Advisory |
| Mac OS X Java Multiple Vulnerabilities - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Third Party Advisory |
| JRockit: Multiple vulnerabilities — Gentoo Linux Documentation | af854a3a-2127-422b-91ae-364da2661108 | security.gentoo.org | Third Party Advisory |
| [VIM] [theall at tenablesecurity.com: Sun JDK Confusion] (fwd) | af854a3a-2127-422b-91ae-364da2661108 | www.attrition.org | Third Party Advisory |
| [VIM] Sun JDK Confusion | af854a3a-2127-422b-91ae-364da2661108 | www.attrition.org | Third Party Advisory |
| VMware ESX Server and VirtualCenter Multiple Security Updates - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Third Party Advisory |
| [VIM] Sun JDK Confusion Revisited | af854a3a-2127-422b-91ae-364da2661108 | www.attrition.org | Third Party Advisory |
| Slackware update for jdk and jre - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Third Party Advisory |
| Gentoo Linux Documentation -- Sun JDK/JRE: Multiple vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.gentoo.org | Third Party Advisory |
| Sun JDK JPG/BMP Parser Multiple Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Third Party Advisory, VDB Entry |
| IBM JDK/JRE: Multiple vulnerabilities — Gentoo Linux Documentation | af854a3a-2127-422b-91ae-364da2661108 | www.gentoo.org | Third Party Advisory |
| Security update for IBM Java | af854a3a-2127-422b-91ae-364da2661108 | support.novell.com | Third Party Advisory |
| Gentoo Linux Documentation -- emul-linux-x86-java: Multiple vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | security.gentoo.org | Third Party Advisory |
| Red Hat update for IBMJava2-JRE and IBMJava2-SDK - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Third Party Advisory |
| Security Announcement | af854a3a-2127-422b-91ae-364da2661108 | www.novell.com | Third Party Advisory |
| rhn.redhat.com | Red Hat Support | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | Third Party Advisory |
| Gentoo update for emul-linux-x86-java - Secunia Advisories - Vulnerability Intelligence - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Third Party Advisory |
| Gentoo updates for sun-jdk and sun-jre-bin - Secunia Advisories - Vulnerability Intelligence - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Third Party Advisory |
| Red Hat update for java-1.4.2-ibm - Secunia Advisories - Vulnerability Intelligence - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Third Party Advisory |
| rhn.redhat.com | Red Hat Support | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.