Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2007-2788

37
FAUCET Score

CVE-2007-2788 is an integer overflow vulnerability in the embedded ICC profile image parser within Sun Java Development Kit (JDK), Java Runtime Environment (JRE), and SDK across multiple versions. This flaw allows remote attackers to execute arbitrary code or cause a denial of service (JVM crash) through specially crafted JPEG or BMP files that trigger a buffer overflow. With a CVSS score of 6.8 (Medium), it has a high FAUCET Risk Score of 98/100, indicating significant potential impact (confidentiality, integrity, availability) with medium attack complexity and no authentication required. While there is an ExploitDB entry referencing multiple Java vulnerabilities, there is no specific Metasploit or Nuclei module for this CVE, and it is not listed on the KEV catalog, suggesting no widespread active exploitation. Community discussion and media coverage are minimal.

Impacted Technologies

VendorProductVersion(s)CPE
1.5.0CPE matchmatch criteria
cpe:2.3:a:sun:jdk:1.5.0:-:*:*:*:*:*:*
1.5.0CPE matchmatch criteria
cpe:2.3:a:sun:jdk:1.5.0:update1:*:*:*:*:*:*
1.5.0CPE matchmatch criteria
cpe:2.3:a:sun:jdk:1.5.0:update10:*:*:*:*:*:*
1.5.0CPE matchmatch criteria
cpe:2.3:a:sun:jdk:1.5.0:update2:*:*:*:*:*:*
1.5.0CPE matchmatch criteria
cpe:2.3:a:sun:jdk:1.5.0:update3:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

6.8MEDIUM

AV:N/AC:M/Au:N/C:P/I:P/A:P

Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
Access Vector
NETWORK
Access Complexity
MEDIUM
Authentication
NONE
Exploitability Score
8.6
Impact Score
6.4
CvssVersion
2.0

Exploit Intelligence

EPSS Score
18.19%
Probability of exploitation in next 30 days
EPSS Percentile
96.9%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
ExploitDB: EDB-30043 · May 16, 2007
This CVE's current EPSS score of 0.1819 is in the 97th percentile among its peer group of 19,955 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (39)

redhatpatch availablevia redhat_api
Product: Extras for RHEL 3Fixed in: java-1.4.2-ibm-0:1.4.2.9-1jpp.1.el3
View patch
redhatpatch availablevia redhat_api
Product: Extras for RHEL 3Fixed in: java-1.4.2-bea-0:1.4.2.16-1jpp.1.el3
View patch
redhatpatch availablevia redhat_api
Product: Extras for RHEL 4Fixed in: java-1.4.2-ibm-0:1.4.2.9-1jpp.1.el4
View patch
redhatpatch availablevia redhat_api
Product: Extras for RHEL 4Fixed in: java-1.5.0-ibm-1:1.5.0.5-1jpp.2.el4
View patch
redhatpatch availablevia redhat_api
Product: Extras for RHEL 4Fixed in: java-1.4.2-bea-0:1.4.2.15-1jpp.2.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 4.2Fixed in: jabberd-0:2.0s10-3.38.rhn
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 4.2Fixed in: java-1.4.2-ibm-0:1.4.2.10-1jpp.2.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 4.2Fixed in: jfreechart-0:0.9.20-3.rhn
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 4.2Fixed in: openmotif21-0:2.1.30-11.RHEL4.6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 4.2Fixed in: perl-Crypt-CBC-0:2.24-1.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 4.2Fixed in: rhn-apache-0:1.3.27-36.rhn.rhel4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 4.2Fixed in: rhn-modjk-0:1.2.23-2rhn.rhel4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 4.2Fixed in: rhn-modperl-0:1.29-16.rhel4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 4.2Fixed in: rhn-modssl-0:2.8.12-8.rhn.10.rhel4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 4.2Fixed in: tomcat5-0:5.0.30-0jpp_10rh
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 4.2 (RHEL3)Fixed in: jabberd-0:2.0s10-3.37.rhn
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 4.2 (RHEL3)Fixed in: java-1.4.2-ibm-0:1.4.2.10-1jpp.2.el3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 4.2 (RHEL3)Fixed in: jfreechart-0:0.9.20-3.rhn
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 4.2 (RHEL3)Fixed in: openmotif21-0:2.1.30-9.RHEL3.8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 4.2 (RHEL3)Fixed in: perl-Crypt-CBC-0:2.24-1.el3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 4.2 (RHEL3)Fixed in: rhn-apache-0:1.3.27-36.rhn.rhel3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 4.2 (RHEL3)Fixed in: rhn-modjk-0:1.2.23-2rhn.rhel3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 4.2 (RHEL3)Fixed in: rhn-modperl-0:1.29-16.rhel3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 4.2 (RHEL3)Fixed in: rhn-modssl-0:2.8.12-8.rhn.10.rhel3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 4.2 (RHEL3)Fixed in: tomcat5-0:5.0.30-0jpp_10rh
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 5.0Fixed in: jabberd-0:2.0s10-3.38.rhn
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 5.0Fixed in: java-1.4.2-ibm-0:1.4.2.10-1jpp.2.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 5.0Fixed in: jfreechart-0:0.9.20-3.rhn
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 5.0Fixed in: openmotif21-0:2.1.30-11.RHEL4.6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 5.0Fixed in: perl-Crypt-CBC-0:2.24-1.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 5.0Fixed in: rhn-apache-0:1.3.27-36.rhn.rhel4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 5.0Fixed in: rhn-modjk-0:1.2.23-2rhn.rhel4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 5.0Fixed in: rhn-modperl-0:1.29-16.rhel4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 5.0Fixed in: rhn-modssl-0:2.8.12-8.rhn.10.rhel4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 5.0Fixed in: tomcat5-0:5.0.30-0jpp_10rh
View patch
redhatpatch availablevia redhat_api
Product: Supplementary for Red Hat Enterprise Linux 5Fixed in: java-1.4.2-ibm-0:1.4.2.9-1jpp.1.el5
View patch
redhatpatch availablevia redhat_api
Product: Supplementary for Red Hat Enterprise Linux 5Fixed in: java-1.5.0-ibm-1:1.5.0.5-1jpp.0.1.el5
View patch
redhatpatch availablevia redhat_api
Product: Supplementary for Red Hat Enterprise Linux 5Fixed in: java-1.5.0-bea-0:1.5.0.11-1jpp.1.el5
View patch
redhatpatch availablevia redhat_api
Product: Supplementary for Red Hat Enterprise Linux 5Fixed in: java-1.4.2-bea-0:1.4.2.16-1jpp.1.el5
View patch

Vendor Advisories (1)

redhatCVE-2007-2788Critical

Integer overflow in the embedded ICC profile image parser in Sun Java Development Kit

May 21, 2007

References

dev2dev.bea.com / pub/advisory/248
Third Party Advisory
docs.info.apple.com / article.html
Broken Link
lists.apple.com / archives/Security-announce/2007/Dec/msg00001.html
Mailing ListThird Party Advisory
lists.vmware.com / pipermail/security-announce/2008/000003.html
Mailing ListThird Party Advisory
scary.beasts.org / security/CESA-2006-004.html
Third Party Advisory
secunia.com / advisories/25295
PatchThird Party Advisory
secunia.com / advisories/25474
Third Party Advisory
secunia.com / advisories/25832
Third Party Advisory
secunia.com / advisories/26049
Third Party Advisory
secunia.com / advisories/26119
Third Party Advisory
secunia.com / advisories/26311
Third Party Advisory
secunia.com / advisories/26369
Third Party Advisory
secunia.com / advisories/26631
Third Party Advisory
secunia.com / advisories/26645
Third Party Advisory
secunia.com / advisories/26933
Third Party Advisory
secunia.com / advisories/27203
Third Party Advisory
secunia.com / advisories/27266
Third Party Advisory
secunia.com / advisories/28056
Third Party Advisory
secunia.com / advisories/28115
Third Party Advisory
secunia.com / advisories/28365
Third Party Advisory
secunia.com / advisories/29340
Third Party Advisory
secunia.com / advisories/29858
Third Party Advisory
secunia.com / advisories/30780
Third Party Advisory
secunia.com / advisories/30805
Third Party Advisory
security.gentoo.org / glsa/glsa-200706-08.xml
Third Party Advisory
security.gentoo.org / glsa/glsa-200804-28.xml
Third Party Advisory
exchange.xforce.ibmcloud.com / vulnerabilities/34318
Third Party AdvisoryVDB Entry
exchange.xforce.ibmcloud.com / vulnerabilities/34652
Third Party AdvisoryVDB Entry
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11700
Third Party Advisory
sunsolve.sun.com / search/document.do
Broken Link
sunsolve.sun.com / search/document.do
Broken Link
support.novell.com / techcenter/psdb/4f850d1e2b871db609de64ec70f0089c.html
Third Party Advisory
support.novell.com / techcenter/psdb/d2f549cc040cd81ae4a268bb5edfe918.html
Third Party Advisory
attrition.org / pipermail/vim/2007-December/001862.html
Third Party Advisory
attrition.org / pipermail/vim/2007-July/001696.html
Third Party Advisory
attrition.org / pipermail/vim/2007-July/001697.html
Third Party Advisory
attrition.org / pipermail/vim/2007-July/001708.html
Third Party Advisory
gentoo.org / security/en/glsa/glsa-200705-23.xml
Third Party Advisory
gentoo.org / security/en/glsa/glsa-200709-15.xml
Third Party Advisory
gentoo.org / security/en/glsa/glsa-200804-20.xml
Third Party Advisory
gentoo.org / security/en/glsa/glsa-200806-11.xml
Third Party Advisory
kb.cert.org / vuls/id/138545
Third Party AdvisoryUS Government Resource
novell.com / linux/security/advisories/2007_45_java.html
Third Party Advisory
novell.com / linux/security/advisories/2007_56_ibmjava.html
Third Party Advisory
redhat.com / support/errata/RHSA-2007-0817.html
Third Party Advisory
redhat.com / support/errata/RHSA-2007-0829.html
Third Party Advisory
redhat.com / support/errata/RHSA-2007-0956.html
Third Party Advisory
redhat.com / support/errata/RHSA-2007-1086.html
Third Party Advisory
redhat.com / support/errata/RHSA-2008-0100.html
Third Party Advisory
redhat.com / support/errata/RHSA-2008-0133.html
Third Party Advisory
redhat.com / support/errata/RHSA-2008-0261.html
Third Party Advisory
securityfocus.com / bid/24004
Third Party AdvisoryVDB Entry
securityfocus.com / bid/24267
Third Party AdvisoryVDB Entry
securitytracker.com / id
Third Party AdvisoryVDB Entry
vupen.com / english/advisories/2007/1836
Permissions Required
vupen.com / english/advisories/2007/3009
Permissions Required
vupen.com / english/advisories/2007/4224
Permissions Required
vupen.com / english/advisories/2008/0065
Permissions Required