CVE-2007-5375 describes an interpretation conflict in the Sun Java Virtual Machine (JVM) that affects Sun Java Virtual Machine products. This vulnerability allows user-assisted remote attackers to perform a multi-pin DNS rebinding attack, leading to arbitrary JavaScript execution within an intranet context. The attack requires an intranet web server hosting an HTML document that references a "mayscript=true" Java applet via a local relative URI, where the browser and JVM may associate different IP addresses. With a CVSS score of 2.6 (low severity), the attack vector is network-based, but requires high attack complexity and user assistance, with a potential impact of partial integrity loss. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage for this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:a:sun:java_virtual_machine:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:H/Au:N/C:N/I:P/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.