Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2007-0243

31
FAUCET Score

CVE-2007-0243 describes a buffer overflow vulnerability in older versions of Sun JDK, JRE, and SDK (5.0 Update 9 and earlier, 1.4.2_12 and earlier, and 1.3.1_18 and earlier). This flaw allows malicious applets to gain elevated privileges by processing a specially crafted GIF image containing a block with a zero-width field, leading to memory corruption. With a CVSS score of 6.8, this vulnerability is remotely exploitable with medium attack complexity, potentially resulting in partial confidentiality, integrity, and availability compromise. While not listed on the KEV catalog or having significant community discussion or media coverage, an exploit is publicly available on ExploitDB, indicating a potential for exploitation.

Impacted Technologies

VendorProductVersion(s)CPE
<= 1.5.0CPE matchmatch criteria
cpe:2.3:a:sun:jdk:*:update9:*:*:*:*:*:*
1.5.0CPE matchmatch criteria
cpe:2.3:a:sun:jdk:1.5.0:update3:*:*:*:*:*:*
1.5.0CPE matchmatch criteria
cpe:2.3:a:sun:jdk:1.5.0:update4:*:*:*:*:*:*
1.5.0CPE matchmatch criteria
cpe:2.3:a:sun:jdk:1.5.0:update5:*:*:*:*:*:*
1.5.0CPE matchmatch criteria
cpe:2.3:a:sun:jdk:1.5.0:update7:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

6.8MEDIUM

AV:N/AC:M/Au:N/C:P/I:P/A:P

Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
Access Vector
NETWORK
Access Complexity
MEDIUM
Authentication
NONE
Exploitability Score
8.6
Impact Score
6.4
CvssVersion
2.0

Exploit Intelligence

EPSS Score
10.99%
Probability of exploitation in next 30 days
EPSS Percentile
95.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
ExploitDB: EDB-3168 · Jan 21, 2007
This CVE's current EPSS score of 0.1099 is in the 95th percentile among its peer group of 19,956 CVEs.

Social Chatter

No social media mentions found for this CVE.

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (38)

redhatpatch availablevia redhat_api
Product: Extras for RHEL 3Fixed in: java-1.4.2-ibm-0:1.4.2.8-1jpp.1.el3
View patch
redhatpatch availablevia redhat_api
Product: Extras for RHEL 4Fixed in: java-1.4.2-ibm-0:1.4.2.8-1jpp.1.el4
View patch
redhatpatch availablevia redhat_api
Product: Extras for RHEL 4Fixed in: java-1.5.0-ibm-1:1.5.0.4-1jpp.3.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 2.1Fixed in: IBMJava2-JRE-1:1.3.1-12
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 2.1Fixed in: IBMJava2-SDK-1:1.3.1-11
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 4.2Fixed in: jabberd-0:2.0s10-3.38.rhn
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 4.2Fixed in: java-1.4.2-ibm-0:1.4.2.10-1jpp.2.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 4.2Fixed in: jfreechart-0:0.9.20-3.rhn
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 4.2Fixed in: openmotif21-0:2.1.30-11.RHEL4.6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 4.2Fixed in: perl-Crypt-CBC-0:2.24-1.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 4.2Fixed in: rhn-apache-0:1.3.27-36.rhn.rhel4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 4.2Fixed in: rhn-modjk-0:1.2.23-2rhn.rhel4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 4.2Fixed in: rhn-modperl-0:1.29-16.rhel4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 4.2Fixed in: rhn-modssl-0:2.8.12-8.rhn.10.rhel4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 4.2Fixed in: tomcat5-0:5.0.30-0jpp_10rh
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 4.2 (RHEL3)Fixed in: jabberd-0:2.0s10-3.37.rhn
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 4.2 (RHEL3)Fixed in: java-1.4.2-ibm-0:1.4.2.10-1jpp.2.el3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 4.2 (RHEL3)Fixed in: jfreechart-0:0.9.20-3.rhn
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 4.2 (RHEL3)Fixed in: openmotif21-0:2.1.30-9.RHEL3.8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 4.2 (RHEL3)Fixed in: perl-Crypt-CBC-0:2.24-1.el3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 4.2 (RHEL3)Fixed in: rhn-apache-0:1.3.27-36.rhn.rhel3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 4.2 (RHEL3)Fixed in: rhn-modjk-0:1.2.23-2rhn.rhel3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 4.2 (RHEL3)Fixed in: rhn-modperl-0:1.29-16.rhel3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 4.2 (RHEL3)Fixed in: rhn-modssl-0:2.8.12-8.rhn.10.rhel3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 4.2 (RHEL3)Fixed in: tomcat5-0:5.0.30-0jpp_10rh
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 5.0Fixed in: jabberd-0:2.0s10-3.38.rhn
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 5.0Fixed in: java-1.4.2-ibm-0:1.4.2.10-1jpp.2.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 5.0Fixed in: jfreechart-0:0.9.20-3.rhn
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 5.0Fixed in: openmotif21-0:2.1.30-11.RHEL4.6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 5.0Fixed in: perl-Crypt-CBC-0:2.24-1.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 5.0Fixed in: rhn-apache-0:1.3.27-36.rhn.rhel4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 5.0Fixed in: rhn-modjk-0:1.2.23-2rhn.rhel4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 5.0Fixed in: rhn-modperl-0:1.29-16.rhel4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 5.0Fixed in: rhn-modssl-0:2.8.12-8.rhn.10.rhel4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 5.0Fixed in: tomcat5-0:5.0.30-0jpp_10rh
View patch
redhatpatch availablevia redhat_api
Product: Supplementary for Red Hat Enterprise Linux 5Fixed in: java-1.4.2-ibm-0:1.4.2.8-1jpp.1.el5
View patch
redhatpatch availablevia redhat_api
Product: Supplementary for Red Hat Enterprise Linux 5Fixed in: java-1.5.0-ibm-1:1.5.0.4-1jpp.3.el5
View patch
redhatpatch availablevia redhat_api
Product: Supplementary for Red Hat Enterprise Linux 5Fixed in: java-1.5.0-bea-0:1.5.0.11-1jpp.1.el5
View patch

Vendor Advisories (1)

redhatCVE-2007-0243Important

java-jre: GIF buffer overflow

Jan 17, 2007

References

dev2dev.bea.com / pub/advisory/242
docs.info.apple.com / article.html
h20000.www2.hp.com / bizsupport/TechSupport/Document.jsp
lists.apple.com / archives/Security-announce/2007/Dec/msg00001.html
osvdb.org / 32834
secunia.com / advisories/23757
secunia.com / advisories/24189
secunia.com / advisories/24202
secunia.com / advisories/24468
secunia.com / advisories/24993
secunia.com / advisories/25283
secunia.com / advisories/26049
secunia.com / advisories/26119
secunia.com / advisories/26645
secunia.com / advisories/27203
secunia.com / advisories/28115
security.gentoo.org / glsa/glsa-200702-08.xml
securityreason.com / securityalert/2158
securitytracker.com / id
exchange.xforce.ibmcloud.com / vulnerabilities/31537
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11073
sunsolve.sun.com / search/document.do
Patch
support.novell.com / techcenter/psdb/4f850d1e2b871db609de64ec70f0089c.html
support.novell.com / techcenter/psdb/d2f549cc040cd81ae4a268bb5edfe918.html
gentoo.org / security/en/glsa/glsa-200702-07.xml
kb.cert.org / vuls/id/388289
US Government Resource
novell.com / linux/security/advisories/2007_45_java.html
redhat.com / support/errata/RHSA-2007-0166.html
redhat.com / support/errata/RHSA-2007-0167.html
redhat.com / support/errata/RHSA-2007-0956.html
redhat.com / support/errata/RHSA-2008-0261.html
securityfocus.com / archive/1/457159/100/0/threaded
securityfocus.com / archive/1/457638/100/0/threaded
securityfocus.com / bid/22085
us-cert.gov / cas/techalerts/TA07-022A.html
US Government Resource
vupen.com / english/advisories/2007/0211
vupen.com / english/advisories/2007/0936
vupen.com / english/advisories/2007/1814
vupen.com / english/advisories/2007/4224
zerodayinitiative.com / advisories/ZDI-07-005.html
PatchVendor Advisory