Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2007-2789

17
FAUCET Score

CVE-2007-2789 describes a denial-of-service vulnerability affecting Sun Java Development Kit (JDK), Java Runtime Environment (JRE), and Software Development Kit (SDK) on Unix/Linux systems. An attacker can exploit this by crafting a malicious BMP image file that, when opened by an untrusted applet or application, causes the Java Virtual Machine (JVM) to hang. This vulnerability has a CVSS score of 4.3, indicating a medium attack complexity and a partial availability impact. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
1.5.0CPE matchmatch criteria
cpe:2.3:a:sun:jdk:1.5.0:-:*:*:*:*:*:*
1.5.0CPE matchmatch criteria
cpe:2.3:a:sun:jdk:1.5.0:update1:*:*:*:*:*:*
1.5.0CPE matchmatch criteria
cpe:2.3:a:sun:jdk:1.5.0:update10:*:*:*:*:*:*
1.5.0CPE matchmatch criteria
cpe:2.3:a:sun:jdk:1.5.0:update2:*:*:*:*:*:*
1.5.0CPE matchmatch criteria
cpe:2.3:a:sun:jdk:1.5.0:update3:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

4.3MEDIUM

AV:N/AC:M/Au:N/C:N/I:N/A:P

Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
PARTIAL
Access Vector
NETWORK
Access Complexity
MEDIUM
Authentication
NONE
Exploitability Score
8.6
Impact Score
2.9
CvssVersion
2.0

Exploit Intelligence

EPSS Score
3.48%
Probability of exploitation in next 30 days
EPSS Percentile
87.9%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0348 is in the 83rd percentile among its peer group of 19,956 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (39)

redhatpatch availablevia redhat_api
Product: Extras for RHEL 3Fixed in: java-1.4.2-ibm-0:1.4.2.9-1jpp.1.el3
View patch
redhatpatch availablevia redhat_api
Product: Extras for RHEL 3Fixed in: java-1.4.2-bea-0:1.4.2.16-1jpp.1.el3
View patch
redhatpatch availablevia redhat_api
Product: Extras for RHEL 4Fixed in: java-1.4.2-ibm-0:1.4.2.9-1jpp.1.el4
View patch
redhatpatch availablevia redhat_api
Product: Extras for RHEL 4Fixed in: java-1.5.0-ibm-1:1.5.0.5-1jpp.2.el4
View patch
redhatpatch availablevia redhat_api
Product: Extras for RHEL 4Fixed in: java-1.4.2-bea-0:1.4.2.15-1jpp.2.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 4.2Fixed in: jabberd-0:2.0s10-3.38.rhn
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 4.2Fixed in: java-1.4.2-ibm-0:1.4.2.10-1jpp.2.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 4.2Fixed in: jfreechart-0:0.9.20-3.rhn
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 4.2Fixed in: openmotif21-0:2.1.30-11.RHEL4.6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 4.2Fixed in: perl-Crypt-CBC-0:2.24-1.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 4.2Fixed in: rhn-apache-0:1.3.27-36.rhn.rhel4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 4.2Fixed in: rhn-modjk-0:1.2.23-2rhn.rhel4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 4.2Fixed in: rhn-modperl-0:1.29-16.rhel4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 4.2Fixed in: rhn-modssl-0:2.8.12-8.rhn.10.rhel4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 4.2Fixed in: tomcat5-0:5.0.30-0jpp_10rh
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 4.2 (RHEL3)Fixed in: jabberd-0:2.0s10-3.37.rhn
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 4.2 (RHEL3)Fixed in: java-1.4.2-ibm-0:1.4.2.10-1jpp.2.el3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 4.2 (RHEL3)Fixed in: jfreechart-0:0.9.20-3.rhn
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 4.2 (RHEL3)Fixed in: openmotif21-0:2.1.30-9.RHEL3.8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 4.2 (RHEL3)Fixed in: perl-Crypt-CBC-0:2.24-1.el3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 4.2 (RHEL3)Fixed in: rhn-apache-0:1.3.27-36.rhn.rhel3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 4.2 (RHEL3)Fixed in: rhn-modjk-0:1.2.23-2rhn.rhel3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 4.2 (RHEL3)Fixed in: rhn-modperl-0:1.29-16.rhel3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 4.2 (RHEL3)Fixed in: rhn-modssl-0:2.8.12-8.rhn.10.rhel3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 4.2 (RHEL3)Fixed in: tomcat5-0:5.0.30-0jpp_10rh
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 5.0Fixed in: jabberd-0:2.0s10-3.38.rhn
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 5.0Fixed in: java-1.4.2-ibm-0:1.4.2.10-1jpp.2.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 5.0Fixed in: jfreechart-0:0.9.20-3.rhn
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 5.0Fixed in: openmotif21-0:2.1.30-11.RHEL4.6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 5.0Fixed in: perl-Crypt-CBC-0:2.24-1.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 5.0Fixed in: rhn-apache-0:1.3.27-36.rhn.rhel4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 5.0Fixed in: rhn-modjk-0:1.2.23-2rhn.rhel4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 5.0Fixed in: rhn-modperl-0:1.29-16.rhel4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 5.0Fixed in: rhn-modssl-0:2.8.12-8.rhn.10.rhel4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 5.0Fixed in: tomcat5-0:5.0.30-0jpp_10rh
View patch
redhatpatch availablevia redhat_api
Product: Supplementary for Red Hat Enterprise Linux 5Fixed in: java-1.4.2-ibm-0:1.4.2.9-1jpp.1.el5
View patch
redhatpatch availablevia redhat_api
Product: Supplementary for Red Hat Enterprise Linux 5Fixed in: java-1.5.0-ibm-1:1.5.0.5-1jpp.0.1.el5
View patch
redhatpatch availablevia redhat_api
Product: Supplementary for Red Hat Enterprise Linux 5Fixed in: java-1.5.0-bea-0:1.5.0.11-1jpp.1.el5
View patch
redhatpatch availablevia redhat_api
Product: Supplementary for Red Hat Enterprise Linux 5Fixed in: java-1.4.2-bea-0:1.4.2.16-1jpp.1.el5
View patch

Vendor Advisories (1)

redhatCVE-2007-2789Critical

BMP image parser vulnerability

May 21, 2007

References

dev2dev.bea.com / pub/advisory/248
Third Party Advisory
docs.info.apple.com / article.html
Broken Link
lists.apple.com / archives/Security-announce/2007/Dec/msg00001.html
Mailing ListThird Party Advisory
scary.beasts.org / security/CESA-2006-004.html
Third Party Advisory
secunia.com / advisories/25295
PatchThird Party Advisory
secunia.com / advisories/25474
Third Party Advisory
secunia.com / advisories/25832
Third Party Advisory
secunia.com / advisories/26049
Third Party Advisory
secunia.com / advisories/26119
Third Party Advisory
secunia.com / advisories/26311
Third Party Advisory
secunia.com / advisories/26369
Third Party Advisory
secunia.com / advisories/26631
Third Party Advisory
secunia.com / advisories/26645
Third Party Advisory
secunia.com / advisories/26933
Third Party Advisory
secunia.com / advisories/27203
Third Party Advisory
secunia.com / advisories/27266
Third Party Advisory
secunia.com / advisories/28056
Third Party Advisory
secunia.com / advisories/28115
Third Party Advisory
secunia.com / advisories/29340
Third Party Advisory
secunia.com / advisories/29858
Third Party Advisory
secunia.com / advisories/30780
Third Party Advisory
secunia.com / advisories/30805
Third Party Advisory
security.gentoo.org / glsa/glsa-200706-08.xml
Third Party Advisory
security.gentoo.org / glsa/glsa-200804-28.xml
Third Party Advisory
exchange.xforce.ibmcloud.com / vulnerabilities/34320
Third Party AdvisoryVDB Entry
exchange.xforce.ibmcloud.com / vulnerabilities/34654
Third Party AdvisoryVDB Entry
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10800
Third Party Advisory
sunsolve.sun.com / search/document.do
Broken Link
sunsolve.sun.com / search/document.do
Broken Link
support.novell.com / techcenter/psdb/4f850d1e2b871db609de64ec70f0089c.html
Third Party Advisory
support.novell.com / techcenter/psdb/d2f549cc040cd81ae4a268bb5edfe918.html
Third Party Advisory
attrition.org / pipermail/vim/2007-December/001862.html
Third Party Advisory
attrition.org / pipermail/vim/2007-July/001696.html
Third Party Advisory
attrition.org / pipermail/vim/2007-July/001697.html
Third Party Advisory
attrition.org / pipermail/vim/2007-July/001708.html
Third Party Advisory
gentoo.org / security/en/glsa/glsa-200705-23.xml
Third Party Advisory
gentoo.org / security/en/glsa/glsa-200709-15.xml
Third Party Advisory
gentoo.org / security/en/glsa/glsa-200804-20.xml
Third Party Advisory
gentoo.org / security/en/glsa/glsa-200806-11.xml
Third Party Advisory
novell.com / linux/security/advisories/2007_45_java.html
Third Party Advisory
novell.com / linux/security/advisories/2007_56_ibmjava.html
Third Party Advisory
redhat.com / support/errata/RHSA-2007-0817.html
Third Party Advisory
redhat.com / support/errata/RHSA-2007-0829.html
Third Party Advisory
redhat.com / support/errata/RHSA-2007-0956.html
Third Party Advisory
redhat.com / support/errata/RHSA-2007-1086.html
Third Party Advisory
redhat.com / support/errata/RHSA-2008-0100.html
Third Party Advisory
redhat.com / support/errata/RHSA-2008-0133.html
Third Party Advisory
redhat.com / support/errata/RHSA-2008-0261.html
Third Party Advisory
securityfocus.com / bid/24004
Third Party AdvisoryVDB Entry
securitytracker.com / id
Third Party AdvisoryVDB Entry
vupen.com / english/advisories/2007/1836
Permissions Required
vupen.com / english/advisories/2007/3009
Permissions Required
vupen.com / english/advisories/2007/4224
Permissions Required