CVE-2007-5273 describes a security bypass vulnerability in Sun Java Runtime Environment (JRE) across multiple versions, including JDK/JRE 6 Update 2 and earlier, JDK/JRE 5.0 Update 12 and earlier, and various SDK/JRE 1.4.2 and 1.3.1 releases. This flaw allows remote attackers to violate an applet's security model for outbound connections when an HTTP proxy is in use. The attack, known as a multi-pin DNS rebinding attack, exploits a discrepancy where applet downloads rely on proxy-side DNS resolution, while applet socket operations use local machine DNS resolution. The vulnerability has a CVSS score of 2.6, indicating a low severity. Its attack vector is network-based, but requires high attack complexity (AC:H), meaning specialized conditions or knowledge are needed for a successful exploit. The potential impact is limited to partial integrity (I:P), as it allows unauthorized modification of data but not confidentiality or availability. There is no evidence of active exploitation for CVE-2007-5273. No exploit code is publicly available via Metasploit, Nuclei, or ExploitDB, and there is no community discussion or media coverage surrounding this CVE, suggesting it has received minimal attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.5.0CPE matchmatch criteria | cpe:2.3:a:sun:jdk:1.5.0:update1:*:*:*:*:*:* | ||
1.5.0CPE matchmatch criteria | cpe:2.3:a:sun:jdk:1.5.0:update10:*:*:*:*:*:* | ||
1.5.0CPE matchmatch criteria | cpe:2.3:a:sun:jdk:1.5.0:update11:*:*:*:*:*:* | ||
1.5.0CPE matchmatch criteria | cpe:2.3:a:sun:jdk:1.5.0:update12:*:*:*:*:*:* | ||
1.5.0CPE matchmatch criteria | cpe:2.3:a:sun:jdk:1.5.0:update2:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:H/Au:N/C:N/I:P/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.