CVE-2009-1107 describes a vulnerability in the Java Plug-in affecting Java SE Development Kit (JDK) and Java Runtime Environment (JRE) versions 6 Update 12 and earlier, and 5.0 Update 17 and earlier. This flaw allows remote attackers to deceive users into trusting a signed applet by manipulating the security warning dialog, stemming from a "Swing JLabel HTML parsing vulnerability." The vulnerability has a CVSS score of 4.3 (Medium), indicating a network-based attack with medium complexity and a potential impact of partial integrity compromise, but no confidentiality or availability impact. Its EPSS score is low, suggesting a low probability of exploitation. There is no evidence of active exploitation, and no public exploit code is available on platforms like Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal, consistent with the majority of reported vulnerabilities.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:a:sun:java:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:N/I:P/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.