Vulnerability Database

289,599

Total vulnerabilities in the database

CVE-2007-3655

Stack-based buffer overflow in javaws.exe in Sun Java Web Start in JRE 5.0 Update 11 and earlier, and 6.0 Update 1 and earlier, allows remote attackers to execute arbitrary code via a long codebase attribute in a JNLP file.

  • Published: Jul 10, 2007
  • Updated: Apr 13, 2023
  • CVE: CVE-2007-3655
  • Severity: Medium
  • Exploit:

CVSS v2:

  • Severity: Medium
  • Score: 6.8
  • AV:N/AC:M/Au:N/C:P/I:P/A:P

CWEs:

Software From Fixed in
sun / jre 1.5.0-update2 1.5.0-update2.x
sun / jre 1.6.0-update_1 1.6.0-update_1.x
sun / jre 1.5.0-update8 1.5.0-update8.x
sun / jre 1.5.0-update11 1.5.0-update11.x
sun / jre 1.5.0-update7 1.5.0-update7.x
sun / jre 1.5.0-update3 1.5.0-update3.x
sun / jre 1.5.0-update5 1.5.0-update5.x
sun / jre 1.5.0-update6 1.5.0-update6.x
sun / jre 1.5.0-update9 1.5.0-update9.x
sun / jre 1.5.0-update1 1.5.0-update1.x
sun / jre 1.5.0-update10 1.5.0-update10.x
sun / jre 1.5.0-update4 1.5.0-update4.x