← Vulnerability feed

Vulnerability record · CVE-2007-2439 · published 16 May 2007

CVE-2007-2439: Caucho technology resin vulnerability

Caucho Technology · Resin

Caucho Resin Professional 3.1.0 and Caucho Resin 3.1.0 and earlier for Windows allows remote attackers to cause a denial of service (device hang) and read data from a COM or LPT device via a DOS device name with an arbitrary extension.

9.4 CVSS 2.0 High EPSS 2.3% · top 17.3%
9.4CVSS 2.0 base score
2.3%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
14References
16 Jun 2026Last modified by NVD

Description

Caucho Resin Professional 3.1.0 and Caucho Resin 3.1.0 and earlier for Windows allows remote attackers to cause a denial of service (device hang) and read data from a COM or LPT device via a DOS device name with an arbitrary extension.

AV:N/AC:L/Au:N/C:C/I:N/A:C

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2007-2439 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.8CVE-2006-1953Caucho technology resin vulnerabilityDirectory traversal vulnerability in Caucho Resin 3.0.17 and 3.0.18 for Windows allows remote attackers to read arbitrary files via a "C:%5C" (encode…EPSS 2.7%5.1CVE-2001-0828Caucho technology resin vulnerabilityA cross-site scripting vulnerability in Caucho Technology Resin before 1.2.4 allows a malicious webmaster to embed Javascript in a hyperlink that end…EPSS 2.5%5.0CVE-2007-2440Caucho technology resin vulnerabilityDirectory traversal vulnerability in Caucho Resin Professional 3.1.0 and Caucho Resin 3.1.0 and earlier for Windows allows remote attackers to read c…EPSS 3.6%5.0CVE-2007-2441Caucho technology resin vulnerabilityCaucho Resin Professional 3.1.0 and Caucho Resin 3.1.0 and earlier for Windows allows remote attackers to obtain the system path via certain URLs ass…EPSS 3.3%5.0CVE-2006-2437Caucho technology resin vulnerabilityThe viewfile servlet in the documentation package (resin-doc) for Caucho Resin 3.0.17 and 3.0.18 allows remote attackers to obtain the source code fo…EPSS 6.8%5.0CVE-2006-2438Caucho technology resin vulnerabilityDirectory traversal vulnerability in the viewfile servlet in the documentation package (resin-doc) for Caucho Resin 3.0.17 and 3.0.18 allows remote a…EPSS 2.4%5.0CVE-2004-0280Caucho technology resin vulnerabilityCaucho Technology Resin 2.1.12 allows remote attackers to view JSP source via an HTTP request to a .jsp file that ends in a "%20" (encoded space char…EPSS 1.5%5.0CVE-2002-1987Caucho technology resin vulnerabilityDirectory traversal vulnerability in view_source.jsp in Resin 2.1.2 allows remote attackers to read arbitrary files via a "\.." (backslash dot dot).EPSS 2.5%

Source: NIST National Vulnerability Database (record CVE-2007-2439), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.