Lucene search

K
cve[email protected]CVE-2002-0076
HistoryApr 02, 2003 - 5:00 a.m.

CVE-2002-0076

2003-04-0205:00:00
web.nvd.nist.gov
17
cve-2002-0076
java runtime environment
jre
bytecode verifier
sandbox escape
cyber security
sdk
jdk
vulnerability

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

7.2 High

AI Score

Confidence

High

0.008 Low

EPSS

Percentile

81.9%

Java Runtime Environment (JRE) Bytecode Verifier allows remote attackers to escape the Java sandbox and execute commands via an applet containing an illegal cast operation, as seen in (1) Microsoft VM build 3802 and earlier as used in Internet Explorer 4.x and 5.x, (2) Netscape 6.2.1 and earlier, and possibly other implementations that use vulnerable versions of SDK or JDK, aka a variant of the “Virtual Machine Verifier” vulnerability.

Affected configurations

NVD
Node
hpjava_jre-jdkMatch1.1.8
OR
hpjava_jre-jdkMatch1.2.2
OR
hpjava_jre-jdkMatch1.3
OR
microsoftvirtual_machineMatch3802
OR
sunjdkMatch1.1.8update14
OR
sunjdkMatch1.1.8update8
OR
sunjreMatch1.1.8update14
OR
sunjreMatch1.1.8update8
OR
sunjreMatch1.2.2update10
OR
sunjreMatch1.3.0update5
OR
sunjreMatch1.3.1update1
OR
sunjreMatch1.3.1update1a
OR
sunsdkMatch1.2.2_10
OR
sunsdkMatch1.2.2_010
OR
sunsdkMatch1.3.1_01
OR
sunsdkMatch1.3.1_01a
OR
sunsdkMatch1.3_05

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

7.2 High

AI Score

Confidence

High

0.008 Low

EPSS

Percentile

81.9%

Related for CVE-2002-0076