Lucene search

K
freebsdFreeBSDAC619D06-3EF8-11D9-8741-C942C075AA41
HistoryNov 24, 2004 - 12:00 a.m.

jdk/jre -- Security Vulnerability With Java Plugin

2004-11-2400:00:00
vuxml.freebsd.org
19

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

EPSS

0.192

Percentile

96.3%

The Sun Java Plugin capability in Java 2 Runtime Environment
(JRE) 1.4.2_01, 1.4.2_04, and possibly earlier versions, does
not properly restrict access between Javascript and Java
applets during data transfer, which allows remote attackers to
load unsafe classes and execute arbitrary code.

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

EPSS

0.192

Percentile

96.3%