7.5

CVE-2002-0076

Java Runtime Environment (JRE) Bytecode Verifier allows remote attackers to escape the Java sandbox and execute commands via an applet containing an illegal cast operation, as seen in (1) Microsoft VM build 3802 and earlier as used in Internet Explorer 4.x and 5.x, (2) Netscape 6.2.1 and earlier, and possibly other implementations that use vulnerable versions of SDK or JDK, aka a variant of the "Virtual Machine Verifier" vulnerability.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Hp ≫ Java Jre-jdk Version 1.1.8
Hp ≫ Java Jre-jdk Version 1.2.2
Hp ≫ Java Jre-jdk Version 1.3
Microsoft ≫ Virtual Machine Version 3802
Sun ≫ Jdk Version 1.1.8 Update update14
Sun ≫ Jdk Version 1.1.8 Update update8
Sun ≫ Jre Version 1.1.8 Update update14
Sun ≫ Jre Version 1.1.8 Update update8
Sun ≫ Jre Version 1.2.2 Update update10
Sun ≫ Jre Version 1.3.0 Update update5
Sun ≫ Jre Version 1.3.1 Update update1
Sun ≫ Jre Version 1.3.1 Update update1a
Sun ≫ Sdk Version 1.2.2_10
Sun ≫ Sdk Version 1.2.2_010
Sun ≫ Sdk Version 1.3.1_01
Sun ≫ Sdk Version 1.3.1_01a
Sun ≫ Sdk Version 1.3_05
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 26.86% 0.978
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-013
http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&doc=secbull/218
Vendor Advisory
http://www.iss.net/security_center/static/8480.php
http://www.securityfocus.com/bid/4313