7.5

CVE-2002-0866

Java Database Connectivity (JDBC) classes in Microsoft Virtual Machine (VM) up to and including 5.0.3805 allow remote attackers to load and execute DLLs (dynamic link libraries) via a Java applet that calls the constructor for com.ms.jdbc.odbc.JdbcOdbc with the desired DLL terminated by a null string, aka "DLL Execution via JDBC Classes."

Data is provided by the National Vulnerability Database (NVD)
MicrosoftVirtual Machine Version2000
MicrosoftVirtual Machine Version3000
MicrosoftVirtual Machine Version3100
MicrosoftVirtual Machine Version3188
MicrosoftVirtual Machine Version3200
MicrosoftVirtual Machine Version3300
MicrosoftVirtual Machine Version3802
MicrosoftVirtual Machine Version3805
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 41.32% 0.971
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P