4.6

CVE-2003-1156

Exploit

Java Runtime Environment (JRE) and Software Development Kit (SDK) 1.4.2 through 1.4.2_02 allows local users to overwrite arbitrary files via a symlink attack on (1) unpack.log, as created by the unpack program, or (2) .mailcap1 and .mime.types1, as created by the RPM program.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SunJdk Version1.4.2 Editionlinux
SunJdk Version1.4.2_02 Editionlinux
SunJre Version1.4.2 Editionlinux
SunJre Version1.4.2 Updateupdate2 Editionlinux
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.06% 0.167
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.6 3.9 6.4
AV:L/AC:L/Au:N/C:P/I:P/A:P