4.6

CVE-2003-1156

Exploit

Java Runtime Environment (JRE) and Software Development Kit (SDK) 1.4.2 through 1.4.2_02 allows local users to overwrite arbitrary files via a symlink attack on (1) unpack.log, as created by the unpack program, or (2) .mailcap1 and .mime.types1, as created by the RPM program.

Data is provided by the National Vulnerability Database (NVD)
SunJdk Version1.4.2 Editionlinux
SunJdk Version1.4.2_02 Editionlinux
SunJre Version1.4.2 Editionlinux
SunJre Version1.4.2 Updateupdate2 Editionlinux
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.06% 0.167
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 4.6 3.9 6.4
AV:L/AC:L/Au:N/C:P/I:P/A:P