9.3
CVE-2004-1029
- EPSS 37.03%
- Veröffentlicht 01.03.2005 05:00:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
The Sun Java Plugin capability in Java 2 Runtime Environment (JRE) 1.4.2_01, 1.4.2_04, and possibly earlier versions, does not properly restrict access between Javascript and Java applets during data transfer, which allows remote attackers to load unsafe classes and execute arbitrary code by using the reflection API to access private Java packages.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Hp ≫ Java Sdk-rte Version1.3 Editionhp-ux_pa-risc
Hp ≫ Java Sdk-rte Version1.4 Editionhp-ux_pa-risc
Symantec ≫ Enterprise Firewall Version8.0
Symantec ≫ Enterprise Firewall Version8.0 Editionsolaris
Symantec ≫ Enterprise Firewall Version8.0 Editionwindows_2000_nt
Symantec ≫ Gateway Security 5400 Version2.0
Symantec ≫ Gateway Security 5400 Version2.0.1
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 37.03% | 0.97 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 9.3 | 8.6 | 10 |
AV:N/AC:M/Au:N/C:C/I:C/A:C
|