CVE-2004-1029
- EPSS 42.56%
- Published 01.03.2005 05:00:00
- Last modified 03.04.2025 01:03:51
The Sun Java Plugin capability in Java 2 Runtime Environment (JRE) 1.4.2_01, 1.4.2_04, and possibly earlier versions, does not properly restrict access between Javascript and Java applets during data transfer, which allows remote attackers to load un...
- EPSS 0.93%
- Published 31.12.2004 05:00:00
- Last modified 03.04.2025 01:03:51
Integer overflow in the InitialDirContext in Java Runtime Environment (JRE) 1.4.2, 1.5.0 and possibly other versions allows remote attackers to cause a denial of service (Java exception and failed DNS requests) via a large number of DNS requests, whi...
- EPSS 0.93%
- Published 31.12.2004 05:00:00
- Last modified 03.04.2025 01:03:51
readObject in (1) Java Runtime Environment (JRE) and (2) Software Development Kit (SDK) 1.4.0 through 1.4.2_05 allows remote attackers to cause a denial of service (JVM unresponsive) via crafted serialized data.
- EPSS 4.62%
- Published 06.08.2004 04:00:00
- Last modified 03.04.2025 01:03:51
Unknown vulnerability in Sun Java Runtime Environment (JRE) 1.4.2 through 1.4.2_03 allows remote attackers to cause a denial of service (virtual machine hang).
CVE-2003-1123
- EPSS 14.56%
- Published 31.12.2003 05:00:00
- Last modified 03.04.2025 01:03:51
Sun Java Runtime Environment (JRE) and SDK 1.4.0_01 and earlier allows untrusted applets to access certain information within trusted applets, which allows attackers to bypass the restrictions of the Java security model.
CVE-2003-1156
- EPSS 0.06%
- Published 31.12.2003 05:00:00
- Last modified 03.04.2025 01:03:51
Java Runtime Environment (JRE) and Software Development Kit (SDK) 1.4.2 through 1.4.2_02 allows local users to overwrite arbitrary files via a symlink attack on (1) unpack.log, as created by the unpack program, or (2) .mailcap1 and .mime.types1, as c...
- EPSS 1.17%
- Published 31.12.2003 05:00:00
- Last modified 03.04.2025 01:03:51
Sun Java Runtime Environment (JRE) 1.x before 1.4.2_11 and 1.5.x before 1.5.0_06, and as used in multiple web browsers, allows remote attackers to cause a denial of service (application crash) via deeply nested object arrays, which are not properly h...
CVE-2003-0896
- EPSS 26.23%
- Published 17.11.2003 05:00:00
- Last modified 03.04.2025 01:03:51
The loadClass method of the sun.applet.AppletClassLoader class in the Java Virtual Machine (JVM) in Sun SDK and JRE 1.4.1_03 and earlier allows remote attackers to bypass sandbox restrictions and execute arbitrary code via a loaded class name that co...
- EPSS 6%
- Published 31.12.2002 05:00:00
- Last modified 03.04.2025 01:03:51
java.security.AccessController in Sun Java Virtual Machine (JVM) in JRE 1.2.2 and 1.3.1 allows remote attackers to cause a denial of service (JVM crash) via a Java program that calls the doPrivileged method with a null argument.
CVE-2002-0076
- EPSS 1.08%
- Published 19.03.2002 05:00:00
- Last modified 03.04.2025 01:03:51
Java Runtime Environment (JRE) Bytecode Verifier allows remote attackers to escape the Java sandbox and execute commands via an applet containing an illegal cast operation, as seen in (1) Microsoft VM build 3802 and earlier as used in Internet Explor...