CVE-2004-1029

Published Mar 1, 2005

Last updated 16 days ago

Overview

Description
The Sun Java Plugin capability in Java 2 Runtime Environment (JRE) 1.4.2_01, 1.4.2_04, and possibly earlier versions, does not properly restrict access between Javascript and Java applets during data transfer, which allows remote attackers to load unsafe classes and execute arbitrary code by using the reflection API to access private Java packages.
Source
cve@mitre.org
NVD status
Modified
Products
java_sdk-rte, jdk, jre, enterprise_firewall, linux, linux, hp-ux, gateway_security_5400

Risk scores

CVSS 2.0

Type
Primary
Base score
9.3
Impact score
10
Exploitability score
8.6
Vector string
AV:N/AC:M/Au:N/C:C/I:C/A:C

Weaknesses

nvd@nist.gov
CWE-264

Social media

Hype score
Not currently trending

Configurations

References

Sources include official advisories and independent security research.