6.8
CVSSv2

CVE-2003-1516

Published: 31/12/2003 Updated: 05/09/2008
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

The org.apache.xalan.processor.XSLProcessorVersion class in Java Plug-in 1.4.2_01 allows signed and unsigned applets to share variables, which violates the Java security model and could allow remote malicious users to read or write data belonging to a signed applet.

Vulnerable Product Search on Vulmon Subscribe to Product

sun java plug-in 1.4.2_01

Exploits

source: wwwsecurityfocuscom/bid/8857/info A vulnerability has been reported in Java implementations that may potentially allow Java applets from two different domains to violate the sandbox security model and share read/write access to data areas This violates the principle of isolation that should be enforced by Java and it is possible ...