6.4
CVSSv2

CVE-2003-1521

Published: 31/12/2003 Updated: 05/09/2008
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
VMScore: 645
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N

Vulnerability Summary

Sun Java Plug-In 1.4 up to and including 1.4.2_02 allows remote malicious users to repeatedly access the floppy drive via the createXmlDocument method in the org.apache.crimson.tree.XmlDocument class, which violates the Java security model.

Vulnerable Product Search on Vulmon Subscribe to Product

sun java plug-in 1.4

sun java plug-in 1.4.2

sun java plug-in 1.4.2_01

sun java plug-in 1.4.2_02

Exploits

source: wwwsecurityfocuscom/bid/8867/info A weakness has been reported in Java implementations that may constitute unauthorized access by Java applets to floppy devices This weakness appears to present a flaw in the Java security model This issue was reported in Java Plug-in 14x versions on Microsoft Windows operating systems, when r ...