9.3
CVSSv2

CVE-2004-1029

Published: 01/03/2005 Updated: 11/10/2017
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 935
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

The Sun Java Plugin capability in Java 2 Runtime Environment (JRE) 1.4.2_01, 1.4.2_04, and possibly earlier versions, does not properly restrict access between Javascript and Java applets during data transfer, which allows remote malicious users to load unsafe classes and execute arbitrary code by using the reflection API to access private Java packages.

Vulnerable Product Search on Vulmon Subscribe to Product

sun jre 1.4.0 02

sun jre 1.3.1 06

symantec enterprise firewall 8.0

sun jre 1.3.1 03

sun jre 1.4.0 04

sun jdk 1.4.0 4

sun jdk 1.3.1 06

sun jdk 1.4.1 03

sun jre 1.4.2

sun jdk 1.4.2 05

sun jdk 1.4.0 02

sun jre 1.4.0 01

sun jdk 1.4.2

sun jdk 1.3.1 02

sun jdk 1.3.1 01

sun jre 1.4.1

sun jdk 1.4.0 03

sun jre 1.3.1 07

sun jdk 1.3.1 03

sun jdk 1.4.1 02

sun jdk 1.3.1 07

sun jdk 1.4

sun jre 1.3.1

sun jre 1.4.0 03

sun jre 1.4.1 02

sun jre 1.4

sun jre 1.4.1 01

sun jdk 1.4.2 01

sun jdk 1.3.1 05

sun jdk 1.4.2 04

sun jre 1.3.1 05

sun jdk 1.4.1

sun jre 1.3.0

sun jdk 1.4.2 03

sun jdk 1.4.0 01

sun jdk 1.4.1 01

sun jre 1.3.1 02

sun jdk 1.3.1 01a

sun jre 1.3.1 09

hp java sdk-rte 1.4

sun jdk 1.3.1 04

sun jdk 1.4.2 02

conectiva linux 10.0

hp java sdk-rte 1.3

sun jre 1.4.1 07

hp hp-ux 11.11

hp hp-ux 11.00

hp hp-ux 11.23

hp hp-ux 11.22

gentoo linux

symantec gateway security 5400 2.0.1

symantec gateway security 5400 2.0

Exploits

source: wwwsecurityfocuscom/bid/11726/info A vulnerability is reported to exist in the access controls of the Java to JavaScript data exchange within web browsers that employ the Sun Java Plug-in Reports indicate that it is possible for a malicious website that contains JavaScript code to exploit this vulnerability to load a dangerous Ja ...