CVE-2004-1029
high · 9.3The Sun Java Plugin capability in Java 2 Runtime Environment (JRE) 1.4.2_01, 1.4.2_04, and possibly earlier versions, does not properly restrict access between Javascript and Java applets during data transfer, which allows remote attackers to load unsafe classes and execute arbitrary code by using the reflection API to access private Java packages.
9.3
CVSS
17.0%
EPSS (exploit prob.)
97th
EPSS percentile
2005-03-01
Published
AV:N/AC:M/Au:N/C:C/I:C/A:C
Weaknesses
CWE-264
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| hp | java_sdk-rte | 1.3 |
| hp | java_sdk-rte | 1.4 |
| sun | jdk | 1.3.1_01 |
| sun | jdk | 1.3.1_01 |
| sun | jdk | 1.3.1_01a |
| sun | jdk | 1.3.1_02 |
| sun | jdk | 1.3.1_02 |
| sun | jdk | 1.3.1_02 |
| sun | jdk | 1.3.1_03 |
| sun | jdk | 1.3.1_03 |
| sun | jdk | 1.3.1_03 |
| sun | jdk | 1.3.1_04 |
| sun | jdk | 1.3.1_05 |
| sun | jdk | 1.3.1_05 |
| sun | jdk | 1.3.1_05 |
| sun | jdk | 1.3.1_06 |
| sun | jdk | 1.3.1_06 |
| sun | jdk | 1.3.1_06 |
| sun | jdk | 1.3.1_07 |
| sun | jdk | 1.3.1_07 |
| sun | jdk | 1.3.1_07 |
| sun | jdk | 1.4 |
| sun | jdk | 1.4 |
| sun | jdk | 1.4 |
| sun | jdk | 1.4.0_01 |
| sun | jdk | 1.4.0_02 |
| sun | jdk | 1.4.0_02 |
| sun | jdk | 1.4.0_02 |
| sun | jdk | 1.4.0_03 |
| sun | jdk | 1.4.0_03 |
| sun | jdk | 1.4.0_03 |
| sun | jdk | 1.4.0_4 |
| sun | jdk | 1.4.0_4 |
| sun | jdk | 1.4.0_4 |
| sun | jdk | 1.4.1 |
| sun | jdk | 1.4.1 |
| sun | jdk | 1.4.1 |
| sun | jdk | 1.4.1_01 |
| sun | jdk | 1.4.1_01 |
| sun | jdk | 1.4.1_01 |
Check a specific version with /api/v1/cve/match.
References
- http://jouko.iki.fi/adv/javaplugin.html
- http://lists.apple.com/archives/security-announce/2005/Feb/msg00000.html
- http://rpmfind.net/linux/RPM/suse/updates/9.3/i386/rpm/i586/java-1_4_2-sun-src-1.4.2.08-0.1.i586.html
- http://secunia.com/advisories/13271
- http://secunia.com/advisories/29035
- http://securityreason.com/securityalert/61
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-101523-1
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-57591-1
- http://www-1.ibm.com/support/docview.wss?uid=swg21257249
- http://www.idefense.com/application/poi/display?id=158&type=vulnerabilities
- http://www.kb.cert.org/vuls/id/760344
- http://www.securityfocus.com/bid/12317
- http://www.vupen.com/english/advisories/2008/0599
- https://exchange.xforce.ibmcloud.com/vulnerabilities/18188
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5674
- http://jouko.iki.fi/adv/javaplugin.html
- http://lists.apple.com/archives/security-announce/2005/Feb/msg00000.html
- http://rpmfind.net/linux/RPM/suse/updates/9.3/i386/rpm/i586/java-1_4_2-sun-src-1.4.2.08-0.1.i586.html
- http://secunia.com/advisories/13271
- http://secunia.com/advisories/29035
- http://securityreason.com/securityalert/61
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-101523-1
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-57591-1
- http://www-1.ibm.com/support/docview.wss?uid=swg21257249
- http://www.idefense.com/application/poi/display?id=158&type=vulnerabilities
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2004-1029