The Sun Java Plugin capability in Java 2 Runtime Environment (JRE) 1.4.2_01, 1.4.2_04, and possibly earlier versions, does not properly restrict access between Javascript and Java applets during data transfer, which allows remote attackers to load unsafe classes and execute arbitrary code by using the reflection API to access private Java packages.
2005-03-01T05:00:00.000
2025-04-03T01:03:51.193
Deferred
CVSSv2: 9.3 (HIGH)
AV:N/AC:M/Au:N/C:C/I:C/A:C
8.6
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | hp | java_sdk-rte | 1.3 | Yes |
Application | hp | java_sdk-rte | 1.4 | Yes |
Application | sun | jdk | 1.3.1_01 | Yes |
Application | sun | jdk | 1.3.1_01 | Yes |
Application | sun | jdk | 1.3.1_01a | Yes |
Application | sun | jdk | 1.3.1_02 | Yes |
Application | sun | jdk | 1.3.1_02 | Yes |
Application | sun | jdk | 1.3.1_02 | Yes |
Application | sun | jdk | 1.3.1_03 | Yes |
Application | sun | jdk | 1.3.1_03 | Yes |
Application | sun | jdk | 1.3.1_03 | Yes |
Application | sun | jdk | 1.3.1_04 | Yes |
Application | sun | jdk | 1.3.1_05 | Yes |
Application | sun | jdk | 1.3.1_05 | Yes |
Application | sun | jdk | 1.3.1_05 | Yes |
Application | sun | jdk | 1.3.1_06 | Yes |
Application | sun | jdk | 1.3.1_06 | Yes |
Application | sun | jdk | 1.3.1_06 | Yes |
Application | sun | jdk | 1.3.1_07 | Yes |
Application | sun | jdk | 1.3.1_07 | Yes |
Application | sun | jdk | 1.3.1_07 | Yes |
Application | sun | jdk | 1.4 | Yes |
Application | sun | jdk | 1.4 | Yes |
Application | sun | jdk | 1.4 | Yes |
Application | sun | jdk | 1.4.0_01 | Yes |
Application | sun | jdk | 1.4.0_02 | Yes |
Application | sun | jdk | 1.4.0_02 | Yes |
Application | sun | jdk | 1.4.0_02 | Yes |
Application | sun | jdk | 1.4.0_03 | Yes |
Application | sun | jdk | 1.4.0_03 | Yes |
Application | sun | jdk | 1.4.0_03 | Yes |
Application | sun | jdk | 1.4.0_4 | Yes |
Application | sun | jdk | 1.4.0_4 | Yes |
Application | sun | jdk | 1.4.0_4 | Yes |
Application | sun | jdk | 1.4.1 | Yes |
Application | sun | jdk | 1.4.1 | Yes |
Application | sun | jdk | 1.4.1 | Yes |
Application | sun | jdk | 1.4.1_01 | Yes |
Application | sun | jdk | 1.4.1_01 | Yes |
Application | sun | jdk | 1.4.1_01 | Yes |
Application | sun | jdk | 1.4.1_02 | Yes |
Application | sun | jdk | 1.4.1_02 | Yes |
Application | sun | jdk | 1.4.1_02 | Yes |
Application | sun | jdk | 1.4.1_03 | Yes |
Application | sun | jdk | 1.4.1_03 | Yes |
Application | sun | jdk | 1.4.1_03 | Yes |
Application | sun | jdk | 1.4.2 | Yes |
Application | sun | jdk | 1.4.2 | Yes |
Application | sun | jdk | 1.4.2 | Yes |
Application | sun | jdk | 1.4.2_01 | Yes |
Application | sun | jdk | 1.4.2_02 | Yes |
Application | sun | jdk | 1.4.2_03 | Yes |
Application | sun | jdk | 1.4.2_03 | Yes |
Application | sun | jdk | 1.4.2_03 | Yes |
Application | sun | jdk | 1.4.2_04 | Yes |
Application | sun | jdk | 1.4.2_04 | Yes |
Application | sun | jdk | 1.4.2_04 | Yes |
Application | sun | jdk | 1.4.2_05 | Yes |
Application | sun | jdk | 1.4.2_05 | Yes |
Application | sun | jdk | 1.4.2_05 | Yes |
Application | sun | jre | 1.3.0 | Yes |
Application | sun | jre | 1.3.0 | Yes |
Application | sun | jre | 1.3.0 | Yes |
Application | sun | jre | 1.3.0 | Yes |
Application | sun | jre | 1.3.0 | Yes |
Application | sun | jre | 1.3.0 | Yes |
Application | sun | jre | 1.3.0 | Yes |
Application | sun | jre | 1.3.0 | Yes |
Application | sun | jre | 1.3.0 | Yes |
Application | sun | jre | 1.3.0 | Yes |
Application | sun | jre | 1.3.0 | Yes |
Application | sun | jre | 1.3.0 | Yes |
Application | sun | jre | 1.3.0 | Yes |
Application | sun | jre | 1.3.1 | Yes |
Application | sun | jre | 1.3.1 | Yes |
Application | sun | jre | 1.3.1 | Yes |
Application | sun | jre | 1.3.1 | Yes |
Application | sun | jre | 1.3.1 | Yes |
Application | sun | jre | 1.3.1 | Yes |
Application | sun | jre | 1.3.1 | Yes |
Application | sun | jre | 1.3.1 | Yes |
Application | sun | jre | 1.3.1 | Yes |
Application | sun | jre | 1.3.1 | Yes |
Application | sun | jre | 1.3.1_02 | Yes |
Application | sun | jre | 1.3.1_02 | Yes |
Application | sun | jre | 1.3.1_02 | Yes |
Application | sun | jre | 1.3.1_03 | Yes |
Application | sun | jre | 1.3.1_03 | Yes |
Application | sun | jre | 1.3.1_03 | Yes |
Application | sun | jre | 1.3.1_05 | Yes |
Application | sun | jre | 1.3.1_05 | Yes |
Application | sun | jre | 1.3.1_05 | Yes |
Application | sun | jre | 1.3.1_06 | Yes |
Application | sun | jre | 1.3.1_06 | Yes |
Application | sun | jre | 1.3.1_06 | Yes |
Application | sun | jre | 1.3.1_07 | Yes |
Application | sun | jre | 1.3.1_07 | Yes |
Application | sun | jre | 1.3.1_07 | Yes |
Application | sun | jre | 1.3.1_09 | Yes |
Application | sun | jre | 1.3.1_09 | Yes |
Application | sun | jre | 1.3.1_09 | Yes |
Application | sun | jre | 1.4 | Yes |
Application | sun | jre | 1.4 | Yes |
Application | sun | jre | 1.4 | Yes |
Application | sun | jre | 1.4.0_01 | Yes |
Application | sun | jre | 1.4.0_01 | Yes |
Application | sun | jre | 1.4.0_02 | Yes |
Application | sun | jre | 1.4.0_02 | Yes |
Application | sun | jre | 1.4.0_02 | Yes |
Application | sun | jre | 1.4.0_03 | Yes |
Application | sun | jre | 1.4.0_03 | Yes |
Application | sun | jre | 1.4.0_03 | Yes |
Application | sun | jre | 1.4.0_04 | Yes |
Application | sun | jre | 1.4.0_04 | Yes |
Application | sun | jre | 1.4.0_04 | Yes |
Application | sun | jre | 1.4.1 | Yes |
Application | sun | jre | 1.4.1 | Yes |
Application | sun | jre | 1.4.1 | Yes |
Application | sun | jre | 1.4.1 | Yes |
Application | sun | jre | 1.4.1 | Yes |
Application | sun | jre | 1.4.1 | Yes |
Application | sun | jre | 1.4.1_01 | Yes |
Application | sun | jre | 1.4.1_01 | Yes |
Application | sun | jre | 1.4.1_01 | Yes |
Application | sun | jre | 1.4.1_02 | Yes |
Application | sun | jre | 1.4.1_02 | Yes |
Application | sun | jre | 1.4.1_02 | Yes |
Application | sun | jre | 1.4.1_07 | Yes |
Application | sun | jre | 1.4.2 | Yes |
Application | sun | jre | 1.4.2 | Yes |
Application | sun | jre | 1.4.2 | Yes |
Application | sun | jre | 1.4.2 | Yes |
Application | sun | jre | 1.4.2 | Yes |
Application | sun | jre | 1.4.2 | Yes |
Application | sun | jre | 1.4.2 | Yes |
Application | sun | jre | 1.4.2 | Yes |
Application | sun | jre | 1.4.2 | Yes |
Application | sun | jre | 1.4.2 | Yes |
Application | sun | jre | 1.4.2 | Yes |
Application | sun | jre | 1.4.2 | Yes |
Application | sun | jre | 1.4.2 | Yes |
Application | sun | jre | 1.4.2 | Yes |
Application | sun | jre | 1.4.2 | Yes |
Application | sun | jre | 1.4.2 | Yes |
Application | sun | jre | 1.4.2 | Yes |
Application | sun | jre | 1.4.2 | Yes |
Application | symantec | enterprise_firewall | 8.0 | Yes |
Application | symantec | enterprise_firewall | 8.0 | Yes |
Application | symantec | enterprise_firewall | 8.0 | Yes |
Operating System | conectiva | linux | 10.0 | Yes |
Operating System | gentoo | linux | * | Yes |
Operating System | hp | hp-ux | 11.00 | Yes |
Operating System | hp | hp-ux | 11.11 | Yes |
Operating System | hp | hp-ux | 11.22 | Yes |
Operating System | hp | hp-ux | 11.23 | Yes |
Hardware | symantec | gateway_security_5400 | 2.0 | Yes |
Hardware | symantec | gateway_security_5400 | 2.0.1 | Yes |