Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2004-1029


The Sun Java Plugin capability in Java 2 Runtime Environment (JRE) 1.4.2_01, 1.4.2_04, and possibly earlier versions, does not properly restrict access between Javascript and Java applets during data transfer, which allows remote attackers to load unsafe classes and execute arbitrary code by using the reflection API to access private Java packages.


Published

2005-03-01T05:00:00.000

Last Modified

2025-04-03T01:03:51.193

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 9.3 (HIGH)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:C/I:C/A:C

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: COMPLETE
  • Integrity Impact: COMPLETE
  • Availability Impact: COMPLETE
Exploitability Score

8.6

Impact Score

10.0

Weaknesses
  • Type: Primary
    CWE-264

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application hp java_sdk-rte 1.3 Yes
Application hp java_sdk-rte 1.4 Yes
Application sun jdk 1.3.1_01 Yes
Application sun jdk 1.3.1_01 Yes
Application sun jdk 1.3.1_01a Yes
Application sun jdk 1.3.1_02 Yes
Application sun jdk 1.3.1_02 Yes
Application sun jdk 1.3.1_02 Yes
Application sun jdk 1.3.1_03 Yes
Application sun jdk 1.3.1_03 Yes
Application sun jdk 1.3.1_03 Yes
Application sun jdk 1.3.1_04 Yes
Application sun jdk 1.3.1_05 Yes
Application sun jdk 1.3.1_05 Yes
Application sun jdk 1.3.1_05 Yes
Application sun jdk 1.3.1_06 Yes
Application sun jdk 1.3.1_06 Yes
Application sun jdk 1.3.1_06 Yes
Application sun jdk 1.3.1_07 Yes
Application sun jdk 1.3.1_07 Yes
Application sun jdk 1.3.1_07 Yes
Application sun jdk 1.4 Yes
Application sun jdk 1.4 Yes
Application sun jdk 1.4 Yes
Application sun jdk 1.4.0_01 Yes
Application sun jdk 1.4.0_02 Yes
Application sun jdk 1.4.0_02 Yes
Application sun jdk 1.4.0_02 Yes
Application sun jdk 1.4.0_03 Yes
Application sun jdk 1.4.0_03 Yes
Application sun jdk 1.4.0_03 Yes
Application sun jdk 1.4.0_4 Yes
Application sun jdk 1.4.0_4 Yes
Application sun jdk 1.4.0_4 Yes
Application sun jdk 1.4.1 Yes
Application sun jdk 1.4.1 Yes
Application sun jdk 1.4.1 Yes
Application sun jdk 1.4.1_01 Yes
Application sun jdk 1.4.1_01 Yes
Application sun jdk 1.4.1_01 Yes
Application sun jdk 1.4.1_02 Yes
Application sun jdk 1.4.1_02 Yes
Application sun jdk 1.4.1_02 Yes
Application sun jdk 1.4.1_03 Yes
Application sun jdk 1.4.1_03 Yes
Application sun jdk 1.4.1_03 Yes
Application sun jdk 1.4.2 Yes
Application sun jdk 1.4.2 Yes
Application sun jdk 1.4.2 Yes
Application sun jdk 1.4.2_01 Yes
Application sun jdk 1.4.2_02 Yes
Application sun jdk 1.4.2_03 Yes
Application sun jdk 1.4.2_03 Yes
Application sun jdk 1.4.2_03 Yes
Application sun jdk 1.4.2_04 Yes
Application sun jdk 1.4.2_04 Yes
Application sun jdk 1.4.2_04 Yes
Application sun jdk 1.4.2_05 Yes
Application sun jdk 1.4.2_05 Yes
Application sun jdk 1.4.2_05 Yes
Application sun jre 1.3.0 Yes
Application sun jre 1.3.0 Yes
Application sun jre 1.3.0 Yes
Application sun jre 1.3.0 Yes
Application sun jre 1.3.0 Yes
Application sun jre 1.3.0 Yes
Application sun jre 1.3.0 Yes
Application sun jre 1.3.0 Yes
Application sun jre 1.3.0 Yes
Application sun jre 1.3.0 Yes
Application sun jre 1.3.0 Yes
Application sun jre 1.3.0 Yes
Application sun jre 1.3.0 Yes
Application sun jre 1.3.1 Yes
Application sun jre 1.3.1 Yes
Application sun jre 1.3.1 Yes
Application sun jre 1.3.1 Yes
Application sun jre 1.3.1 Yes
Application sun jre 1.3.1 Yes
Application sun jre 1.3.1 Yes
Application sun jre 1.3.1 Yes
Application sun jre 1.3.1 Yes
Application sun jre 1.3.1 Yes
Application sun jre 1.3.1_02 Yes
Application sun jre 1.3.1_02 Yes
Application sun jre 1.3.1_02 Yes
Application sun jre 1.3.1_03 Yes
Application sun jre 1.3.1_03 Yes
Application sun jre 1.3.1_03 Yes
Application sun jre 1.3.1_05 Yes
Application sun jre 1.3.1_05 Yes
Application sun jre 1.3.1_05 Yes
Application sun jre 1.3.1_06 Yes
Application sun jre 1.3.1_06 Yes
Application sun jre 1.3.1_06 Yes
Application sun jre 1.3.1_07 Yes
Application sun jre 1.3.1_07 Yes
Application sun jre 1.3.1_07 Yes
Application sun jre 1.3.1_09 Yes
Application sun jre 1.3.1_09 Yes
Application sun jre 1.3.1_09 Yes
Application sun jre 1.4 Yes
Application sun jre 1.4 Yes
Application sun jre 1.4 Yes
Application sun jre 1.4.0_01 Yes
Application sun jre 1.4.0_01 Yes
Application sun jre 1.4.0_02 Yes
Application sun jre 1.4.0_02 Yes
Application sun jre 1.4.0_02 Yes
Application sun jre 1.4.0_03 Yes
Application sun jre 1.4.0_03 Yes
Application sun jre 1.4.0_03 Yes
Application sun jre 1.4.0_04 Yes
Application sun jre 1.4.0_04 Yes
Application sun jre 1.4.0_04 Yes
Application sun jre 1.4.1 Yes
Application sun jre 1.4.1 Yes
Application sun jre 1.4.1 Yes
Application sun jre 1.4.1 Yes
Application sun jre 1.4.1 Yes
Application sun jre 1.4.1 Yes
Application sun jre 1.4.1_01 Yes
Application sun jre 1.4.1_01 Yes
Application sun jre 1.4.1_01 Yes
Application sun jre 1.4.1_02 Yes
Application sun jre 1.4.1_02 Yes
Application sun jre 1.4.1_02 Yes
Application sun jre 1.4.1_07 Yes
Application sun jre 1.4.2 Yes
Application sun jre 1.4.2 Yes
Application sun jre 1.4.2 Yes
Application sun jre 1.4.2 Yes
Application sun jre 1.4.2 Yes
Application sun jre 1.4.2 Yes
Application sun jre 1.4.2 Yes
Application sun jre 1.4.2 Yes
Application sun jre 1.4.2 Yes
Application sun jre 1.4.2 Yes
Application sun jre 1.4.2 Yes
Application sun jre 1.4.2 Yes
Application sun jre 1.4.2 Yes
Application sun jre 1.4.2 Yes
Application sun jre 1.4.2 Yes
Application sun jre 1.4.2 Yes
Application sun jre 1.4.2 Yes
Application sun jre 1.4.2 Yes
Application symantec enterprise_firewall 8.0 Yes
Application symantec enterprise_firewall 8.0 Yes
Application symantec enterprise_firewall 8.0 Yes
Operating System conectiva linux 10.0 Yes
Operating System gentoo linux * Yes
Operating System hp hp-ux 11.00 Yes
Operating System hp hp-ux 11.11 Yes
Operating System hp hp-ux 11.22 Yes
Operating System hp hp-ux 11.23 Yes
Hardware symantec gateway_security_5400 2.0 Yes
Hardware symantec gateway_security_5400 2.0.1 Yes

References