HIGH · 9.3

CVE-2004-1029

The Sun Java Plugin capability in Java 2 Runtime Environment (JRE) 1.4.2_01, 1.4.2_04, and possibly earlier versions, does not properly restrict access between Javascript and Java applets during data ...

Vulnerability Description

The Sun Java Plugin capability in Java 2 Runtime Environment (JRE) 1.4.2_01, 1.4.2_04, and possibly earlier versions, does not properly restrict access between Javascript and Java applets during data transfer, which allows remote attackers to load unsafe classes and execute arbitrary code by using the reflection API to access private Java packages.

CVSS Score

9.3

HIGH

AV:N/AC:M/Au:N/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
HpJava Sdk-Rte1.3
SunJdk1.3.1_01
SunJre1.3.0
SymantecEnterprise Firewall8.0
ConectivaLinux10.0
GentooLinuxAll versions
HpHp-Ux11.00
SymantecGateway Security 54002.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2004-1029?

CVE-2004-1029 is a vulnerability with a CVSS score of 9.3 (HIGH). The Sun Java Plugin capability in Java 2 Runtime Environment (JRE) 1.4.2_01, 1.4.2_04, and possibly earlier versions, does not properly restrict access between Javascript and Java applets during data ...

How severe is CVE-2004-1029?

CVE-2004-1029 has been rated HIGH with a CVSS base score of 9.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2004-1029?

Check the references section above for vendor advisories and patch information. Affected products include: Hp Java Sdk-Rte, Sun Jdk, Sun Jre, Symantec Enterprise Firewall, Conectiva Linux.