CVE-2004-1029 : Detail

CVE-2004-1029

A01-Broken Access Control
83.4%V3
Network
2004-11-24
04h00 +00:00
2017-10-09
22h57 +00:00
Notifications for a CVE
Stay informed of any changes for a specific CVE.
Notifications manage

CVE Descriptions

The Sun Java Plugin capability in Java 2 Runtime Environment (JRE) 1.4.2_01, 1.4.2_04, and possibly earlier versions, does not properly restrict access between Javascript and Java applets during data transfer, which allows remote attackers to load unsafe classes and execute arbitrary code by using the reflection API to access private Java packages.

CVE Informations

Related Weaknesses

CWE-ID Weakness Name Source
CWE-264 Category : Permissions, Privileges, and Access Controls
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.

Metrics

Metrics Score Severity CVSS Vector Source
V2 9.3 AV:N/AC:M/Au:N/C:C/I:C/A:C [email protected]

EPSS

EPSS is a scoring model that predicts the likelihood of a vulnerability being exploited.

EPSS Score

The EPSS model produces a probability score between 0 and 1 (0 and 100%). The higher the score, the greater the probability that a vulnerability will be exploited.

EPSS Percentile

The percentile is used to rank CVE according to their EPSS score. For example, a CVE in the 95th percentile according to its EPSS score is more likely to be exploited than 95% of other CVE. Thus, the percentile is used to compare the EPSS score of a CVE with that of other CVE.

Exploit information

Exploit Database EDB-ID : 24763

Publication date : 2004-11-21 23h00 +00:00
Author : Jouko Pynnonen
EDB Verified : Yes

source: https://www.securityfocus.com/bid/11726/info A vulnerability is reported to exist in the access controls of the Java to JavaScript data exchange within web browsers that employ the Sun Java Plug-in. Reports indicate that it is possible for a malicious website that contains JavaScript code to exploit this vulnerability to load a dangerous Java class and to pass this class to an invoked applet. [script language=javascript] var c=document.applets[0].getClass().forName('sun.text.Utility'); alert('got Class object: '+c) [/script]

Products Mentioned

Configuraton 0

Hp>>Java_sdk-rte >> Version 1.3

    Hp>>Java_sdk-rte >> Version 1.4

      Sun>>Jdk >> Version 1.3.1_01

        Sun>>Jdk >> Version 1.3.1_01

          Sun>>Jdk >> Version 1.3.1_01a

            Sun>>Jdk >> Version 1.3.1_02

              Sun>>Jdk >> Version 1.3.1_02

                Sun>>Jdk >> Version 1.3.1_02

                  Sun>>Jdk >> Version 1.3.1_03

                    Sun>>Jdk >> Version 1.3.1_03

                      Sun>>Jdk >> Version 1.3.1_03

                        Sun>>Jdk >> Version 1.3.1_04

                          Sun>>Jdk >> Version 1.3.1_05

                            Sun>>Jdk >> Version 1.3.1_05

                              Sun>>Jdk >> Version 1.3.1_05

                                Sun>>Jdk >> Version 1.3.1_06

                                  Sun>>Jdk >> Version 1.3.1_06

                                    Sun>>Jdk >> Version 1.3.1_06

                                      Sun>>Jdk >> Version 1.3.1_07

                                        Sun>>Jdk >> Version 1.3.1_07

                                          Sun>>Jdk >> Version 1.3.1_07

                                            Sun>>Jdk >> Version 1.4

                                              Sun>>Jdk >> Version 1.4

                                                Sun>>Jdk >> Version 1.4

                                                  Sun>>Jdk >> Version 1.4.0_01

                                                    Sun>>Jdk >> Version 1.4.0_02

                                                      Sun>>Jdk >> Version 1.4.0_02

                                                        Sun>>Jdk >> Version 1.4.0_02

                                                          Sun>>Jdk >> Version 1.4.0_03

                                                            Sun>>Jdk >> Version 1.4.0_03

                                                              Sun>>Jdk >> Version 1.4.0_03

                                                                Sun>>Jdk >> Version 1.4.0_4

                                                                  Sun>>Jdk >> Version 1.4.0_4

                                                                    Sun>>Jdk >> Version 1.4.0_4

                                                                      Sun>>Jdk >> Version 1.4.1

                                                                        Sun>>Jdk >> Version 1.4.1

                                                                          Sun>>Jdk >> Version 1.4.1

                                                                            Sun>>Jdk >> Version 1.4.1_01

                                                                              Sun>>Jdk >> Version 1.4.1_01

                                                                                Sun>>Jdk >> Version 1.4.1_01

                                                                                  Sun>>Jdk >> Version 1.4.1_02

                                                                                    Sun>>Jdk >> Version 1.4.1_02

                                                                                      Sun>>Jdk >> Version 1.4.1_02

                                                                                        Sun>>Jdk >> Version 1.4.1_03

                                                                                          Sun>>Jdk >> Version 1.4.1_03

                                                                                            Sun>>Jdk >> Version 1.4.1_03

                                                                                              Sun>>Jdk >> Version 1.4.2

                                                                                                Sun>>Jdk >> Version 1.4.2

                                                                                                  Sun>>Jdk >> Version 1.4.2

                                                                                                    Sun>>Jdk >> Version 1.4.2_01

                                                                                                      Sun>>Jdk >> Version 1.4.2_02

                                                                                                        Sun>>Jdk >> Version 1.4.2_03

                                                                                                          Sun>>Jdk >> Version 1.4.2_03

                                                                                                            Sun>>Jdk >> Version 1.4.2_03

                                                                                                              Sun>>Jdk >> Version 1.4.2_04

                                                                                                                Sun>>Jdk >> Version 1.4.2_04

                                                                                                                  Sun>>Jdk >> Version 1.4.2_04

                                                                                                                    Sun>>Jdk >> Version 1.4.2_05

                                                                                                                      Sun>>Jdk >> Version 1.4.2_05

                                                                                                                        Sun>>Jdk >> Version 1.4.2_05

                                                                                                                          Sun>>Jre >> Version 1.3.0

                                                                                                                          Sun>>Jre >> Version 1.3.0

                                                                                                                            Sun>>Jre >> Version 1.3.0

                                                                                                                              Sun>>Jre >> Version 1.3.0

                                                                                                                                Sun>>Jre >> Version 1.3.0

                                                                                                                                Sun>>Jre >> Version 1.3.0

                                                                                                                                  Sun>>Jre >> Version 1.3.0

                                                                                                                                    Sun>>Jre >> Version 1.3.0

                                                                                                                                      Sun>>Jre >> Version 1.3.0

                                                                                                                                        Sun>>Jre >> Version 1.3.0

                                                                                                                                          Sun>>Jre >> Version 1.3.0

                                                                                                                                            Sun>>Jre >> Version 1.3.0

                                                                                                                                              Sun>>Jre >> Version 1.3.0

                                                                                                                                                Sun>>Jre >> Version 1.3.1

                                                                                                                                                  Sun>>Jre >> Version 1.3.1

                                                                                                                                                    Sun>>Jre >> Version 1.3.1

                                                                                                                                                      Sun>>Jre >> Version 1.3.1

                                                                                                                                                        Sun>>Jre >> Version 1.3.1

                                                                                                                                                          Sun>>Jre >> Version 1.3.1

                                                                                                                                                            Sun>>Jre >> Version 1.3.1

                                                                                                                                                              Sun>>Jre >> Version 1.3.1

                                                                                                                                                                Sun>>Jre >> Version 1.3.1

                                                                                                                                                                  Sun>>Jre >> Version 1.3.1

                                                                                                                                                                    Sun>>Jre >> Version 1.3.1_02

                                                                                                                                                                      Sun>>Jre >> Version 1.3.1_02

                                                                                                                                                                        Sun>>Jre >> Version 1.3.1_02

                                                                                                                                                                          Sun>>Jre >> Version 1.3.1_03

                                                                                                                                                                            Sun>>Jre >> Version 1.3.1_03

                                                                                                                                                                              Sun>>Jre >> Version 1.3.1_03

                                                                                                                                                                                Sun>>Jre >> Version 1.3.1_05

                                                                                                                                                                                  Sun>>Jre >> Version 1.3.1_05

                                                                                                                                                                                    Sun>>Jre >> Version 1.3.1_05

                                                                                                                                                                                      Sun>>Jre >> Version 1.3.1_06

                                                                                                                                                                                        Sun>>Jre >> Version 1.3.1_06

                                                                                                                                                                                          Sun>>Jre >> Version 1.3.1_06

                                                                                                                                                                                            Sun>>Jre >> Version 1.3.1_07

                                                                                                                                                                                              Sun>>Jre >> Version 1.3.1_07

                                                                                                                                                                                                Sun>>Jre >> Version 1.3.1_07

                                                                                                                                                                                                  Sun>>Jre >> Version 1.3.1_09

                                                                                                                                                                                                    Sun>>Jre >> Version 1.3.1_09

                                                                                                                                                                                                      Sun>>Jre >> Version 1.3.1_09

                                                                                                                                                                                                        Sun>>Jre >> Version 1.4

                                                                                                                                                                                                          Sun>>Jre >> Version 1.4

                                                                                                                                                                                                            Sun>>Jre >> Version 1.4

                                                                                                                                                                                                              Sun>>Jre >> Version 1.4.0_01

                                                                                                                                                                                                                Sun>>Jre >> Version 1.4.0_01

                                                                                                                                                                                                                  Sun>>Jre >> Version 1.4.0_02

                                                                                                                                                                                                                    Sun>>Jre >> Version 1.4.0_02

                                                                                                                                                                                                                      Sun>>Jre >> Version 1.4.0_02

                                                                                                                                                                                                                        Sun>>Jre >> Version 1.4.0_03

                                                                                                                                                                                                                          Sun>>Jre >> Version 1.4.0_03

                                                                                                                                                                                                                            Sun>>Jre >> Version 1.4.0_03

                                                                                                                                                                                                                              Sun>>Jre >> Version 1.4.0_04

                                                                                                                                                                                                                                Sun>>Jre >> Version 1.4.0_04

                                                                                                                                                                                                                                  Sun>>Jre >> Version 1.4.0_04

                                                                                                                                                                                                                                    Sun>>Jre >> Version 1.4.1

                                                                                                                                                                                                                                      Sun>>Jre >> Version 1.4.1

                                                                                                                                                                                                                                        Sun>>Jre >> Version 1.4.1

                                                                                                                                                                                                                                          Sun>>Jre >> Version 1.4.1

                                                                                                                                                                                                                                            Sun>>Jre >> Version 1.4.1

                                                                                                                                                                                                                                              Sun>>Jre >> Version 1.4.1

                                                                                                                                                                                                                                                Sun>>Jre >> Version 1.4.1_01

                                                                                                                                                                                                                                                  Sun>>Jre >> Version 1.4.1_01

                                                                                                                                                                                                                                                    Sun>>Jre >> Version 1.4.1_01

                                                                                                                                                                                                                                                      Sun>>Jre >> Version 1.4.1_02

                                                                                                                                                                                                                                                        Sun>>Jre >> Version 1.4.1_02

                                                                                                                                                                                                                                                          Sun>>Jre >> Version 1.4.1_02

                                                                                                                                                                                                                                                            Sun>>Jre >> Version 1.4.1_07

                                                                                                                                                                                                                                                              Sun>>Jre >> Version 1.4.2

                                                                                                                                                                                                                                                                Sun>>Jre >> Version 1.4.2

                                                                                                                                                                                                                                                                  Sun>>Jre >> Version 1.4.2

                                                                                                                                                                                                                                                                    Sun>>Jre >> Version 1.4.2

                                                                                                                                                                                                                                                                      Sun>>Jre >> Version 1.4.2

                                                                                                                                                                                                                                                                        Sun>>Jre >> Version 1.4.2

                                                                                                                                                                                                                                                                          Sun>>Jre >> Version 1.4.2

                                                                                                                                                                                                                                                                            Sun>>Jre >> Version 1.4.2

                                                                                                                                                                                                                                                                              Sun>>Jre >> Version 1.4.2

                                                                                                                                                                                                                                                                                Sun>>Jre >> Version 1.4.2

                                                                                                                                                                                                                                                                                  Sun>>Jre >> Version 1.4.2

                                                                                                                                                                                                                                                                                    Sun>>Jre >> Version 1.4.2

                                                                                                                                                                                                                                                                                      Sun>>Jre >> Version 1.4.2

                                                                                                                                                                                                                                                                                        Sun>>Jre >> Version 1.4.2

                                                                                                                                                                                                                                                                                          Sun>>Jre >> Version 1.4.2

                                                                                                                                                                                                                                                                                            Sun>>Jre >> Version 1.4.2

                                                                                                                                                                                                                                                                                              Sun>>Jre >> Version 1.4.2

                                                                                                                                                                                                                                                                                                Sun>>Jre >> Version 1.4.2

                                                                                                                                                                                                                                                                                                  Symantec>>Enterprise_firewall >> Version 8.0

                                                                                                                                                                                                                                                                                                  Symantec>>Enterprise_firewall >> Version 8.0

                                                                                                                                                                                                                                                                                                    Symantec>>Enterprise_firewall >> Version 8.0

                                                                                                                                                                                                                                                                                                      Conectiva>>Linux >> Version 10.0

                                                                                                                                                                                                                                                                                                      Configuraton 0

                                                                                                                                                                                                                                                                                                      Gentoo>>Linux >> Version *

                                                                                                                                                                                                                                                                                                      Hp>>Hp-ux >> Version 11.00

                                                                                                                                                                                                                                                                                                      Hp>>Hp-ux >> Version 11.11

                                                                                                                                                                                                                                                                                                      Hp>>Hp-ux >> Version 11.22

                                                                                                                                                                                                                                                                                                      Hp>>Hp-ux >> Version 11.23

                                                                                                                                                                                                                                                                                                        Configuraton 0

                                                                                                                                                                                                                                                                                                        Symantec>>Gateway_security_5400 >> Version 2.0

                                                                                                                                                                                                                                                                                                          Symantec>>Gateway_security_5400 >> Version 2.0.1

                                                                                                                                                                                                                                                                                                            References

                                                                                                                                                                                                                                                                                                            http://secunia.com/advisories/13271
                                                                                                                                                                                                                                                                                                            Tags : third-party-advisory, x_refsource_SECUNIA
                                                                                                                                                                                                                                                                                                            http://secunia.com/advisories/29035
                                                                                                                                                                                                                                                                                                            Tags : third-party-advisory, x_refsource_SECUNIA
                                                                                                                                                                                                                                                                                                            http://securityreason.com/securityalert/61
                                                                                                                                                                                                                                                                                                            Tags : third-party-advisory, x_refsource_SREASON
                                                                                                                                                                                                                                                                                                            http://www.securityfocus.com/bid/12317
                                                                                                                                                                                                                                                                                                            Tags : vdb-entry, x_refsource_BID
                                                                                                                                                                                                                                                                                                            http://www.vupen.com/english/advisories/2008/0599
                                                                                                                                                                                                                                                                                                            Tags : vdb-entry, x_refsource_VUPEN
                                                                                                                                                                                                                                                                                                            http://sunsolve.sun.com/search/document.do?assetkey=1-26-101523-1
                                                                                                                                                                                                                                                                                                            Tags : vendor-advisory, x_refsource_SUNALERT
                                                                                                                                                                                                                                                                                                            http://www.kb.cert.org/vuls/id/760344
                                                                                                                                                                                                                                                                                                            Tags : third-party-advisory, x_refsource_CERT-VN
                                                                                                                                                                                                                                                                                                            http://sunsolve.sun.com/search/document.do?assetkey=1-26-57591-1
                                                                                                                                                                                                                                                                                                            Tags : vendor-advisory, x_refsource_SUNALERT