CVE-2004-1029

Description

The Sun Java Plugin capability in Java 2 Runtime Environment (JRE) 1.4.2_01, 1.4.2_04, and possibly earlier versions, does not properly restrict access between Javascript and Java applets during data transfer, which allows remote attackers to load unsafe classes and execute arbitrary code by using the reflection API to access private Java packages.

Risk Information

Base Score
9.8
MODERATE
Vector
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
37.032

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2004-1029,CVE-2004-2540 are affected in Java jdk (x64) 4.2_05(x64)Windows
Vulnerabilities CVE-2004-1029,CVE-2004-2540 are affected in Java jdk 4.2_05Windows
Multiple vulnerabilities affected in Java jre (x64) 4.2(x64)Windows
Multiple vulnerabilities affected in Java jre 4.2Windows
Multiple Vulnerabilities affected in hp-ux 11.23-ia64_64-bitNCM
Multiple Vulnerabilities affected in hp-ux 11.11NCM
Multiple Vulnerabilities affected in hp-ux 11.22NCM
Multiple Vulnerabilities affected in hp-ux 11.00NCM
Vulnerabilities CVE-2004-1029 are affected in java_sdk-rte 1.4-hp-ux_pa-riscNCM
Vulnerabilities CVE-2004-1029 are affected in java_sdk-rte 1.3-hp-ux_pa-riscNCM
CVE-2004-1029NCM

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234