CVE-2002-0076

3 documents3 sources
Severity
7.5HIGH
EPSS
1.1%
top 22.21%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 19
Latest updateApr 30

Description

Java Runtime Environment (JRE) Bytecode Verifier allows remote attackers to escape the Java sandbox and execute commands via an applet containing an illegal cast operation, as seen in (1) Microsoft VM build 3802 and earlier as used in Internet Explorer 4.x and 5.x, (2) Netscape 6.2.1 and earlier, and possibly other implementations that use vulnerable versions of SDK or JDK, aka a variant of the "Virtual Machine Verifier" vulnerability.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4

Affected Packages5 packages

NVDhp/java_jre-jdk1.1.8, 1.2.2, 1.3+2
NVDsun/jdk1.1.8
NVDsun/jre4 versions+3
NVDsun/sdk5 versions+4

🔴Vulnerability Details

2
GHSA
GHSA-x79p-2mvq-597f: Java Runtime Environment (JRE) Bytecode Verifier allows remote attackers to escape the Java sandbox and execute commands via an applet containing an i2022-04-30
CVEList
CVE-2002-0076: Java Runtime Environment (JRE) Bytecode Verifier allows remote attackers to escape the Java sandbox and execute commands via an applet containing an i2003-04-02
CVE-2002-0076 (HIGH CVSS 7.5) | Java Runtime Environment (JRE) Byte | cvebase.io