CVE-2002-1293

3 documents3 sources
Severity
7.5HIGH
EPSS
2.5%
top 14.59%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 29
Latest updateApr 30

Description

The Microsoft Java implementation, as used in Internet Explorer, provides a public load0() method for the CabCracker class (com.ms.vm.loader.CabCracker), which allows remote attackers to bypass the security checks that are performed by the load() method.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-3cqw-4qwf-ghv9: The Microsoft Java implementation, as used in Internet Explorer, provides a public load0() method for the CabCracker class (com2022-04-30
CVEList
CVE-2002-1293: The Microsoft Java implementation, as used in Internet Explorer, provides a public load0() method for the CabCracker class (com2002-11-14
CVE-2002-1293 (HIGH CVSS 7.5) | The Microsoft Java implementation | cvebase.io