cbcvebase.
CVE-2002-1295
published 2002-11-29

CVE-2002-1295: The Microsoft Java implementation, as used in Internet Explorer, allows remote attackers to cause a denial of service (crash) and possibly conduct other…

PriorityP422high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
15.44%
96.4th percentile
The Microsoft Java implementation, as used in Internet Explorer, allows remote attackers to cause a denial of service (crash) and possibly conduct other unauthorized activities via applet tags in HTML that bypass Java class restrictions (such as private constructors) by providing the class name in the code parameter, aka "Incomplete Java Object Instantiation Vulnerability."

Affected

1 ranges
VendorProductVersion rangeFixed in
microsoftjava_virtual_machine
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.