Sun Java Plug-In vulnerabilities
4 known vulnerabilities affecting sun/java_plug-in.
Total CVEs
4
CISA KEV
0
Public exploits
2
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM3
Vulnerabilities
Page 1 of 1
CVE-2005-4845MEDIUMCVSS 5.0v1.4.2_03v1.4.2_042005-12-31
CVE-2005-4845 [MEDIUM] CWE-16 CVE-2005-4845: The Java Plug-in 1.4.2_03 and 1.4.2_04 controls, and the 1.4.2_03 and 1.4.2_04 <applet> redirector c
The Java Plug-in 1.4.2_03 and 1.4.2_04 controls, and the 1.4.2_03 and 1.4.2_04 redirector controls, allow remote attackers to cause a denial of service (Internet Explorer crash) by creating a COM object of the class associated with the control's CLSID, which is not intended for use within Internet Explorer.
nvd
CVE-2003-1516MEDIUMCVSS 6.8PoCv1.4.2_012003-12-31
CVE-2003-1516 [MEDIUM] CVE-2003-1516: The org.apache.xalan.processor.XSLProcessorVersion class in Java Plug-in 1.4.2_01 allows signed and
The org.apache.xalan.processor.XSLProcessorVersion class in Java Plug-in 1.4.2_01 allows signed and unsigned applets to share variables, which violates the Java security model and could allow remote attackers to read or write data belonging to a signed applet.
nvd
CVE-2003-1521MEDIUMCVSS 6.4PoCv1.4v1.4.2+2 more2003-12-31
CVE-2003-1521 [MEDIUM] CVE-2003-1521: Sun Java Plug-In 1.4 through 1.4.2_02 allows remote attackers to repeatedly access the floppy drive
Sun Java Plug-In 1.4 through 1.4.2_02 allows remote attackers to repeatedly access the floppy drive via the createXmlDocument method in the org.apache.crimson.tree.XmlDocument class, which violates the Java security model.
nvd
CVE-2001-1008HIGHCVSS 7.5v1.42001-08-31
CVE-2001-1008 [HIGH] CVE-2001-1008: Java Plugin 1.4 for JRE 1.3 executes signed applets even if the certificate is expired, which could
Java Plugin 1.4 for JRE 1.3 executes signed applets even if the certificate is expired, which could allow remote attackers to conduct unauthorized activities via an applet that has been signed by an expired certificate.
nvd