VYPR
Unrated severityNVD Advisory· Published Dec 31, 2004· Updated Apr 16, 2026

CVE-2004-2627

CVE-2004-2627

Description

Java 2 Micro Edition fails to validate bytecode, enabling sandbox escape and arbitrary code execution on mobile devices.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Java 2 Micro Edition fails to validate bytecode, enabling sandbox escape and arbitrary code execution on mobile devices.

Vulnerability

Java 2 Micro Edition (J2ME) does not properly validate bytecode, allowing attackers to escape the Kilobyte Virtual Machine (KVM) sandbox. This flaw affects multiple mobile phone models, including the Nokia 6310i, and likely others running J2ME implementations from Sun Microsystems [2].

Exploitation

An attacker can exploit this vulnerability by delivering a malicious Java application to a target device, e.g., via SMS or download. No authentication is required. The exploit has been demonstrated on a Nokia 6310i handset, where the attacker's Java code executes outside the sandbox [2].

Impact

Successful exploitation leads to complete compromise of Java security on the device. Attackers can access phone data (contacts, SMS messages, dialed numbers), send arbitrary SMS messages, transfer data over the network, and write to permanent memory, potentially creating a backdoor or rendering the phone unusable [2].

Mitigation

No official patch or fix is disclosed in the available references. Users should avoid installing untrusted Java applications on affected devices. As this is an older vulnerability, modern devices may have addressed it through updated J2ME implementations.

AI Insight generated on May 24, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

7

News mentions

0

No linked articles in our index yet.