VYPR

Java Plug In

by Sun Corporation

CVEs (4)

  • CVE-2003-1521Dec 31, 2003
    risk 0.03cvss epss 0.02

    Sun Java Plug-In 1.4 through 1.4.2_02 allows remote attackers to repeatedly access the floppy drive via the createXmlDocument method in the org.apache.crimson.tree.XmlDocument class, which violates the Java security model.

  • CVE-2003-1516Dec 31, 2003
    risk 0.03cvss epss 0.03

    The org.apache.xalan.processor.XSLProcessorVersion class in Java Plug-in 1.4.2_01 allows signed and unsigned applets to share variables, which violates the Java security model and could allow remote attackers to read or write data belonging to a signed applet.

  • CVE-2005-4845Dec 31, 2005
    risk 0.00cvss epss 0.01

    The Java Plug-in 1.4.2_03 and 1.4.2_04 controls, and the 1.4.2_03 and 1.4.2_04 redirector controls, allow remote attackers to cause a denial of service (Internet Explorer crash) by creating a COM object of the class associated with the control's CLSID, which is not intended for use within Internet Explorer.

  • CVE-2001-1008Aug 31, 2001
    risk 0.00cvss epss 0.01

    Java Plugin 1.4 for JRE 1.3 executes signed applets even if the certificate is expired, which could allow remote attackers to conduct unauthorized activities via an applet that has been signed by an expired certificate.