VYPR

Java Virtual Machine

by Microsoft

CVEs (28)

  • CVE-2002-1291Nov 29, 2002
    risk 0.01cvss —epss 0.18

    The Microsoft Java implementation, as used in Internet Explorer, allows remote attackers to read arbitrary local files and network shares via an applet tag with a codebase set to a "file://%00" (null character) URL.

  • CVE-2002-1294Nov 29, 2002
    risk 0.01cvss —epss 0.15

    The Microsoft Java implementation, as used in Internet Explorer, can provide HTML object references to applets via Javascript, which allows remote attackers to cause a denial of service (crash due to illegal memory accesses) and possibly conduct other unauthorized activities via…

  • CVE-2002-1295Nov 29, 2002
    risk 0.01cvss —epss 0.15

    The Microsoft Java implementation, as used in Internet Explorer, allows remote attackers to cause a denial of service (crash) and possibly conduct other unauthorized activities via applet tags in HTML that bypass Java class restrictions (such as private constructors) by…

  • CVE-2002-0979Sep 24, 2002
    risk 0.01cvss —epss 0.06

    The Java logging feature for the Java Virtual Machine in Internet Explorer writes output from functions such as System.out.println to a known pathname, which can be used to execute arbitrary code.

  • CVE-2002-0058Mar 15, 2002
    risk 0.01cvss —epss 0.09

    Vulnerability in Java Runtime Environment (JRE) allows remote malicious web sites to hijack or sniff a web client's sessions, when an HTTP proxy is being used, via a Java applet that redirects the session to another server, as seen in (1) Netscape 6.0 through 6.1 and 4.79 and…

  • CVE-2000-0162Feb 18, 2000
    risk 0.01cvss —epss 0.08

    The Microsoft virtual machine (VM) in Internet Explorer 4.x and 5.x allows a remote attacker to read files via a malicious Java applet that escapes the Java sandbox, aka the "VM File Reading" vulnerability.

  • CVE-2000-0327Oct 21, 1999
    risk 0.01cvss —epss 0.12

    Microsoft Virtual Machine (VM) allows remote attackers to escape the Java sandbox and execute commands via an applet containing an illegal cast operation, aka the "Virtual Machine Verifier" vulnerability.

  • CVE-1999-0766Oct 21, 1999
    risk 0.01cvss —epss 0.07

    The Microsoft Java Virtual Machine allows a malicious Java applet to execute arbitrary commands outside of the sandbox environment.

Page 2 of 2