← Back

CVE-2002-0076

nvd nist
Published: Mar 19, 2002Modified: Apr 16, 2026

JSON object

Loading...
7.5
Vector
AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploitability: 10.0 / Impact: 6.4
Source: NVD

Description

Java Runtime Environment (JRE) Bytecode Verifier allows remote attackers to escape the Java sandbox and execute commands via an applet containing an illegal cast operation, as seen in (1) Microsoft VM build 3802 and earlier as used in Internet Explorer 4.x and 5.x, (2) Netscape 6.2.1 and earlier, and possibly other implementations that use vulnerable versions of SDK or JDK, aka a variant of the "Virtual Machine Verifier" vulnerability.

Affected (17)

1 product
Java Jre Jdk
1 product
Virtual Machine
3 products
Jdk
Jre
Sdk
Configuration A
17 vulnerable
Vulnerable SoftwareAffected Versions
Hp
Version 1.1.8
Version 1.2.2
Version 1.3
Version 3802
Sun
Version 1.1.8 update14
Version 1.1.8 update8
Sun
Version 1.1.8 update14
Version 1.1.8 update8
Version 1.2.2 update10
Version 1.3.0 update5
Version 1.3.1 update1
Version 1.3.1 update1a
Sun
Version 1.2.2_010
Version 1.2.2_10
Version 1.3.1_01
Version 1.3.1_01a
Version 1.3_05

Timeline

No history available yet.