VulnerabilityModified
CVE-2001-1008
Java Plugin 1.4 for JRE 1.3 executes signed applets even if the certificate is expired, which could allow remote attackers to conduct unauthorized activities via an applet that has been signed by an expired certificate.
HIGH 7.5EPSS 1.73%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.73%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Java Plugin 1.4 for JRE 1.3 executes signed applets even if the certificate is expired, which could allow remote attackers to conduct unauthorized activities via an applet that has been signed by an expired certificate.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 1.73% probability · 76th percentile
- CISA KEV
- Not listed
- Affected
- sun/java plug-in · sun/jre
- Source
- cve@mitre.org
References
- http://archives.neohapsis.com/archives/bugtraq/2001-08/0359.htmlVendor Advisory
- http://www.iss.net/security_center/static/7048.php
- http://www.securityfocus.com/bid/3245Exploit, Patch, Vendor Advisory
- http://archives.neohapsis.com/archives/bugtraq/2001-08/0359.htmlVendor Advisory
- http://www.iss.net/security_center/static/7048.php
- http://www.securityfocus.com/bid/3245Exploit, Patch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.