SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2003-1572

Sun Java Media Framework (JMF) 2.1.1 through 2.1.1c allows unsigned applets to cause a denial of service (JVM crash) and read or write unauthorized memory locations via the ReadEnv class, as demonstrated by reading environment variables using modified…

HIGH 9.3EPSS 1.72%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (1.72%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

Sun Java Media Framework (JMF) 2.1.1 through 2.1.1c allows unsigned applets to cause a denial of service (JVM crash) and read or write unauthorized memory locations via the ReadEnv class, as demonstrated by reading environment variables using modified .data and .size fields.

CVSS 2.0
9.3 HIGHAV:N/AC:M/Au:N/C:C/I:C/A:C
EPSS
1.72% probability · 76th percentile
CISA KEV
Not listed
Affected
sun/jmf
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.