CVE-2004-0723
Microsoft Java virtual machine (VM) 5.0.0.3810 allows remote attackers to bypass sandbox restrictions to read or write certain data between applets from different domains via the "GET/Key" and "PUT/Key/Value" commands, aka "cross-site Java."
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 13.0%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.
Description
Microsoft Java virtual machine (VM) 5.0.0.3810 allows remote attackers to bypass sandbox restrictions to read or write certain data between applets from different domains via the "GET/Key" and "PUT/Key/Value" commands, aka "cross-site Java."
- CVSS 2.0
- 6.4 MEDIUMAV:N/AC:L/Au:N/C:P/I:P/A:N
- EPSS
- 13.05% probability · 96th percentile
- CISA KEV
- Not listed
- Affected
- microsoft/java virtual machine
- Source
- cve@mitre.org
References
- http://marc.info/?l=bugtraq&m=108948405808522&w=2
- http://www.securityfocus.com/bid/10688Exploit, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/16666
- http://marc.info/?l=bugtraq&m=108948405808522&w=2
- http://www.securityfocus.com/bid/10688Exploit, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/16666
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.