|
Internet Explorer / Netscape / Java multiple vulnerabilities
|
|
Secunia Advisory:
|
SA7587
|
|
|
Release Date:
|
2002-11-25
|
|
Last Update:
|
2002-12-11
|
|
Popularity:
|
18,042 views
|
|
|
Critical:
|
 Moderately critical
|
|
Impact:
|
Exposure of system information Exposure of sensitive information System access
|
|
Where:
|
From remote
|
|
Solution Status:
|
Vendor Patch
|
|
| Software: | Microsoft Internet Explorer 5.01 Microsoft Internet Explorer 5.5 Microsoft Internet Explorer 6.x Netscape 4.7x Sun Java JDK 1.2.x
|
|
|
Secunia CVSS-2 Score:
|
Available in Secunia business solutions
|
|
|
Subscribe:
|
Instant alerts on relevant vulnerabilities
|
|
| Advisory Content (Page 1 of 3) | [ 1 ] [ 2 ] [ 3 ] | |
|
Description: Multiple vulnerabilities has been discovered in different Java implementations. Java Virtual Machines in browsers are supposed to prevent malicious websites from using Java to access local system resources.
JIT bug affecting Netscape versions 4 - 4.8 (Windows)
It is possible to completely bypass safety rules. Allowing malicious websites to access system resources.
Bytecode Verifier vulnerability affecting Internet Explorer all versions 4 - 6
It is possible to completely bypass safety rules. Allowing malicious websites to access system resources.
Bytecode Verifier vulnerability affecting SUN JDK versions 1.1 - 1.4, Netscape versions 4 - 4.8 (all platforms)
It is possible to completely bypass safety rules. Allowing malicious websites to access system resources.
System class implementation affecting Netscape versions 4 - 4.8 (Windows)
Allowing malicious websites to load user provided libraries, when used with the Bytecode Verifier vulnerability an attacker may succesfully execute arbitrary code.
Change Page: [ 1 ] [ 2 ] [ 3 ]
|
|
|
Track this Secunia Advisory
|
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.
Read more about our Vulnerability Intelligence solutions and what they can do for you and your company.
|
|
|
About this Secunia Advisory
|
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.
Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
|