CVE Database
/

CVE-2002-1292

Back to search

CVE-2002-1292

Published: Nov 14, 2002

Modified: Aug 8, 2024

PUBLISHED

Description

The Microsoft Java virtual machine (VM) build 5.0.3805 and earlier, as used in Internet Explorer, allows remote attackers to extend the Standard Security Manager (SSM) class (com.ms.security.StandardSecurityManager) and bypass intended StandardSecurityManager restrictions by modifying the (1) deniedDefinitionPackages or (2) deniedAccessPackages settings, causing a denial of service by adding Java applets to the list of applets that are prevented from running.

VendorProductVersions

n/a

n/a

affected
n/a

References

msvm-ssm-restriction-bypass(10585)
vdb-entry
x_refsource_XF
MS02-069
vendor-advisory
x_refsource_MS
6133
vdb-entry
x_refsource_BID
VU#237777
third-party-advisory
x_refsource_CERT-VN

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now