| Vulnerability Name: | CCN-456 | ||||||
| Published: | 1997-08-01 | ||||||
| Updated: | 1997-08-01 | ||||||
| Summary: | A vulnerability in Internet Explorer and Netscape could allow a Java applet to open network connections to a server other than the one it came from. | ||||||
| CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||
| CVSS v2 Severity: | 5.0 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N)
| ||||||
| Vulnerability Consequences: | Bypass Security | ||||||
| References: | Source: CCN Type: Netscape Communications, Inc. Web site Upgrade Available! Netscape 6.0 Source: CCN Type: Ben Mesander's Web site Demo of Browser Security Hole Source: CCN Type: Apple Computer, Inc. Web site Mac OS - Java Source: CCN Type: Microsoft Corporation Web site Internet Explorer 5.5 Service Pack 1 and Internet Tools Source: XF Type: UNKNOWN http-java-connect(456) | ||||||
| Vulnerable Configuration: | Configuration CCN 1: Denotes that component is vulnerable | ||||||
| BACK | |||||||