Vulnerability Name: | CVE-1999-0141 (CCN-490) | ||||||||
Assigned: | 1996-03-01 | ||||||||
Published: | 1996-03-01 | ||||||||
Updated: | 2008-09-09 | ||||||||
Summary: | Java Bytecode Verifier allows malicious applets to execute arbitrary commands as the user of the applet. | ||||||||
CVSS v3 Severity: | 4.9 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||
CVSS v2 Severity: | 3.7 Low (CVSS v2 Vector: AV:L/AC:H/Au:N/C:P/I:P/A:P)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Other | ||||||||
References: | Source: MITRE Type: CNA CVE-1999-0141 Source: SUN Type: UNKNOWN 00134 Source: CCN Type: Sun Microsystems, Inc. Security Bulletin #00134 Availability of version 1.0.1 of the Java Developer's Kit Source: CCN Type: CERT Advisory CA-1996-07 Weaknesses in Java Bytecode Verifier Source: CCN Type: OSVDB ID: 11721 Java Bytecode Verifier Applet Arbitrary Command Execution Source: CCN Type: SmartComputing Reference Series Article, May 2001, Vol.5 Issue 2, Page(s) 20-22 in print issue Pouring On The Java: Use Of Java & Java Applets Gets More Popular On The Web Source: XF Type: UNKNOWN http-java-applet(490) Source: CCN Type: Microsoft Knowledge Base Article 240346 Malicious Java Applet May Be Able to Read, Write, or Delete Files on the Computer of a Web Site Visitor | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
BACK |