Vulnerability Name: | CVE-2001-1008 (CCN-7048) | ||||||||
Assigned: | 2001-08-24 | ||||||||
Published: | 2001-08-24 | ||||||||
Updated: | 2008-09-05 | ||||||||
Summary: | Java Plugin 1.4 for JRE 1.3 executes signed applets even if the certificate is expired, which could allow remote attackers to conduct unauthorized activities via an applet that has been signed by an expired certificate. | ||||||||
CVSS v3 Severity: | 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||
CVSS v2 Severity: | 7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: BUGTRAQ Type: Vendor Advisory 20010824 Java Plugin 1.4 with JRE 1.3 -> Ignores certificates. Source: CCN Type: BugTraq Mailing List, Fri Aug 24 2001 - 17:58:58 CDT Java Plugin 1.4 with JRE 1.3 -> Ignores certificates. Source: MITRE Type: CNA CVE-2001-1008 Source: XF Type: UNKNOWN javaplugin-jre-expired-certificate(7048) Source: CCN Type: OSVDB ID: 5479 Java Plugin for JRE Expired Certificate Signature Applet Execution Source: BID Type: Exploit, Patch, Vendor Advisory 3245 Source: CCN Type: BID-3245 Java Plug-In 1.4/JRE 1.3 Expired Certificate Vulnerability Source: XF Type: UNKNOWN javaplugin-jre-expired-certificate(7048) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
BACK |