First published: Thu Nov 14 2002(Updated: )
The Microsoft Java implementation, as used in Internet Explorer, allows remote attackers to read arbitrary local files and network shares via an applet tag with a codebase set to a "file://%00" (null character) URL.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle Java Virtual Machine | =1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-1291 is considered a medium severity vulnerability due to its potential for local file exposure.
To fix CVE-2002-1291, disable or uninstall the Microsoft Java Virtual Machine if it is not needed.
CVE-2002-1291 can be exploited to read arbitrary local files and access network shares through malicious applets.
CVE-2002-1291 affects the Microsoft Java Virtual Machine version 1.1.
Yes, CVE-2002-1291 can be exploited by remote attackers leveraging specific applet tags.