First published: Wed Nov 24 2004(Updated: )
The Sun Java Plugin capability in Java 2 Runtime Environment (JRE) 1.4.2_01, 1.4.2_04, and possibly earlier versions, does not properly restrict access between Javascript and Java applets during data transfer, which allows remote attackers to load unsafe classes and execute arbitrary code by using the reflection API to access private Java packages.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
HP Java SDK-RTE | =1.3 | |
HP Java SDK-RTE | =1.4 | |
OpenJDK | =1.3.1_01 | |
OpenJDK | =1.3.1_01 | |
OpenJDK | =1.3.1_01a | |
OpenJDK | =1.3.1_02 | |
OpenJDK | =1.3.1_02 | |
OpenJDK | =1.3.1_02 | |
OpenJDK | =1.3.1_03 | |
OpenJDK | =1.3.1_03 | |
OpenJDK | =1.3.1_03 | |
OpenJDK | =1.3.1_04 | |
OpenJDK | =1.3.1_05 | |
OpenJDK | =1.3.1_05 | |
OpenJDK | =1.3.1_05 | |
OpenJDK | =1.3.1_06 | |
OpenJDK | =1.3.1_06 | |
OpenJDK | =1.3.1_06 | |
OpenJDK | =1.3.1_07 | |
OpenJDK | =1.3.1_07 | |
OpenJDK | =1.3.1_07 | |
OpenJDK | =1.4 | |
OpenJDK | =1.4 | |
OpenJDK | =1.4 | |
OpenJDK | =1.4.0_01 | |
OpenJDK | =1.4.0_02 | |
OpenJDK | =1.4.0_02 | |
OpenJDK | =1.4.0_02 | |
OpenJDK | =1.4.0_03 | |
OpenJDK | =1.4.0_03 | |
OpenJDK | =1.4.0_03 | |
OpenJDK | =1.4.0_4 | |
OpenJDK | =1.4.0_4 | |
OpenJDK | =1.4.0_4 | |
OpenJDK | =1.4.1 | |
OpenJDK | =1.4.1 | |
OpenJDK | =1.4.1 | |
OpenJDK | =1.4.1_01 | |
OpenJDK | =1.4.1_01 | |
OpenJDK | =1.4.1_01 | |
OpenJDK | =1.4.1_02 | |
OpenJDK | =1.4.1_02 | |
OpenJDK | =1.4.1_02 | |
OpenJDK | =1.4.1_03 | |
OpenJDK | =1.4.1_03 | |
OpenJDK | =1.4.1_03 | |
OpenJDK | =1.4.2 | |
OpenJDK | =1.4.2 | |
OpenJDK | =1.4.2 | |
OpenJDK | =1.4.2_01 | |
OpenJDK | =1.4.2_02 | |
OpenJDK | =1.4.2_03 | |
OpenJDK | =1.4.2_03 | |
OpenJDK | =1.4.2_03 | |
OpenJDK | =1.4.2_04 | |
OpenJDK | =1.4.2_04 | |
OpenJDK | =1.4.2_04 | |
OpenJDK | =1.4.2_05 | |
OpenJDK | =1.4.2_05 | |
OpenJDK | =1.4.2_05 | |
Sun JRE | =1.3.0 | |
Sun JRE | =1.3.0 | |
Sun JRE | =1.3.0 | |
Sun JRE | =1.3.0-update1 | |
Sun JRE | =1.3.0-update2 | |
Sun JRE | =1.3.0-update2 | |
Sun JRE | =1.3.0-update2 | |
Sun JRE | =1.3.0-update3 | |
Sun JRE | =1.3.0-update4 | |
Sun JRE | =1.3.0-update4 | |
Sun JRE | =1.3.0-update5 | |
Sun JRE | =1.3.0-update5 | |
Sun JRE | =1.3.0-update5 | |
Sun JRE | =1.3.1 | |
Sun JRE | =1.3.1-update1 | |
Sun JRE | =1.3.1-update1 | |
Sun JRE | =1.3.1-update1 | |
Sun JRE | =1.3.1-update1a | |
Sun JRE | =1.3.1-update4 | |
Sun JRE | =1.3.1-update4 | |
Sun JRE | =1.3.1-update8 | |
Sun JRE | =1.3.1-update8 | |
Sun JRE | =1.3.1-update8 | |
Sun JRE | =1.3.1_02 | |
Sun JRE | =1.3.1_02 | |
Sun JRE | =1.3.1_02 | |
Sun JRE | =1.3.1_03 | |
Sun JRE | =1.3.1_03 | |
Sun JRE | =1.3.1_03 | |
Sun JRE | =1.3.1_05 | |
Sun JRE | =1.3.1_05 | |
Sun JRE | =1.3.1_05 | |
Sun JRE | =1.3.1_06 | |
Sun JRE | =1.3.1_06 | |
Sun JRE | =1.3.1_06 | |
Sun JRE | =1.3.1_07 | |
Sun JRE | =1.3.1_07 | |
Sun JRE | =1.3.1_07 | |
Sun JRE | =1.3.1_09 | |
Sun JRE | =1.3.1_09 | |
Sun JRE | =1.3.1_09 | |
Sun JRE | =1.4 | |
Sun JRE | =1.4 | |
Sun JRE | =1.4 | |
Sun JRE | =1.4.0_01 | |
Sun JRE | =1.4.0_01 | |
Sun JRE | =1.4.0_02 | |
Sun JRE | =1.4.0_02 | |
Sun JRE | =1.4.0_02 | |
Sun JRE | =1.4.0_03 | |
Sun JRE | =1.4.0_03 | |
Sun JRE | =1.4.0_03 | |
Sun JRE | =1.4.0_04 | |
Sun JRE | =1.4.0_04 | |
Sun JRE | =1.4.0_04 | |
Sun JRE | =1.4.1 | |
Sun JRE | =1.4.1 | |
Sun JRE | =1.4.1 | |
Sun JRE | =1.4.1-update3 | |
Sun JRE | =1.4.1-update3 | |
Sun JRE | =1.4.1-update3 | |
Sun JRE | =1.4.1_01 | |
Sun JRE | =1.4.1_01 | |
Sun JRE | =1.4.1_01 | |
Sun JRE | =1.4.1_02 | |
Sun JRE | =1.4.1_02 | |
Sun JRE | =1.4.1_02 | |
Sun JRE | =1.4.1_07 | |
Sun JRE | =1.4.2 | |
Sun JRE | =1.4.2 | |
Sun JRE | =1.4.2 | |
Sun JRE | =1.4.2-update1 | |
Sun JRE | =1.4.2-update1 | |
Sun JRE | =1.4.2-update1 | |
Sun JRE | =1.4.2-update2 | |
Sun JRE | =1.4.2-update2 | |
Sun JRE | =1.4.2-update2 | |
Sun JRE | =1.4.2-update3 | |
Sun JRE | =1.4.2-update3 | |
Sun JRE | =1.4.2-update3 | |
Sun JRE | =1.4.2-update4 | |
Sun JRE | =1.4.2-update4 | |
Sun JRE | =1.4.2-update4 | |
Sun JRE | =1.4.2-update5 | |
Sun JRE | =1.4.2-update5 | |
Sun JRE | =1.4.2-update5 | |
Symantec Enterprise Firewall | =8.0 | |
Symantec Enterprise Firewall | =8.0 | |
Symantec Enterprise Firewall | =8.0 | |
Conectiva Linux | =10.0 | |
Gentoo Linux | ||
HPE HP-UX | =11.00 | |
HPE HP-UX | =11.11 | |
HPE HP-UX | =11.22 | |
HPE HP-UX | =11.23 | |
Symantec Gateway Security 5400 | =2.0 | |
Symantec Gateway Security 5400 | =2.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-1029 is rated as high severity due to its ability to allow remote attackers to execute arbitrary code.
To fix CVE-2004-1029, users should upgrade to a patched version of the Java Runtime Environment or Java Development Kit.
CVE-2004-1029 affects Sun Java Plugin in JRE 1.4.2_01, 1.4.2_04, and possibly earlier versions.
CVE-2004-1029 impacts systems running various versions of Sun JRE and JDK on Windows, Solaris, and Linux.
CVE-2004-1029 can be exploited to load unsafe classes and execute arbitrary Java code via malicious Java applets.