Sun SDK and Java Runtime Environment (JRE) 1.4.2 through 1.4.2_04, 1.4.1 through 1.4.1_07, and 1.4.0 through 1.4.0_04 allows untrusted applets and unprivileged servlets to gain privileges and read data from other applets via unspecified vectors related to classes in the XSLT processor, aka "XML sniffing."
References
Configurations
Configuration 1 (hide)
|
History
20 Nov 2024, 23:54
Type | Values Removed | Values Added |
---|---|---|
References | () http://archive.cert.uni-stuttgart.de/uniras/2004/08/msg00007.html - | |
References | () http://groups.google.com/group/comp.security.unix/tree/browse_frm/month/2004-10/fe63f1daa9689d50?rnum=161&_done=%2Fgroup%2Fcomp.security.unix%2Fbrowse_frm%2Fmonth%2F2004-10%3Ffwc%3D1%26#doc_29036353582c690d - | |
References | () http://secunia.com/advisories/12206 - Vendor Advisory | |
References | () http://securitytracker.com/id?1011661 - | |
References | () http://www.osvdb.org/8288 - | |
References | () http://www.securityfocus.com/archive/1/371208 - | |
References | () http://www.securityfocus.com/bid/10844 - | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/16864 - |
Information
Published : 2009-06-02 10:30
Updated : 2024-11-20 23:54
NVD link : CVE-2004-2764
Mitre link : CVE-2004-2764
CVE.ORG link : CVE-2004-2764
JSON object : View
Products Affected
sun
- sdk
- jre
CWE
CWE-264
Permissions, Privileges, and Access Controls